Skip to content

feat(security): screen for a requirement identifier PAIRED WITH A VERDICT, not for identifiers (BACKLOG #1337) #2503

feat(security): screen for a requirement identifier PAIRED WITH A VERDICT, not for identifiers (BACKLOG #1337)

feat(security): screen for a requirement identifier PAIRED WITH A VERDICT, not for identifiers (BACKLOG #1337) #2503

Triggered via pull request August 26, 2026 04:41
Status Success
Total duration 17m 31s
Artifacts

security.yml

on: pull_request
pip-audit (dependency vulnerabilities)
1m 22s
pip-audit (dependency vulnerabilities)
npm-audit (ide dependency vulnerabilities)
9s
npm-audit (ide dependency vulnerabilities)
released-line-audit (latest release's pinned runtime)
released-line-audit (latest release's pinned runtime)
SBOMs (CycloneDX, multi-ecosystem)
SBOMs (CycloneDX, multi-ecosystem)
trivy (container image vulnerabilities)
trivy (container image vulnerabilities)
bandit (Python SAST)
26s
bandit (Python SAST)
gitleaks (secret scan)
17s
gitleaks (secret scan)
semgrep (project SAST rules)
31s
semgrep (project SAST rules)
crypto-inventory (ASVS 11.1.3 discovery gate)
9s
crypto-inventory (ASVS 11.1.3 discovery gate)
forbidden-content (customer/PHI leak guard)
44s
forbidden-content (customer/PHI leak guard)
Fit to window
Zoom out
Zoom in