Skip to content

ci: add ThreatCrush security scan #1

ci: add ThreatCrush security scan

ci: add ThreatCrush security scan #1

Triggered via pull request August 3, 2026 10:47
Status Success
Total duration 34s
Artifacts 1

threatcrush-scan.yml

on: pull_request
Scan for credentials and vulnerable patterns
29s
Scan for credentials and vulnerable patterns
Fit to window
Zoom out
Zoom in

Annotations

11 warnings and 1 notice
Scan for credentials and vulnerable patterns
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/github-script@v7, actions/setup-node@v4, actions/upload-artifact@v4, github/codeql-action/upload-sarif@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Scan for credentials and vulnerable patterns
Calculated fingerprint of 2a16d434e948164a:1 for file tests/nuclear-delete.test.js line 97, but found existing inconsistent fingerprint value threatcrush-generic-secret:tests/nuclear-delete.test.js:97
Scan for credentials and vulnerable patterns
Calculated fingerprint of 95c2fda588b999db:1 for file tests/nuclear-delete.test.js line 89, but found existing inconsistent fingerprint value threatcrush-generic-secret:tests/nuclear-delete.test.js:89
Scan for credentials and vulnerable patterns
Calculated fingerprint of a2d8ea535defec7c:1 for file tests/nuclear-delete.test.js line 19, but found existing inconsistent fingerprint value threatcrush-generic-secret:tests/nuclear-delete.test.js:19
Scan for credentials and vulnerable patterns
Calculated fingerprint of 38854a84ceae9889:1 for file tests/gpg-private-key-export.test.js line 64, but found existing inconsistent fingerprint value threatcrush-generic-secret:tests/gpg-private-key-export.test.js:64
Scan for credentials and vulnerable patterns
Calculated fingerprint of d157dcd825308f9e:1 for file tests/gpg-private-key-export.test.js line 63, but found existing inconsistent fingerprint value threatcrush-generic-secret:tests/gpg-private-key-export.test.js:63
Scan for credentials and vulnerable patterns
Calculated fingerprint of aabd23c2b71832b4:1 for file tests/debug-sms.js line 10, but found existing inconsistent fingerprint value threatcrush-jwt-token:tests/debug-sms.js:10
Scan for credentials and vulnerable patterns
Calculated fingerprint of e712725931797470:1 for file tests/chat-archive.test.js line 22, but found existing inconsistent fingerprint value threatcrush-generic-secret:tests/chat-archive.test.js:22
Scan for credentials and vulnerable patterns
Calculated fingerprint of 6757e7656df378b9:1 for file src/app/api/auth/upload-avatar/route.test.js line 27, but found existing inconsistent fingerprint value threatcrush-jwt-token:src/app/api/auth/upload-avatar/route.test.js:27
Scan for credentials and vulnerable patterns
Calculated fingerprint of a11e5512f8e935b5:1 for file debug-dev-server.js line 13, but found existing inconsistent fingerprint value threatcrush-generic-secret:debug-dev-server.js:13
Scan for credentials and vulnerable patterns
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
Scan for credentials and vulnerable patterns
CLI 0.2.2 predates --format; converting terminal output instead.

Artifacts

Produced during runtime
Name Size Digest
threatcrush-sarif
1.35 KB
sha256:3c339f719f631381aff1f9a5d8fb28fbc358bfa49d193c35da784adaa2ddf310