Merge pull request #74 from OpenSPP/improve/spp-simulation #247
security.yml
on: push
Secret Detection (Gitleaks)
14s
Dependency Scan
40s
Static Analysis (Semgrep)
2m 27s
API Auth Audit
6s
Container Scan (Trivy)
8m 51s
Annotations
7 warnings
|
Secret Detection (Gitleaks)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Dependency Scan
pip-audit found vulnerabilities (see output above)
|
|
Dependency Scan
Fiona/GDAL excluded (require native GDAL/libgdal-dev build dependencies)
|
|
|
|
Dependency Scan
Skipping VCS/URL dependencies (cannot be audited):
|
|
Static Analysis (Semgrep)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Container Scan (Trivy)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|