Skip to content

ci(security): add Bandit SAST to CI + CodeQL/pip-audit workflow #1

ci(security): add Bandit SAST to CI + CodeQL/pip-audit workflow

ci(security): add Bandit SAST to CI + CodeQL/pip-audit workflow #1

Triggered via push July 10, 2026 10:23
Status Success
Total duration 56s
Artifacts

security.yml

on: push
CodeQL (Python SAST)
52s
CodeQL (Python SAST)
pip-audit (CVE re-scan)
pip-audit (CVE re-scan)
Fit to window
Zoom out
Zoom in

Annotations

2 warnings
CodeQL (Python SAST)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, github/codeql-action/analyze@v3, github/codeql-action/init@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
CodeQL (Python SAST)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/