π Security Scanning #60
security.yml
on: schedule
π Dependency Scan
1m 31s
π Code Security Analysis
3m 18s
π Secret Scanning
10s
π³ Docker Security
3m 52s
ποΈ Infrastructure Security
5s
π Security Summary
5s
Annotations
8 errors and 25 warnings
|
π Dependency Scan
Process completed with exit code 1.
|
|
π Code Security Analysis
Path does not exist: semgrep.sarif
|
|
π³ Docker Security
Path does not exist: scout-frontend-results.sarif
|
|
π³ Docker Security
Path does not exist: scout-backend-results.sarif
|
|
π³ Docker Security
Path does not exist: trivy-fs-results.sarif
|
|
π³ Docker Security
Aborting upload: only one run of the codeql/analyze or codeql/upload-sarif actions is allowed per job per tool/category. The easiest fix is to specify a unique value for the `category` input. If .runs[].automationDetails.id is specified in the sarif file, that will take precedence over your configured `category`. Category: (.github/workflows/security.yml:docker-security/) Tool: (Trivy)
|
|
π³ Docker Security
Resource not accessible by integration - https://docs.github.com/rest
|
|
π Security Summary
Unhandled error: HttpError: Resource not accessible by integration
|
|
ποΈ Infrastructure Security
No files were found with the provided path: k8s-security-scan.json
k8s-issues.json
infra-security-summary.md. No artifacts will be uploaded.
|
|
π Secret Scanning
π Leaks detected, see job summary for details
|
|
π Dependency Scan
No files were found with the provided path: dependency-scan.log
npm-audit.json
security-summary.md. No artifacts will be uploaded.
|
|
π Code Security Analysis
Unexpected input(s) 'publishDeployment', 'generateSarif', valid inputs are ['entryPoint', 'args', 'config', 'publishToken']
|
|
π Code Security Analysis:
backend/ModernAPI.Application/Services/ETagService.cs#L204
Missing XML comment for publicly visible type or member 'ETagService.CheckIfMatch(string?, string)'
|
|
π Code Security Analysis:
backend/ModernAPI.Application/Services/ETagService.cs#L174
Missing XML comment for publicly visible type or member 'ETagService.CheckIfNoneMatch(string?, string)'
|
|
π Code Security Analysis:
backend/ModernAPI.Application/Services/ETagService.cs#L152
Missing XML comment for publicly visible type or member 'ETagService.ParseETagHeader(string?)'
|
|
π Code Security Analysis:
backend/ModernAPI.Application/Services/ETagService.cs#L147
Missing XML comment for publicly visible type or member 'ETagService.ValidateETag(string?, UserDto)'
|
|
π Code Security Analysis:
backend/ModernAPI.Application/Services/ETagService.cs#L135
Missing XML comment for publicly visible type or member 'ETagService.ValidateETag(string?, Guid, DateTime)'
|
|
π Code Security Analysis:
backend/ModernAPI.Application/Services/ETagService.cs#L129
Missing XML comment for publicly visible type or member 'ETagService.GenerateCollectionETag(IEnumerable<UserDto>)'
|
|
π Code Security Analysis:
backend/ModernAPI.Application/Services/ETagService.cs#L111
Missing XML comment for publicly visible type or member 'ETagService.GenerateCollectionETag(IEnumerable<(Guid Id, DateTime LastModified)>)'
|
|
π Code Security Analysis:
backend/ModernAPI.Application/Services/ETagService.cs#L106
Missing XML comment for publicly visible type or member 'ETagService.GenerateETag(UserDto)'
|
|
π Code Security Analysis:
backend/ModernAPI.Application/Services/ETagService.cs#L93
Missing XML comment for publicly visible type or member 'ETagService.GenerateETag(Guid, DateTime)'
|
|
π Code Security Analysis:
backend/ModernAPI.Application/Services/AuthService.cs#L23
Missing XML comment for publicly visible type or member 'AuthService.AuthService(UserManager<User>, IPasswordService, IJwtTokenService, IUnitOfWork, ILogger<AuthService>)'
|
|
π³ Docker Security
Resource not accessible by integration - https://docs.github.com/rest
|
|
π³ Docker Security
Resource not accessible by integration - https://docs.github.com/rest
|
|
π³ Docker Security
Resource not accessible by integration - https://docs.github.com/rest
|
|
π³ Docker Security
Resource not accessible by integration - https://docs.github.com/rest
|
|
π³ Docker Security
Resource not accessible by integration - https://docs.github.com/rest
|
|
π³ Docker Security
Resource not accessible by integration - https://docs.github.com/rest
|
|
π³ Docker Security
Resource not accessible by integration - https://docs.github.com/rest
|
|
π³ Docker Security
Resource not accessible by integration - https://docs.github.com/rest
|
|
π³ Docker Security
Resource not accessible by integration - https://docs.github.com/rest
|
|
π³ Docker Security
Resource not accessible by integration - https://docs.github.com/rest
|
|
π³ Docker Security
Resource not accessible by integration - https://docs.github.com/rest
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
comprehensive-security-report
Expired
|
13.9 KB |
sha256:f1953ae865756f1159dfc6fb5cf9e08eaff55787fbcac04a5e36fb5c1fd65551
|
|
|
docker-security-results
Expired
|
4.08 KB |
sha256:6e3b36543c04968e01d9c117d09e35b3d87e386565512e439e9aafde9fb2d6f2
|
|
|
gitleaks-results.sarif
Expired
|
8.96 KB |
sha256:cb80311f160af8dd5ceac3d84d6ac43cee13bd768051b5dffe5e5e091d2e2991
|
|