Skip to content

Bump library/golang from 1.26.3-alpine to 1.26.5-alpine in /services/tool-firewall #269

Bump library/golang from 1.26.3-alpine to 1.26.5-alpine in /services/tool-firewall

Bump library/golang from 1.26.3-alpine to 1.26.5-alpine in /services/tool-firewall #269

Triggered via pull request July 10, 2026 03:53
Status Failure
Total duration 9m 19s
Artifacts 1

ci.yml

on: pull_request
Matrix: Go Build & Test
Python Test & Lint
35s
Python Test & Lint
Hadolint & Semgrep
19s
Hadolint & Semgrep
Security Regression Tests
47s
Security Regression Tests
Test Count Drift Check
47s
Test Count Drift Check
Dependency Vulnerability Audit
1m 7s
Dependency Vulnerability Audit
Documentation Validation
8s
Documentation Validation
Shell Script Lint
6s
Shell Script Lint
Release Helper Script Smoke
15s
Release Helper Script Smoke
Validate YAML configs
7s
Validate YAML configs
Image Reference Consistency
7s
Image Reference Consistency
Verify action, container, and EOL pins
7s
Verify action, container, and EOL pins
Supply Chain & SBOM Verification
21s
Supply Chain & SBOM Verification
Sandbox OpenVEX Smoke
7m 55s
Sandbox OpenVEX Smoke
Release Branch Hardened Gate
0s
Release Branch Hardened Gate
Fit to window
Zoom out
Zoom in

Annotations

11 errors and 4 warnings
Verify action, container, and EOL pins
Process completed with exit code 1.
Dependency Vulnerability Audit
securectl.cmdStatus calls fmt.Fprintf, which calls tls.Conn.Write
Dependency Vulnerability Audit
securectl.apiRequest calls io.ReadAll, which eventually calls tls.Conn.Read
Dependency Vulnerability Audit
registry.main calls http.Server.ListenAndServe, which eventually calls tls.Conn.HandshakeContext
Dependency Vulnerability Audit
airlock: govulncheck found vulnerabilities
Dependency Vulnerability Audit
airlock.loadSources calls fmt.Errorf, which eventually calls x509.HostnameError.Error
Dependency Vulnerability Audit
airlock.main calls http.Server.ListenAndServe, which eventually calls x509.Certificate.VerifyHostname
Dependency Vulnerability Audit
airlock.main calls http.Server.ListenAndServe, which eventually calls x509.Certificate.Verify
Dependency Vulnerability Audit
airlock.main calls http.Server.ListenAndServe, which eventually calls textproto.Reader.ReadMIMEHeader
Dependency Vulnerability Audit
airlock.main calls signal.NotifyContext, which eventually calls tls.Conn.Read
Dependency Vulnerability Audit
airlock.main calls http.Server.ListenAndServe, which eventually calls tls.Conn.HandshakeContext
Security Regression Tests
Restore cache failed: Dependencies file is not found in /home/runner/work/SecAI_OS/SecAI_OS. Supported file pattern: go.mod
Dependency Vulnerability Audit
Restore cache failed: Dependencies file is not found in /home/runner/work/SecAI_OS/SecAI_OS. Supported file pattern: go.mod
Test Count Drift Check
Restore cache failed: Dependencies file is not found in /home/runner/work/SecAI_OS/SecAI_OS. Supported file pattern: go.mod
Supply Chain & SBOM Verification
Restore cache failed: Dependencies file is not found in /home/runner/work/SecAI_OS/SecAI_OS. Supported file pattern: go.mod

Artifacts

Produced during runtime
Name Size Digest
sandbox-vex-smoke
1.43 KB
sha256:165e21793b96193c40d4099e930cfbffd912b37bcd9852f55b16c8f1f30ca024