Skip to content

ci: add ThreatCrush security scan #1

ci: add ThreatCrush security scan

ci: add ThreatCrush security scan #1

Triggered via pull request August 3, 2026 10:32
Status Success
Total duration 1m 48s
Artifacts 1

threatcrush-scan.yml

on: pull_request
Scan for credentials and vulnerable patterns
1m 15s
Scan for credentials and vulnerable patterns
Fit to window
Zoom out
Zoom in

Annotations

1 error, 4 warnings, and 1 notice
Scan for credentials and vulnerable patterns
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/github-script@v7, actions/setup-node@v4, actions/upload-artifact@v4, github/codeql-action/upload-sarif@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Scan for credentials and vulnerable patterns
Failed to gather information for telemetry: Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run. Will skip sending status report.
Scan for credentials and vulnerable patterns
Failed to gather information for telemetry: Resource not accessible by integration - https://docs.github.com/rest/actions/workflow-runs#get-a-workflow-run. Will skip sending status report.
Scan for credentials and vulnerable patterns
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Scan for credentials and vulnerable patterns
CLI 0.2.2 predates --format; converting terminal output instead.

Artifacts

Produced during runtime
Name Size Digest
threatcrush-sarif
381 Bytes
sha256:0bcc7575ef6c4b2115049d749a32c4c7ff310ff3ab5d845387c8d2eda3d79bf8