ci: add ThreatCrush security scan #1
threatcrush-scan.yml
on: pull_request
Scan for credentials and vulnerable patterns
29s
Annotations
11 warnings and 1 notice
|
Scan for credentials and vulnerable patterns
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/github-script@v7, actions/setup-node@v4, actions/upload-artifact@v4, github/codeql-action/upload-sarif@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Scan for credentials and vulnerable patterns
Calculated fingerprint of 2a16d434e948164a:1 for file tests/nuclear-delete.test.js line 97, but found existing inconsistent fingerprint value threatcrush-generic-secret:tests/nuclear-delete.test.js:97
|
|
Scan for credentials and vulnerable patterns
Calculated fingerprint of 95c2fda588b999db:1 for file tests/nuclear-delete.test.js line 89, but found existing inconsistent fingerprint value threatcrush-generic-secret:tests/nuclear-delete.test.js:89
|
|
Scan for credentials and vulnerable patterns
Calculated fingerprint of a2d8ea535defec7c:1 for file tests/nuclear-delete.test.js line 19, but found existing inconsistent fingerprint value threatcrush-generic-secret:tests/nuclear-delete.test.js:19
|
|
Scan for credentials and vulnerable patterns
Calculated fingerprint of 38854a84ceae9889:1 for file tests/gpg-private-key-export.test.js line 64, but found existing inconsistent fingerprint value threatcrush-generic-secret:tests/gpg-private-key-export.test.js:64
|
|
Scan for credentials and vulnerable patterns
Calculated fingerprint of d157dcd825308f9e:1 for file tests/gpg-private-key-export.test.js line 63, but found existing inconsistent fingerprint value threatcrush-generic-secret:tests/gpg-private-key-export.test.js:63
|
|
Scan for credentials and vulnerable patterns
Calculated fingerprint of aabd23c2b71832b4:1 for file tests/debug-sms.js line 10, but found existing inconsistent fingerprint value threatcrush-jwt-token:tests/debug-sms.js:10
|
|
Scan for credentials and vulnerable patterns
Calculated fingerprint of e712725931797470:1 for file tests/chat-archive.test.js line 22, but found existing inconsistent fingerprint value threatcrush-generic-secret:tests/chat-archive.test.js:22
|
|
Scan for credentials and vulnerable patterns
Calculated fingerprint of 6757e7656df378b9:1 for file src/app/api/auth/upload-avatar/route.test.js line 27, but found existing inconsistent fingerprint value threatcrush-jwt-token:src/app/api/auth/upload-avatar/route.test.js:27
|
|
Scan for credentials and vulnerable patterns
Calculated fingerprint of a11e5512f8e935b5:1 for file debug-dev-server.js line 13, but found existing inconsistent fingerprint value threatcrush-generic-secret:debug-dev-server.js:13
|
|
Scan for credentials and vulnerable patterns
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Scan for credentials and vulnerable patterns
CLI 0.2.2 predates --format; converting terminal output instead.
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
threatcrush-sarif
|
1.35 KB |
sha256:3c339f719f631381aff1f9a5d8fb28fbc358bfa49d193c35da784adaa2ddf310
|
|