Skip to content

fix(deps): resolve all npm vulnerabilities — 0 remaining #83

fix(deps): resolve all npm vulnerabilities — 0 remaining

fix(deps): resolve all npm vulnerabilities — 0 remaining #83

Triggered via push June 7, 2026 05:33
Status Cancelled
Total duration 1m 15s
Artifacts 1

security.yml

on: push
Hardcoded Secrets Detection
2s
Hardcoded Secrets Detection
Dependency Vulnerability Review
7s
Dependency Vulnerability Review
CodeQL (.NET Backend)
29s
CodeQL (.NET Backend)
CodeQL (TypeScript/React)
1m 2s
CodeQL (TypeScript/React)
NuGet Vulnerability Audit
0s
NuGet Vulnerability Audit
npm Vulnerability Audit
0s
npm Vulnerability Audit
Docker Image Security Scan
0s
Docker Image Security Scan
Tenant Isolation Security Tests
0s
Tenant Isolation Security Tests
Security Scan Report
5s
Security Scan Report
Security Gate
4s
Security Gate
Fit to window
Zoom out
Zoom in

Annotations

7 errors and 8 warnings
Hardcoded Secrets Detection
Unable to resolve action goreleaser/gitleaks-action, repository not found
Dependency Vulnerability Review
Both a base ref and head ref must be provided, either via the `base_ref`/`head_ref` config options, `base-ref`/`head-ref` workflow action options, or by running a `pull_request`/`pull_request_target`/`merge_group` workflow.
CodeQL (.NET Backend)
Encountered a fatal error while running "/opt/hostedtoolcache/CodeQL/2.25.6/x64/codeql/codeql database finalize --finalize-dataset --threads=4 --ram=14575 /home/runner/work/_temp/codeql_databases/csharp". Exit code was 32 and last log line was: CodeQL detected code written in C# but could not process any of it. For more information, review our troubleshooting guide at https://gh.io/troubleshooting-code-scanning/no-source-code-seen-during-build . See the logs for more details.
CodeQL (TypeScript/React)
Canceling since a higher priority waiting request for security-refs/heads/main exists
CodeQL (TypeScript/React)
The operation was canceled.
Security Gate
Process completed with exit code 1.
Security Pipeline
Canceling since a higher priority waiting request for security-refs/heads/main exists
Dependency Vulnerability Review
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/dependency-review-action@v4. Actions will be forced to run with Node.js 24 by default starting June 16th, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
CodeQL (.NET Backend)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, github/codeql-action/analyze@v3, github/codeql-action/init@v3. Actions will be forced to run with Node.js 24 by default starting June 16th, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
CodeQL (.NET Backend)
1 issue was detected with this workflow: Not all workflow steps that use `github/codeql-action` actions use the same version. Please ensure that all such steps use the same version to avoid compatibility issues.
CodeQL (.NET Backend)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
CodeQL (TypeScript/React)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, github/codeql-action/analyze@v3, github/codeql-action/init@v3. Actions will be forced to run with Node.js 24 by default starting June 16th, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
CodeQL (TypeScript/React)
1 issue was detected with this workflow: Not all workflow steps that use `github/codeql-action` actions use the same version. Please ensure that all such steps use the same version to avoid compatibility issues.
CodeQL (TypeScript/React)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Security Scan Report
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 16th, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/

Artifacts

Produced during runtime
Name Size Digest
security-scan-report
371 Bytes
sha256:b6bd4fa7aeffc641e311494318face00b8ec1c71ba0034e77376099e6d92605e