Repository navigation
Bump @grpc/grpc-js from 1.14.4 to 1.14.5 in the security group across 1 directory #656
security-pr.yml Required
on: pull_request
semgrep-oss/scan
44s
zizmor
24s
Annotations
2 errors, 4 warnings, and 2 notices
|
github-app:
.github/workflows/boop-website.yml#L14
boop-website.yml:14: dangerous use of GitHub App tokens: app token inherits blanket installation permissions
|
|
github-app:
.github/workflows/boop-website.yml#L20
boop-website.yml:20: dangerous use of GitHub App tokens: token granted access to all repositories for this owner's app installation
|
|
excessive-permissions:
.github/workflows/build.yml#L12
build.yml:12: overly broad permissions: default permissions used due to no permissions: block
|
|
artipacked:
.github/workflows/build.yml#L16
build.yml:16: credential persistence through GitHub Actions artifacts: does not set persist-credentials: false
|
|
excessive-permissions:
.github/workflows/boop-website.yml#L11
boop-website.yml:11: overly broad permissions: default permissions used due to no permissions: block
|
|
zizmor
No file matched to [/home/runner/work/documentation/documentation/**/*requirements*.txt,/home/runner/work/documentation/documentation/**/*requirements*.in,/home/runner/work/documentation/documentation/**/*constraints*.txt,/home/runner/work/documentation/documentation/**/*constraints*.in,/home/runner/work/documentation/documentation/**/pyproject.toml,/home/runner/work/documentation/documentation/**/uv.lock,/home/runner/work/documentation/documentation/**/*.py.lock]. The cache will never get invalidated. Make sure you have checked out the target repository and configured the cache-dependency-glob input correctly.
|
|
zizmor
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
semgrep-oss/scan
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|