Skip to content

Dependencies & Security #48

Dependencies & Security

Dependencies & Security #48

Triggered via schedule March 16, 2026 09:21
Status Failure
Total duration 58s
Artifacts 3

dependencies.yml

on: schedule
Vulnerability Scan
31s
Vulnerability Scan
License Compliance
46s
License Compliance
Dependency Analysis
25s
Dependency Analysis
Security Advisories
35s
Security Advisories
Update Dependencies
0s
Update Dependencies
Summary Report
4s
Summary Report
Fit to window
Zoom out
Zoom in

Annotations

10 errors and 5 warnings
Vulnerability Scan
cmd.main calls http.Server.ListenAndServe, which eventually calls tls.Conn.HandshakeContext
Vulnerability Scan
neo4j.Neo4jRepository.ExecuteQuery calls neo4j.session.Run, which eventually calls tls.Conn.Handshake
Vulnerability Scan
api.PerformanceHandlers.GetQueryMetrics calls url.URL.Query
Vulnerability Scan
cmd.main calls http.Server.ListenAndServe, which eventually calls url.ParseQuery
Vulnerability Scan
cmd.main calls http.Server.ListenAndServe, which eventually calls url.ParseRequestURI
Vulnerability Scan
neo4j.NewNeo4jClient calls neo4j.NewDriver, which calls url.Parse
Vulnerability Scan
cmd.main calls signal.Notify, which eventually calls os.ReadDir
Vulnerability Scan
cmd.main calls http.Server.ListenAndServe, which eventually calls os.File.Readdir
Vulnerability Scan
cmd.main calls http.Server.ListenAndServe, which eventually calls os.File.ReadDir
Vulnerability Scan
cmd.main calls http.Server.ListenAndServe, which eventually calls template.Template.Execute
Dependency Analysis
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/setup-go@v4, actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Vulnerability Scan
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/setup-go@v4, actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Vulnerability Scan
No files were found with the provided path: sbom.txt sbom.spdx.json sbom.syft.json. No artifacts will be uploaded.
Security Advisories
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/setup-go@v4, actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
License Compliance
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/setup-go@v4, actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/

Artifacts

Produced during runtime
Name Size Digest
dependency-analysis Expired
1.9 KB
sha256:df84f381a73f84f282f58176dc228ba232f8b4e9dcbae8694bb4376ff8584785
license-report
729 Bytes
sha256:88bdca1c223bbffe3a0b6f1456b65ac305a51dbce38f4d4eadb439d5161f8169
security-report
766 Bytes
sha256:6129c933fe838539ac9471206c9b93a42b411e5e2c17924a4e5574f879452e28