service communication channels + filesystem - #127
Merged
Merged
Annotations
11 errors and 13 warnings
|
Gitleaks scan
🛑 GITHUB_TOKEN is now required to scan pull requests. You can use the automatically created token as shown in the [README](https://github.com/gitleaks/gitleaks-action#usage-example). For more info about the recent breaking update, see [here](https://github.com/gitleaks/gitleaks-action#-announcement).
|
|
ESLint security scan:
static/js/active-connections.js#L219
'd3' is not defined
|
|
ESLint security scan:
static/js/active-connections.js#L74
'd3' is not defined
|
|
ESLint security scan:
static/js/active-connections.js#L70
'debugLog' is not defined
|
|
ESLint security scan:
static/js/active-connections.js#L47
'debugLog' is not defined
|
|
ESLint security scan:
static/js/active-connections.js#L36
'debugLog' is not defined
|
|
ESLint security scan:
static/js/active-connections.js#L35
'debugLog' is not defined
|
|
ESLint security scan:
static/js/active-connections.js#L22
'debugLog' is not defined
|
|
ESLint security scan:
static/js/active-connections.js#L19
'debugLog' is not defined
|
|
ESLint security scan:
static/js/active-connections.js#L15
'debugLog' is not defined
|
|
ESLint security scan:
static/js/active-connections.js#L4
'debugLog' is not defined
|
|
Complete job
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/setup-node@v4, actions/setup-python@v5, actions/upload-artifact@v4, gitleaks/gitleaks-action@v2. Actions will be forced to run with Node.js 24 by default starting June 16th, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Post Trivy filesystem scan
Unexpected input(s) 'config', valid inputs are ['scan-type', 'image-ref', 'input', 'scan-ref', 'exit-code', 'ignore-unfixed', 'vuln-type', 'severity', 'format', 'template', 'output', 'skip-dirs', 'skip-files', 'cache-dir', 'timeout', 'ignore-policy', 'hide-progress', 'list-all-pkgs', 'scanners', 'trivyignores', 'github-pat', 'trivy-config', 'tf-vars', 'limit-severities-for-sarif', 'docker-host', 'version', 'cache', 'skip-setup-trivy', 'token-setup-trivy']
|
|
Trivy filesystem scan
Unexpected input(s) 'config', valid inputs are ['scan-type', 'image-ref', 'input', 'scan-ref', 'exit-code', 'ignore-unfixed', 'vuln-type', 'severity', 'format', 'template', 'output', 'skip-dirs', 'skip-files', 'cache-dir', 'timeout', 'ignore-policy', 'hide-progress', 'list-all-pkgs', 'scanners', 'trivyignores', 'github-pat', 'trivy-config', 'tf-vars', 'limit-severities-for-sarif', 'docker-host', 'version', 'cache', 'skip-setup-trivy', 'token-setup-trivy']
|
|
ESLint security scan:
static/js/crypto-belt.js#L1352
Function Call Object Injection Sink
|
|
ESLint security scan:
static/js/crypto-belt.js#L1337
Generic Object Injection Sink
|
|
ESLint security scan:
static/js/crypto-belt.js#L1337
Generic Object Injection Sink
|
|
ESLint security scan:
static/js/crypto-belt.js#L1336
Generic Object Injection Sink
|
|
ESLint security scan:
static/js/crypto-belt.js#L860
Generic Object Injection Sink
|
|
ESLint security scan:
static/js/crypto-belt.js#L860
Generic Object Injection Sink
|
|
ESLint security scan:
static/js/crypto-belt.js#L848
Generic Object Injection Sink
|
|
ESLint security scan:
static/js/crypto-belt.js#L848
Generic Object Injection Sink
|
|
ESLint security scan:
static/js/bezier_curves.js#L115
Generic Object Injection Sink
|
|
ESLint security scan:
static/js/active-connections.js#L152
Generic Object Injection Sink
|
background
wait
wait-all
cancel
parallel
Loading