Skip to content

ML stages

ML stages #211

Triggered via pull request August 7, 2026 14:24
Status Success
Total duration 1m 15s
Artifacts 2

security.yaml

on: pull_request
Fit to window
Zoom out
Zoom in

Annotations

11 errors and 13 warnings
security
🛑 GITHUB_TOKEN is now required to scan pull requests. You can use the automatically created token as shown in the [README](https://github.com/gitleaks/gitleaks-action#usage-example). For more info about the recent breaking update, see [here](https://github.com/gitleaks/gitleaks-action#-announcement).
security: static/js/active-connections.js#L233
'd3' is not defined
security: static/js/active-connections.js#L74
'd3' is not defined
security: static/js/active-connections.js#L70
'debugLog' is not defined
security: static/js/active-connections.js#L47
'debugLog' is not defined
security: static/js/active-connections.js#L36
'debugLog' is not defined
security: static/js/active-connections.js#L35
'debugLog' is not defined
security: static/js/active-connections.js#L22
'debugLog' is not defined
security: static/js/active-connections.js#L19
'debugLog' is not defined
security: static/js/active-connections.js#L15
'debugLog' is not defined
security: static/js/active-connections.js#L4
'debugLog' is not defined
security
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-node@v4, actions/setup-python@v5, actions/upload-artifact@v4, gitleaks/gitleaks-action@v2. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
security
Unexpected input(s) 'config', valid inputs are ['scan-type', 'image-ref', 'input', 'scan-ref', 'exit-code', 'ignore-unfixed', 'vuln-type', 'severity', 'format', 'template', 'output', 'skip-dirs', 'skip-files', 'cache-dir', 'timeout', 'ignore-policy', 'hide-progress', 'list-all-pkgs', 'scanners', 'trivyignores', 'github-pat', 'trivy-config', 'tf-vars', 'limit-severities-for-sarif', 'docker-host', 'version', 'cache', 'skip-setup-trivy', 'token-setup-trivy']
security
Unexpected input(s) 'config', valid inputs are ['scan-type', 'image-ref', 'input', 'scan-ref', 'exit-code', 'ignore-unfixed', 'vuln-type', 'severity', 'format', 'template', 'output', 'skip-dirs', 'skip-files', 'cache-dir', 'timeout', 'ignore-policy', 'hide-progress', 'list-all-pkgs', 'scanners', 'trivyignores', 'github-pat', 'trivy-config', 'tf-vars', 'limit-severities-for-sarif', 'docker-host', 'version', 'cache', 'skip-setup-trivy', 'token-setup-trivy']
security: static/js/aes-ref.js#L153
Generic Object Injection Sink
security: static/js/aes-ref.js#L151
Generic Object Injection Sink
security: static/js/aes-ref.js#L151
Generic Object Injection Sink
security: static/js/aes-ref.js#L118
Generic Object Injection Sink
security: static/js/aes-ref.js#L110
Function Call Object Injection Sink
security: static/js/aes-ref.js#L75
Generic Object Injection Sink
security: static/js/aes-ref.js#L74
Generic Object Injection Sink
security: static/js/aes-ref.js#L63
Generic Object Injection Sink
security: static/js/aes-ref.js#L60
Generic Object Injection Sink
security: static/js/active-connections.js#L166
Generic Object Injection Sink

Artifacts

Produced during runtime
Name Size Digest
bandit-report
1.43 KB
sha256:36d5035d75ec038d41c22fea0193ec69ca698823f46c7108928696919500235c
pip-audit-report
9.05 KB
sha256:e5e977d0cc76d5f2df4b5a6fa2fca5ef16310fc1c5532074a5c20c972846a2a2