Skip to content

πŸ”’ Security Scanning #69

πŸ”’ Security Scanning

πŸ”’ Security Scanning #69

Triggered via schedule August 24, 2025 02:40
Status Failure
Total duration 4m 16s
Artifacts 3

security.yml

on: schedule
πŸ” Dependency Scan
1m 47s
πŸ” Dependency Scan
πŸ” Code Security Analysis
2m 54s
πŸ” Code Security Analysis
πŸ” Secret Scanning
13s
πŸ” Secret Scanning
🐳 Docker Security
4m 2s
🐳 Docker Security
πŸ—οΈ Infrastructure Security
6s
πŸ—οΈ Infrastructure Security
πŸ“Š Security Summary
6s
πŸ“Š Security Summary
Fit to window
Zoom out
Zoom in

Annotations

8 errors and 25 warnings
πŸ” Dependency Scan
Process completed with exit code 1.
πŸ” Code Security Analysis
Path does not exist: semgrep.sarif
🐳 Docker Security
Path does not exist: scout-frontend-results.sarif
🐳 Docker Security
Path does not exist: scout-backend-results.sarif
🐳 Docker Security
Path does not exist: trivy-fs-results.sarif
🐳 Docker Security
Aborting upload: only one run of the codeql/analyze or codeql/upload-sarif actions is allowed per job per tool/category. The easiest fix is to specify a unique value for the `category` input. If .runs[].automationDetails.id is specified in the sarif file, that will take precedence over your configured `category`. Category: (.github/workflows/security.yml:docker-security/) Tool: (Trivy)
🐳 Docker Security
Resource not accessible by integration - https://docs.github.com/rest
πŸ“Š Security Summary
Unhandled error: HttpError: Resource not accessible by integration
πŸ—οΈ Infrastructure Security
No files were found with the provided path: k8s-security-scan.json k8s-issues.json infra-security-summary.md. No artifacts will be uploaded.
πŸ” Secret Scanning
πŸ›‘ Leaks detected, see job summary for details
πŸ” Dependency Scan
No files were found with the provided path: dependency-scan.log npm-audit.json security-summary.md. No artifacts will be uploaded.
πŸ” Code Security Analysis
Unexpected input(s) 'publishDeployment', 'generateSarif', valid inputs are ['entryPoint', 'args', 'config', 'publishToken']
πŸ” Code Security Analysis: backend/ModernAPI.Application/Services/ETagService.cs#L204
Missing XML comment for publicly visible type or member 'ETagService.CheckIfMatch(string?, string)'
πŸ” Code Security Analysis: backend/ModernAPI.Application/Services/ETagService.cs#L174
Missing XML comment for publicly visible type or member 'ETagService.CheckIfNoneMatch(string?, string)'
πŸ” Code Security Analysis: backend/ModernAPI.Application/Services/ETagService.cs#L152
Missing XML comment for publicly visible type or member 'ETagService.ParseETagHeader(string?)'
πŸ” Code Security Analysis: backend/ModernAPI.Application/Services/ETagService.cs#L147
Missing XML comment for publicly visible type or member 'ETagService.ValidateETag(string?, UserDto)'
πŸ” Code Security Analysis: backend/ModernAPI.Application/Services/ETagService.cs#L135
Missing XML comment for publicly visible type or member 'ETagService.ValidateETag(string?, Guid, DateTime)'
πŸ” Code Security Analysis: backend/ModernAPI.Application/Services/ETagService.cs#L129
Missing XML comment for publicly visible type or member 'ETagService.GenerateCollectionETag(IEnumerable<UserDto>)'
πŸ” Code Security Analysis: backend/ModernAPI.Application/Services/ETagService.cs#L111
Missing XML comment for publicly visible type or member 'ETagService.GenerateCollectionETag(IEnumerable<(Guid Id, DateTime LastModified)>)'
πŸ” Code Security Analysis: backend/ModernAPI.Application/Services/ETagService.cs#L106
Missing XML comment for publicly visible type or member 'ETagService.GenerateETag(UserDto)'
πŸ” Code Security Analysis: backend/ModernAPI.Application/Services/ETagService.cs#L93
Missing XML comment for publicly visible type or member 'ETagService.GenerateETag(Guid, DateTime)'
πŸ” Code Security Analysis: backend/ModernAPI.Application/Services/AuthService.cs#L23
Missing XML comment for publicly visible type or member 'AuthService.AuthService(UserManager<User>, IPasswordService, IJwtTokenService, IUnitOfWork, ILogger<AuthService>)'
🐳 Docker Security
Resource not accessible by integration - https://docs.github.com/rest
🐳 Docker Security
Resource not accessible by integration - https://docs.github.com/rest
🐳 Docker Security
Resource not accessible by integration - https://docs.github.com/rest
🐳 Docker Security
Resource not accessible by integration - https://docs.github.com/rest
🐳 Docker Security
Resource not accessible by integration - https://docs.github.com/rest
🐳 Docker Security
Resource not accessible by integration - https://docs.github.com/rest
🐳 Docker Security
Resource not accessible by integration - https://docs.github.com/rest
🐳 Docker Security
Resource not accessible by integration - https://docs.github.com/rest
🐳 Docker Security
Resource not accessible by integration - https://docs.github.com/rest
🐳 Docker Security
Resource not accessible by integration - https://docs.github.com/rest
🐳 Docker Security
Resource not accessible by integration - https://docs.github.com/rest

Artifacts

Produced during runtime
Name Size Digest
comprehensive-security-report Expired
13.8 KB
sha256:5f5a777bcc8a4a4ff08f93f2f2b11aa4bc9e9a8575a651991a71f1f9de46c6dc
docker-security-results Expired
4.08 KB
sha256:75f196a263378f5ace05520866aa4e468aa2ed9f60d9b4b1a540290995a723b9
gitleaks-results.sarif Expired
8.94 KB
sha256:88915f9702b259882887f2579c209d420a87a15dca5bf35a3611cbf2e6588ae4