Skip to content

Add scan CI step

Add scan CI step #16

Triggered via pull request October 16, 2024 19:12
Status Success
Total duration 2m 34s
Billable time 1m
Artifacts

ci.yml

on: pull_request
Run TokenMessengerMinter tests  /  run_yarn_tests
2m 11s
Run TokenMessengerMinter tests / run_yarn_tests
Run MessageTransmitter tests  /  run_yarn_tests
2m 11s
Run MessageTransmitter tests / run_yarn_tests
scan  /  scan
8s
scan / scan
release-sbom  /  release_attach_assets
release-sbom / release_attach_assets
Fit to window
Zoom out
Zoom in

Annotations

13 warnings
Run TokenMessengerMinter tests / run_yarn_tests
Your docker password is not masked. See https://github.com/aws-actions/amazon-ecr-login#docker-credentials for more information.
Run TokenMessengerMinter tests / run_yarn_tests
One of the secrets has a name that is not POSIX compliant and hence cannot directly be used/injected as an environment variable name. Therefore, it will be transformed into a POSIX compliant environment variable name. Enable GitHub Actions Debug Logging (https://docs.github.com/en/free-pro-team@latest/actions/managing-workflow-runs/enabling-debug-logging) to see the transformed environment variable name. POSIX compliance: environment variable names can only contain upper case letters, digits and underscores. It cannot begin with a digit.
Run TokenMessengerMinter tests / run_yarn_tests
One of the secrets has a name that is not POSIX compliant and hence cannot directly be used/injected as an environment variable name. Therefore, it will be transformed into a POSIX compliant environment variable name. Enable GitHub Actions Debug Logging (https://docs.github.com/en/free-pro-team@latest/actions/managing-workflow-runs/enabling-debug-logging) to see the transformed environment variable name. POSIX compliance: environment variable names can only contain upper case letters, digits and underscores. It cannot begin with a digit.
Run TokenMessengerMinter tests / run_yarn_tests
Your docker password is not masked. See https://github.com/aws-actions/amazon-ecr-login#docker-credentials for more information.
Run TokenMessengerMinter tests / run_yarn_tests
The following actions uses node12 which is deprecated and will be forced to run on node16: abhilash1in/[email protected]. For more info: https://github.blog/changelog/2023-06-13-github-actions-all-actions-will-run-on-node16-instead-of-node12-by-default/
Run TokenMessengerMinter tests / run_yarn_tests
The following actions use a deprecated Node.js version and will be forced to run on node20: aws-actions/amazon-ecr-login@v1, abhilash1in/[email protected], actions/[email protected], KengoTODA/[email protected], actions/setup-node@v3, aws-actions/configure-aws-credentials@v2, andstor/file-existence-action@v2. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
Run MessageTransmitter tests / run_yarn_tests
Your docker password is not masked. See https://github.com/aws-actions/amazon-ecr-login#docker-credentials for more information.
Run MessageTransmitter tests / run_yarn_tests
One of the secrets has a name that is not POSIX compliant and hence cannot directly be used/injected as an environment variable name. Therefore, it will be transformed into a POSIX compliant environment variable name. Enable GitHub Actions Debug Logging (https://docs.github.com/en/free-pro-team@latest/actions/managing-workflow-runs/enabling-debug-logging) to see the transformed environment variable name. POSIX compliance: environment variable names can only contain upper case letters, digits and underscores. It cannot begin with a digit.
Run MessageTransmitter tests / run_yarn_tests
One of the secrets has a name that is not POSIX compliant and hence cannot directly be used/injected as an environment variable name. Therefore, it will be transformed into a POSIX compliant environment variable name. Enable GitHub Actions Debug Logging (https://docs.github.com/en/free-pro-team@latest/actions/managing-workflow-runs/enabling-debug-logging) to see the transformed environment variable name. POSIX compliance: environment variable names can only contain upper case letters, digits and underscores. It cannot begin with a digit.
Run MessageTransmitter tests / run_yarn_tests
Your docker password is not masked. See https://github.com/aws-actions/amazon-ecr-login#docker-credentials for more information.
Run MessageTransmitter tests / run_yarn_tests
The following actions uses node12 which is deprecated and will be forced to run on node16: abhilash1in/[email protected]. For more info: https://github.blog/changelog/2023-06-13-github-actions-all-actions-will-run-on-node16-instead-of-node12-by-default/
Run MessageTransmitter tests / run_yarn_tests
The following actions use a deprecated Node.js version and will be forced to run on node20: aws-actions/amazon-ecr-login@v1, abhilash1in/[email protected], actions/[email protected], KengoTODA/[email protected], actions/setup-node@v3, aws-actions/configure-aws-credentials@v2, andstor/file-existence-action@v2. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
OpenSSF Scorecard Warning
npm/elliptic has an OpenSSF Scorecard of 2.1, which is less than this repository's threshold of 3.