chore(ci): supply-chain security workflow (per quantcli/common QUA-7) #1
security.yml
on: pull_request
govulncheck (Go vuln DB)
42s
osv-scanner (transitive vulns)
1m 46s
license policy (allowlist)
42s
Annotations
15 errors and 3 warnings
|
govulncheck (Go vuln DB)
cronoclient.NewLoggedIn calls gocronometer.Client.Login, which eventually calls url.Parse
|
|
govulncheck (Go vuln DB)
cronoclient.NewLoggedIn calls os.Getenv, which eventually calls os.ReadDir
|
|
govulncheck (Go vuln DB)
cronoclient.Client.Notes calls gocronometer.Client.ExportNotes, which eventually calls tls.Dialer.DialContext
|
|
govulncheck (Go vuln DB)
cronoclient.Client.Notes calls gocronometer.Client.ExportNotes, which eventually calls tls.Conn.Write
|
|
govulncheck (Go vuln DB)
cronoclient.Client.Notes calls gocronometer.Client.ExportNotes, which eventually calls tls.Conn.Read
|
|
govulncheck (Go vuln DB)
cronoclient.Client.Notes calls gocronometer.Client.ExportNotes, which eventually calls tls.Conn.HandshakeContext
|
|
govulncheck (Go vuln DB)
cronoclient.Client.Notes calls gocronometer.Client.ExportNotes, which calls http.Client.Do
|
|
govulncheck (Go vuln DB)
cronoclient.Client.Notes calls gocronometer.Client.ExportNotes, which eventually calls x509.Certificate.Verify
|
|
govulncheck (Go vuln DB)
cronoclient.Client.Notes calls gocronometer.Client.ExportNotes, which eventually calls x509.Certificate.Verify
|
|
govulncheck (Go vuln DB)
cronoclient.Client.Notes calls gocronometer.Client.ExportNotes, which eventually calls net.Dialer.DialContext
|
|
license policy (allowlist)
Process completed with exit code 1.
|
|
license policy (allowlist)
See quantcli/common SECURITY.md for the policy and how to request an exception.
|
|
license policy (allowlist)
License policy violated. Allowlist: Apache-2.0,MIT,BSD-2-Clause,BSD-3-Clause,MPL-2.0,ISC,Unlicense
|
|
license policy (allowlist)
Disallowed license: module=github.com/jrmycanady/gocronometer license=GPL-2.0
|
|
osv-scanner (transitive vulns)
Process completed with exit code 1.
|
|
govulncheck (Go vuln DB)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
license policy (allowlist)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
osv-scanner (transitive vulns)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/setup-go@44694675825211faa026b3c33043df3e48a5fa00. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|