fix: validate header names/values and prevent CRLF injection (#1817) #180
trivy-scan.yml
on: pull_request
Matrix: build
Synthetic CVE policy gate test
16s
Matrix: trivy-scan
Annotations
1 error and 6 warnings
|
Synthetic CVE policy gate test
Process completed with exit code 1.
|
|
Build backend image
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/upload-artifact@v4, docker/build-push-action@v6, docker/setup-buildx-action@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Build frontend image
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/upload-artifact@v4, docker/build-push-action@v6, docker/setup-buildx-action@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Trivy scan - frontend
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/download-artifact@v4, actions/upload-artifact@v4, github/codeql-action/upload-sarif@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Trivy scan - frontend
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Trivy scan - backend
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/download-artifact@v4, actions/upload-artifact@v4, github/codeql-action/upload-sarif@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Trivy scan - backend
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
secuscan-backend-tar
Expired
|
200 MB |
sha256:587ca631128fa35f58db8fa2331bbe6fd362e70c9d778620152b95136938ccfb
|
|
|
secuscan-frontend-tar
Expired
|
22.9 MB |
sha256:dc28090c443ee4adb031965f8a0a9c2516b0e4529104cb09524c95be1d8dad2f
|
|
|
trivy-report-backend
|
89.5 KB |
sha256:ecbe27f6d02ef5104fc403cc4cf592ab735d52993808fa33e95e9d0fb1ea5284
|
|
|
trivy-report-frontend
|
30.2 KB |
sha256:9d251404035d341fd85b97c719b71fd4f799d6a49e6f7562d8f673b51d87ea03
|
|
|
utksh1~SecuScan~ONZ3W8.dockerbuild
|
35 KB |
sha256:50e84c527e8bbc2185e33684ddc0c6a92017e2b9197403cfcd01787a8b3ac5e5
|
|
|
utksh1~SecuScan~RHYKCK.dockerbuild
|
44.5 KB |
sha256:a010466afe1aaf043d93a11ec5fd31ca7e76a921b42b46616ce618b14277f611
|
|