build(deps-dev): Bump @types/node from 20.19.27 to 20.19.35 #82
security-scan.yml
on: pull_request
Matrix: Trivy Container Scan
CodeQL Security Analysis
4m 52s
Dependency Security Audit
8s
Dependency Review
6s
Snyk Security Scan
26s
Semgrep Security Scan
1m 2s
Secret Scanning
12s
Security Policy Check
4s
OSSF Scorecard
13s
Security Summary
5s
Annotations
11 errors and 2 warnings
|
Dependency Security Audit
Dependencies lock file is not found in /home/runner/work/SmartCRDT/SmartCRDT. Supported file patterns: package-lock.json,npm-shrinkwrap.json,yarn.lock
|
|
Trivy Container Scan (full)
Process completed with exit code 1.
|
|
Trivy Container Scan (cli)
The strategy configuration was canceled because "trivy.full" failed
|
|
Trivy Container Scan (cli)
The operation was canceled.
|
|
Dependency Review
[
{
"code": "custom",
"message": "You cannot specify both allow-licenses and deny-licenses",
"path": []
}
]
|
|
OSSF Scorecard
Unable to upload "results.json" as it is not valid SARIF:
- instance is not allowed to have the additional property "date"
- instance is not allowed to have the additional property "repo"
- instance is not allowed to have the additional property "scorecard"
- instance is not allowed to have the additional property "score"
- instance is not allowed to have the additional property "checks"
- instance is not allowed to have the additional property "metadata"
- instance requires property "version"
- instance requires property "runs"
|
|
Trivy Container Scan (base)
The strategy configuration was canceled because "trivy.full" failed
|
|
Trivy Container Scan (base)
The operation was canceled.
|
|
Snyk Security Scan
Dependencies lock file is not found in /home/runner/work/SmartCRDT/SmartCRDT. Supported file patterns: package-lock.json,npm-shrinkwrap.json,yarn.lock
|
|
CodeQL Security Analysis
Error running analysis for javascript: Encountered a fatal error while running "/opt/hostedtoolcache/CodeQL/2.24.2/x64/codeql/codeql database interpret-results --threads=4 --format=sarif-latest -v --output=../results/javascript.sarif --print-diagnostics-summary --print-metrics-summary --sarif-add-baseline-file-info --sarif-codescanning-config=/home/runner/work/_temp/user-config.yaml --sarif-group-rules-by-pack --sarif-include-query-help=always --sublanguage-file-coverage --sarif-run-property=jobRunUuid=661f261a-77ac-4859-953a-986e7ea2405b --sarif-run-property=incrementalMode=diff-informed --sarif-category /language:javascript-typescript --sarif-include-diagnostics /home/runner/work/_temp/codeql_databases/javascript". Exit code was 2 and error was: A fatal error occurred: Could not process query metadata for /home/runner/work/_temp/codeql_databases/javascript/results/codeql/javascript-queries/Security/trest/test.bqrs.
Error was: Cannot process query metadata for a query without the '@kind' metadata property. To learn more, see https://codeql.github.com/docs/writing-codeql-queries/metadata-for-codeql-queries/ [NO_KIND_SPECIFIED]. See the logs for more details.
|
|
Security Summary
Unhandled error: HttpError: Resource not accessible by integration
|
|
OSSF Scorecard
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
CodeQL Security Analysis
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
gitleaks-results.sarif
Expired
|
6.61 KB |
sha256:d2ad5281c1c3fe3e86d167271b44a739ef663c55de0f6d3097d09cf4b38d86ae
|
|