Update All v5 dependencies (v5) - #2886
Quality Gate failed
Failed conditions
E Security Rating on New Code (required ≥ A)
See analysis details on SonarQube Cloud
Catch issues before they fail your Quality Gate with our IDE extension
SonarQube for IDE
Annotations
Check warning on line 22 in .github/workflows/validate_dependencies.yml
sonarqubecloud / SonarCloud Code Analysis
Omitting "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKL7HvSpjtQlrUjV0&open=AZ9yKL7HvSpjtQlrUjV0&pullRequest=2886
Check warning on line 14 in .github/workflows/finalize_release.yml
sonarqubecloud / SonarCloud Code Analysis
Move this write permission from workflow level to job level.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKL9TvSpjtQlrUjV5&open=AZ9yKL9TvSpjtQlrUjV5&pullRequest=2886
Check warning on line 63 in .github/workflows/generate_release_notes.yml
sonarqubecloud / SonarCloud Code Analysis
Using dependencies without locking resolved versions is security-sensitive.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKL63vSpjtQlrUjVy&open=AZ9yKL63vSpjtQlrUjVy&pullRequest=2886
Check warning on line 42 in .github/workflows/update_verification_metadata.yml
sonarqubecloud / SonarCloud Code Analysis
Avoid expanding secrets in a run block.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKL51vSpjtQlrUjVv&open=AZ9yKL51vSpjtQlrUjVv&pullRequest=2886
Check warning on line 43 in .github/workflows/update_verification_metadata.yml
sonarqubecloud / SonarCloud Code Analysis
Avoid expanding secrets in a run block.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKL51vSpjtQlrUjVw&open=AZ9yKL51vSpjtQlrUjVw&pullRequest=2886
Check failure on line 32 in .github/workflows/add_pr_label.yml
sonarqubecloud / SonarCloud Code Analysis
The expression github.event.pull_request.head.ref can be set by an external actor to a specially crafted value, enabling script injection. Change this workflow to not use user-controlled data directly in a run block, for example by assigning this expression to an environment variable.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKL9hvSpjtQlrUjV6&open=AZ9yKL9hvSpjtQlrUjV6&pullRequest=2886
Check warning on line 22 in .github/workflows/validate_dependencies.yml
sonarqubecloud / SonarCloud Code Analysis
Using dependencies without locking resolved versions is security-sensitive.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKL7HvSpjtQlrUjV1&open=AZ9yKL7HvSpjtQlrUjV1&pullRequest=2886
Check warning on line 38 in .github/workflows/publish_to_maven_central.yml
sonarqubecloud / SonarCloud Code Analysis
Using dependencies without locking resolved versions is security-sensitive.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKLzwvSpjtQlrUjVr&open=AZ9yKLzwvSpjtQlrUjVr&pullRequest=2886
Check warning on line 63 in .github/workflows/generate_release_notes.yml
sonarqubecloud / SonarCloud Code Analysis
Omitting "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKL63vSpjtQlrUjVx&open=AZ9yKL63vSpjtQlrUjVx&pullRequest=2886
Check warning on line 7 in .github/workflows/check_dependency_changes.yml
sonarqubecloud / SonarCloud Code Analysis
Move this write permission from workflow level to job level.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKL9GvSpjtQlrUjV2&open=AZ9yKL9GvSpjtQlrUjV2&pullRequest=2886
Check warning on line 100 in .github/workflows/publish_to_maven_central.yml
sonarqubecloud / SonarCloud Code Analysis
Using dependencies without locking resolved versions is security-sensitive.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKLzwvSpjtQlrUjVt&open=AZ9yKLzwvSpjtQlrUjVt&pullRequest=2886
Check warning on line 13 in .github/workflows/update_release_notes.yml
sonarqubecloud / SonarCloud Code Analysis
Move this write permission from workflow level to job level.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKL4hvSpjtQlrUjVu&open=AZ9yKL4hvSpjtQlrUjVu&pullRequest=2886
Check warning on line 11 in .github/workflows/generate_release_notes.yml
sonarqubecloud / SonarCloud Code Analysis
Move this write permission from workflow level to job level.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKL63vSpjtQlrUjVz&open=AZ9yKL63vSpjtQlrUjVz&pullRequest=2886
Check warning on line 15 in .github/workflows/add_pr_label.yml
sonarqubecloud / SonarCloud Code Analysis
Move this write permission from workflow level to job level.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKL9hvSpjtQlrUjV7&open=AZ9yKL9hvSpjtQlrUjV7&pullRequest=2886
Check warning on line 8 in .github/workflows/check_dependency_changes.yml
sonarqubecloud / SonarCloud Code Analysis
Move this write permission from workflow level to job level.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKL9GvSpjtQlrUjV3&open=AZ9yKL9GvSpjtQlrUjV3&pullRequest=2886
Check warning on line 100 in .github/workflows/publish_to_maven_central.yml
sonarqubecloud / SonarCloud Code Analysis
Omitting "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKLzwvSpjtQlrUjVs&open=AZ9yKLzwvSpjtQlrUjVs&pullRequest=2886
Check warning on line 13 in .github/workflows/finalize_release.yml
sonarqubecloud / SonarCloud Code Analysis
Move this write permission from workflow level to job level.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKL9TvSpjtQlrUjV4&open=AZ9yKL9TvSpjtQlrUjV4&pullRequest=2886
Check warning on line 38 in .github/workflows/publish_to_maven_central.yml
sonarqubecloud / SonarCloud Code Analysis
Omitting "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.
See more on https://sonarcloud.io/project/issues?id=Adyen_adyen-android&issues=AZ9yKLzwvSpjtQlrUjVq&open=AZ9yKLzwvSpjtQlrUjVq&pullRequest=2886