feat: Complete 1.1.1 Initialize Node.js project structure #2
security.yml
on: pull_request
Security Audit
1m 25s
Dependency Review
1m 39s
Annotations
14 warnings
|
Security Audit
Unexpected input(s) 'languages', valid inputs are ['check_name', 'output', 'upload', 'cleanup-level', 'ram', 'add-snippets', 'skip-queries', 'threads', 'checkout_path', 'ref', 'sha', 'category', 'upload-database', 'wait-for-processing', 'token', 'matrix', 'expect-error']
|
|
Security Audit
Unexpected input(s) 'languages', valid inputs are ['check_name', 'output', 'upload', 'cleanup-level', 'ram', 'add-snippets', 'skip-queries', 'threads', 'checkout_path', 'ref', 'sha', 'category', 'upload-database', 'wait-for-processing', 'token', 'matrix', 'expect-error']
|
|
Security Audit
Feature flags do not specify a default CLI version. Falling back to the CLI version shipped with the Action. This is 2.22.1.
|
|
Security Audit
This run of the CodeQL Action does not have permission to access Code Scanning API endpoints. As a result, it will not be opted into any experimental features. This could be because the Action is running on a pull request from a fork. If not, please ensure the Action has the 'security-events: write' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
|
|
OpenSSF Scorecard Warning
npm/graceful-fs has an OpenSSF Scorecard of 2.5, which is less than this repository's threshold of 3.
|
|
OpenSSF Scorecard Warning
npm/get-caller-file has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|
|
OpenSSF Scorecard Warning
npm/gensync has an OpenSSF Scorecard of 1.9, which is less than this repository's threshold of 3.
|
|
OpenSSF Scorecard Warning
npm/fs.realpath has an OpenSSF Scorecard of 2.5, which is less than this repository's threshold of 3.
|
|
OpenSSF Scorecard Warning
npm/external-editor has an OpenSSF Scorecard of 2.3, which is less than this repository's threshold of 3.
|
|
OpenSSF Scorecard Warning
npm/deepmerge has an OpenSSF Scorecard of 2.1, which is less than this repository's threshold of 3.
|
|
OpenSSF Scorecard Warning
npm/cross-spawn has an OpenSSF Scorecard of 2.9, which is less than this repository's threshold of 3.
|
|
OpenSSF Scorecard Warning
npm/bs-logger has an OpenSSF Scorecard of 1.7, which is less than this repository's threshold of 3.
|
|
OpenSSF Scorecard Warning
npm/@jridgewell/resolve-uri has an OpenSSF Scorecard of 2.5, which is less than this repository's threshold of 3.
|
|
OpenSSF Scorecard Warning
npm/@bcoe/v8-coverage has an OpenSSF Scorecard of 2.4, which is less than this repository's threshold of 3.
|