Skip to content

Reorg repo

Reorg repo #21

Triggered via push December 8, 2025 12:53
Status Failure
Total duration 2m 27s
Artifacts
Secret Detection
9s
Secret Detection
Dependency Vulnerability Scan
8s
Dependency Vulnerability Scan
Semgrep SAST
2m 17s
Semgrep SAST
IaC Security Scan
37s
IaC Security Scan
Container Security
1m 16s
Container Security
Security Gate
3s
Security Gate
Fit to window
Zoom out
Zoom in

Annotations

15 errors and 4 warnings
Secret Detection
Process completed with exit code 1.
Secret Detection
BASE and HEAD commits are the same. TruffleHog won't scan anything. Please see documentation (https://github.com/trufflesecurity/trufflehog#octocat-trufflehog-github-action).
Dependency Vulnerability Scan
An error occurred trying to start process '/usr/bin/bash' with working directory '/home/runner/work/github-security-testbed/github-security-testbed/./NodeGoat'. No such file or directory
IaC Security Scan: lesson-05/demo-01-iac-templates/hardened/ec2-hardened.tf#L442
CKV_AWS_300: "Ensure S3 lifecycle configuration sets period for aborting failed uploads"
IaC Security Scan: lesson-05/demo-01-iac-templates/hardened/ec2-hardened.tf#L316
CKV_AWS_135: "Ensure that EC2 is EBS optimized"
IaC Security Scan: lesson-05/demo-01-iac-templates/hardened/ec2-hardened.tf#L118
CKV_AWS_24: "Ensure no security groups allow ingress from 0.0.0.0:0 to port 22"
IaC Security Scan: lesson-02/demo-04-zero-trust/terraform/main.tf#L504
CKV_AZURE_12: "Ensure that Network Security Group Flow Log retention period is 'greater than 90 days'"
IaC Security Scan: lesson-02/demo-04-zero-trust/terraform/main.tf#L470
CKV_AZURE_12: "Ensure that Network Security Group Flow Log retention period is 'greater than 90 days'"
IaC Security Scan: lesson-02/demo-04-zero-trust/terraform/main.tf#L436
CKV_AZURE_12: "Ensure that Network Security Group Flow Log retention period is 'greater than 90 days'"
IaC Security Scan: lesson-02/demo-04-zero-trust/terraform/main.tf#L120
CKV_AZURE_59: "Ensure that Storage accounts disallow public access"
IaC Security Scan: lesson-02/demo-04-zero-trust/terraform/main.tf#L120
CKV_AZURE_33: "Ensure Storage logging is enabled for Queue service for read, write and delete requests"
IaC Security Scan: lesson-02/demo-04-zero-trust/terraform/main.tf#L120
CKV_AZURE_190: "Ensure that Storage blobs restrict public access"
IaC Security Scan: lesson-02/demo-04-zero-trust/terraform/main.tf#L120
CKV_AZURE_206: "Ensure that Storage Accounts use replication"
Security Gate
Process completed with exit code 1.
Security Gate
Security gate failed - secrets detected in code
Dependency Vulnerability Scan
No files were found with the provided path: npm-audit-*.json. No artifacts will be uploaded.
IaC Security Scan
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Container Security
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Semgrep SAST
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/