Security #93
security.yml
on: schedule
shared
/
Action pin lint (40-char SHA required)
5s
shared
/
Vulnerability allowlist expiry check
9s
shared
/
OSV-Scanner (vendored + manifest deps)
6s
shared
/
Dependency review (GitHub advisory DB)
shared
/
Secret scan (gitleaks)
6s
Annotations
1 warning
|
shared / OSV-Scanner (vendored + manifest deps)
OSV-Scanner found no package sources in the requested paths — treating as non-fatal.
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
gitleaks-report
|
6.91 KB |
sha256:ef16f670fbd6aedab2c4c773664af8c6201a79569f41582ddf9fdd9785c88eed
|
|