Skip to content

ci: add ThreatCrush security scan #1

ci: add ThreatCrush security scan

ci: add ThreatCrush security scan #1

Triggered via pull request August 3, 2026 10:31
Status Success
Total duration 37s
Artifacts 1

threatcrush-scan.yml

on: pull_request
Scan for credentials and vulnerable patterns
27s
Scan for credentials and vulnerable patterns
Fit to window
Zoom out
Zoom in

Annotations

11 warnings and 1 notice
Scan for credentials and vulnerable patterns
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/github-script@v7, actions/setup-node@v4, actions/upload-artifact@v4, github/codeql-action/upload-sarif@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Scan for credentials and vulnerable patterns
Calculated fingerprint of 6b2454b1d27c1370:1 for file internal/mailclients/mailclients.go line 300, but found existing inconsistent fingerprint value threatcrush-generic-secret:internal/mailclients/mailclients.go:300
Scan for credentials and vulnerable patterns
Calculated fingerprint of 28a7d8e667e6cdfe:1 for file deploy/ergo/ircd.yaml line 1033, but found existing inconsistent fingerprint value threatcrush-generic-secret:deploy/ergo/ircd.yaml:1033
Scan for credentials and vulnerable patterns
Calculated fingerprint of 2f93bc75fea4ab55:1 for file deploy/ergo/ircd.yaml line 1025, but found existing inconsistent fingerprint value threatcrush-generic-secret:deploy/ergo/ircd.yaml:1025
Scan for credentials and vulnerable patterns
Calculated fingerprint of a34122fd0caf548b:1 for file deploy/ergo/ircd.yaml line 787, but found existing inconsistent fingerprint value threatcrush-generic-secret:deploy/ergo/ircd.yaml:787
Scan for credentials and vulnerable patterns
Calculated fingerprint of f73737dbf1678f6c:1 for file deploy/ergo/ircd.yaml line 772, but found existing inconsistent fingerprint value threatcrush-generic-secret:deploy/ergo/ircd.yaml:772
Scan for credentials and vulnerable patterns
Calculated fingerprint of bf56ee84035ed86b:1 for file deploy/ergo/ircd.yaml line 638, but found existing inconsistent fingerprint value threatcrush-generic-secret:deploy/ergo/ircd.yaml:638
Scan for credentials and vulnerable patterns
Calculated fingerprint of 753c9b736e87b272:1 for file deploy/ergo/ircd.yaml line 221, but found existing inconsistent fingerprint value threatcrush-generic-secret:deploy/ergo/ircd.yaml:221
Scan for credentials and vulnerable patterns
Calculated fingerprint of 174f2a6607bd8954:1 for file deploy/ergo/ircd.yaml line 162, but found existing inconsistent fingerprint value threatcrush-generic-secret:deploy/ergo/ircd.yaml:162
Scan for credentials and vulnerable patterns
Calculated fingerprint of 46b8cadcf0458a91:1 for file cmd/agentbbs/main.go line 1269, but found existing inconsistent fingerprint value threatcrush-generic-secret:cmd/agentbbs/main.go:1269
Scan for credentials and vulnerable patterns
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Scan for credentials and vulnerable patterns
CLI 0.2.2 predates --format; converting terminal output instead.

Artifacts

Produced during runtime
Name Size Digest
threatcrush-sarif
875 Bytes
sha256:11ea34b91bbc1bff985932728c783cddd37c0fa6d580c04afe79a43cf98c9041