ci: add ThreatCrush security scan #1
threatcrush-scan.yml
on: pull_request
Scan for credentials and vulnerable patterns
30s
Annotations
3 warnings and 1 notice
|
Scan for credentials and vulnerable patterns
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/github-script@v7, actions/setup-node@v4, actions/upload-artifact@v4, github/codeql-action/upload-sarif@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Scan for credentials and vulnerable patterns
Calculated fingerprint of 1cb09cd227b7930:1 for file services/api/src/store/payments.test.ts line 11, but found existing inconsistent fingerprint value threatcrush-generic-secret:services/api/src/store/payments.test.ts:11
|
|
Scan for credentials and vulnerable patterns
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Scan for credentials and vulnerable patterns
CLI 0.2.2 predates --format; converting terminal output instead.
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
threatcrush-sarif
|
716 Bytes |
sha256:19f2472ead8d832e51face4fd4952112e4b2fb871d9b708d58321b56f5d93fdb
|
|