Skip to content

ci: add ThreatCrush security scan #57

ci: add ThreatCrush security scan

ci: add ThreatCrush security scan #57

Triggered via pull request August 3, 2026 10:48
Status Success
Total duration 44s
Artifacts 1

threatcrush-scan.yml

on: pull_request
Scan for credentials and vulnerable patterns
31s
Scan for credentials and vulnerable patterns
Fit to window
Zoom out
Zoom in

Annotations

11 warnings and 1 notice
Scan for credentials and vulnerable patterns
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/github-script@v7, actions/setup-node@v4, actions/upload-artifact@v4, github/codeql-action/upload-sarif@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Scan for credentials and vulnerable patterns
Calculated fingerprint of e134d8d8b689d373:1 for file packages/ai/arcee/src/index.test.ts line 101, but found existing inconsistent fingerprint value threatcrush-generic-api-key:packages/ai/arcee/src/index.test.ts:101
Scan for credentials and vulnerable patterns
Calculated fingerprint of 1d231d1f19c961a2:1 for file packages/ai/amazon-bedrock/src/index.ts line 11, but found existing inconsistent fingerprint value threatcrush-generic-secret:packages/ai/amazon-bedrock/src/index.ts:11
Scan for credentials and vulnerable patterns
Calculated fingerprint of e5920fb73e46c5c6:1 for file packages/ai/amazon-bedrock/src/index.ts line 10, but found existing inconsistent fingerprint value threatcrush-generic-secret:packages/ai/amazon-bedrock/src/index.ts:10
Scan for credentials and vulnerable patterns
Calculated fingerprint of c9a84908c5ed7e48:1 for file packages/ai/amazon-bedrock/src/index.ts line 9, but found existing inconsistent fingerprint value threatcrush-generic-secret:packages/ai/amazon-bedrock/src/index.ts:9
Scan for credentials and vulnerable patterns
Calculated fingerprint of e134d8d8b689d373:1 for file packages/ai/ai21/src/index.test.ts line 101, but found existing inconsistent fingerprint value threatcrush-generic-api-key:packages/ai/ai21/src/index.test.ts:101
Scan for credentials and vulnerable patterns
Calculated fingerprint of ce6a74fc827ae441:1 for file packages/agent-providers/opencode/src/__tests__/opencode.test.ts line 99, but found existing inconsistent fingerprint value threatcrush-generic-secret:packages/agent-providers/opencode/src/__tests__/opencode.test.ts:99
Scan for credentials and vulnerable patterns
Calculated fingerprint of 157f8bd1d8eb4476:1 for file packages/affiliates/sovrn/src/index.ts line 28, but found existing inconsistent fingerprint value threatcrush-generic-api-key:packages/affiliates/sovrn/src/index.ts:28
Scan for credentials and vulnerable patterns
Calculated fingerprint of d479d626c885d314:1 for file packages/affiliates/skimlinks/src/index.test.ts line 38, but found existing inconsistent fingerprint value threatcrush-generic-secret:packages/affiliates/skimlinks/src/index.test.ts:38
Scan for credentials and vulnerable patterns
Calculated fingerprint of a48895426f139322:1 for file packages/affiliates/skimlinks/src/index.test.ts line 7, but found existing inconsistent fingerprint value threatcrush-generic-secret:packages/affiliates/skimlinks/src/index.test.ts:7
Scan for credentials and vulnerable patterns
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Scan for credentials and vulnerable patterns
CLI 0.2.2 predates --format; converting terminal output instead.

Artifacts

Produced during runtime
Name Size Digest
threatcrush-sarif
2.28 KB
sha256:b1a3aeb687bd5842108541f3884314a38424ea8eb78496bd20dd134385d4e9d8