Skip to content

Security Scanning

Security Scanning #81

Triggered via schedule February 16, 2026 03:07
Status Success
Total duration 9m 8s
Artifacts

security.yml

on: schedule
Secret Detection (Gitleaks)
17s
Secret Detection (Gitleaks)
Dependency Scan
52s
Dependency Scan
Static Analysis (Semgrep)
2m 22s
Static Analysis (Semgrep)
API Auth Audit
5s
API Auth Audit
Container Scan (Trivy)
9m 3s
Container Scan (Trivy)
Fit to window
Zoom out
Zoom in

Annotations

7 warnings
Secret Detection (Gitleaks)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Dependency Scan
pip-audit found vulnerabilities (see output above)
Dependency Scan
Fiona/GDAL excluded (require native GDAL/libgdal-dev build dependencies)
Dependency Scan
Skipping VCS/URL dependencies (cannot be audited):
Static Analysis (Semgrep)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Container Scan (Trivy)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/