Skip to content

update: bump the gh-actions-packages group across 5 directories with … #78

update: bump the gh-actions-packages group across 5 directories with …

update: bump the gh-actions-packages group across 5 directories with … #78

Triggered via push November 22, 2024 11:27
Status Success
Total duration 6m 46s
Artifacts 4

push.yml

on: push
ci  /  conditionals
0s
ci / conditionals
ci  /  ...  /  context
5s
ci / build / context
ci  /  ...  /  ossf-scorecard
0s
ci / compliance / ossf-scorecard
ci  /  ...  /  dependency review
0s
ci / compliance / dependency review
ci  /  ...  /  check-commit-message
0s
ci / compliance / check-commit-message
ci  /  ...  /  unit tests
30s
ci / unit-test / unit tests
ci  /  ...  /  checkov
34s
ci / sast / checkov
ci  /  ...  /  codeql
3m 45s
ci / sast / codeql
ci  /  ...  /  golangci-lint
1m 40s
ci / sast / golangci-lint
ci  /  ...  /  gosec
2m 10s
ci / sast / gosec
ci  /  ...  /  hadolint
22s
ci / sast / hadolint
ci  /  ...  /  kubelinter
20s
ci / sast / kubelinter
ci  /  ...  /  semgrep
33s
ci / sast / semgrep
ci  /  ...  /  trivy config
45s
ci / sast / trivy config
ci  /  ...  /  deploy
13s
ci / docs / deploy
ci  /  ...  /  trivy image
30s
ci / sca / trivy image
ci  /  ...  /  grype
52s
ci / sca / grype
ci  /  ...  /  dependency review
19s
ci / sca / syft / dependency review
Matrix: ci / integration-test / functional
Matrix: ci / integration-test / k8s versions
Matrix: ci / integration-test / optional
Matrix: ci / integration-test / optional k8s versions
Matrix: ci / integration-test / self-hosted-notary
Fit to window
Zoom out
Zoom in

Annotations

10 errors and 2 warnings
ci / sast / checkov: deployment/deployment.yaml#L286
CKV_K8S_38: "Ensure that Service Account Tokens are only mounted where necessary"
ci / sast / checkov: deployment/deployment.yaml#L286
CKV_K8S_35: "Prefer using secrets as files over secrets as environment variables"
ci / sast / checkov: deployment/deployment.yaml#L286
CKV_K8S_43: "Image should use digest"
ci / sast / checkov: deployment/deployment.yaml#L286
CKV_K8S_15: "Image Pull Policy should be Always"
ci / sast / checkov: deployment/deployment.yaml#L410
CKV_K8S_35: "Prefer using secrets as files over secrets as environment variables"
ci / sast / checkov: deployment/deployment.yaml#L410
CKV_K8S_43: "Image should use digest"
ci / sast / checkov: deployment/deployment.yaml#L410
CKV_K8S_40: "Containers should run as a high UID to avoid host conflict"
ci / sast / checkov: deployment/deployment.yaml#L286
CKV2_K8S_6: "Minimize the admission of pods which lack an associated NetworkPolicy"
ci / sast / checkov: deployment/deployment.yaml#L410
CKV2_K8S_6: "Minimize the admission of pods which lack an associated NetworkPolicy"
ci / sast / checkov: deployment/deployment.yaml#L219
CKV2_K8S_5: "No ServiceAccount/Node should be able to read all secrets"
ci / unit-test / unit tests
The following actions use a deprecated Node.js version and will be forced to run on node20: codecov/codecov-action@eaaf4bedf32dbdc6b720b63067d99c4d77d6047d. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
ci / sast / trivy config
Uploading multiple SARIF runs with the same category is deprecated and will be removed on June 4, 2025. Please update your workflow to upload a single run per category. For more information, see https://github.blog/changelog/2024-05-06-code-scanning-will-stop-combining-runs-from-a-single-upload

Artifacts

Produced during runtime
Name Size
cosign.pub
287 Bytes
sbom.cdx
32 KB
sse-secure-systems-connaisseur_sha-a2095dd.cyclonedx.json
32.1 KB
sse-secure-systems~connaisseur~QVSFVJ.dockerbuild
47.1 KB