Security #92
security.yml
on: schedule
shared
/
Action pin lint (40-char SHA required)
6s
shared
/
Vulnerability allowlist expiry check
8s
shared
/
OSV-Scanner (vendored + manifest deps)
5s
shared
/
Dependency review (GitHub advisory DB)
shared
/
Secret scan (gitleaks)
10s
Annotations
1 warning
|
shared / OSV-Scanner (vendored + manifest deps)
OSV-Scanner found no package sources in the requested paths — treating as non-fatal.
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
gitleaks-report
|
6.91 KB |
sha256:9c95638bb1bf3d20a80ec481ef6e794ee799a9e4fb9950c228562f8b933473b3
|
|