Skip to content

Bump js-yaml from 3.14.1 to 3.14.2 in the npm_and_yarn group across 1 directory #82

Bump js-yaml from 3.14.1 to 3.14.2 in the npm_and_yarn group across 1 directory

Bump js-yaml from 3.14.1 to 3.14.2 in the npm_and_yarn group across 1 directory #82

Triggered via pull request November 18, 2025 10:49
Status Failure
Total duration 3m 30s
Artifacts 1

ci.yml

on: pull_request
Fit to window
Zoom out
Zoom in

Annotations

15 errors, 10 warnings, and 1 notice
Security Scan
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Security Scan
github.Integration.CreatePullRequest calls io.ReadAll, which eventually calls tls.Conn.Read
Security Scan
gogent.runServer calls gracewrap.Graceful.WrapHTTP, which eventually calls tls.Conn.HandshakeContext
Security Scan
gogent.NewClient calls sql.Open, which eventually calls tls.Conn.Handshake
Security Scan
apiauth.GitHubAppHandler.generateJWT calls pem.Decode
Security Scan
github.Integration.CreatePullRequest calls http.Client.Do, which eventually calls url.URL.Parse
Security Scan
gogent.runServer calls gracewrap.Graceful.WrapHTTP, which eventually calls url.ParseRequestURI
Security Scan
github.Integration.CreatePullRequest calls http.NewRequestWithContext, which calls url.Parse
Security Scan
apiauth.GitHubAppHandler.generateJWT calls x509.ParsePKCS8PrivateKey, which calls asn1.Unmarshal
Security Scan
github.Integration.CreatePullRequest calls http.Client.Do
Security Scan
github.Integration.CreatePullRequest calls io.ReadAll, which eventually calls x509.Certificate.Verify
Lint
issues found
Lint: internal/agents/database.go#L416
File is not properly formatted (gofmt)
Lint: internal/agents/database.go#L446
func `(*Handler).getExecutionTokens` is unused (unused)
Dependency Scan
Dependency review detected vulnerable packages.
OpenSSF Scorecard Warning
npm/css-in-js-utils has an OpenSSF Scorecard of 2.1, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/cross-spawn has an OpenSSF Scorecard of 2.9, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/chownr has an OpenSSF Scorecard of 2.9, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/bs-logger has an OpenSSF Scorecard of 1.7, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/agent-base has an OpenSSF Scorecard of 2.9, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/@humanwhocodes/object-schema has an OpenSSF Scorecard of 2.9, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/@expo/bunyan has an OpenSSF Scorecard of 2.8, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/@egjs/hammerjs has an OpenSSF Scorecard of 2, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/@bcoe/v8-coverage has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/@babel/preset-modules has an OpenSSF Scorecard of 2.9, which is less than this repository's threshold of 3.
Test Coverage
Coverage is 4.7% (Threshold: 4%)

Artifacts

Produced during runtime
Name Size Digest
dependency-review-summary Expired
36.8 KB
sha256:49de684d9ca29a2e6742407702b968f80730a5495e350e7feeeb313653ae681b