Skip to content

Bump aquasecurity/tfsec-sarif-action from 0.1.0 to 0.1.4

c057366
Select commit
Loading
Failed to load commit list.
Merged

Bump aquasecurity/tfsec-sarif-action from 0.1.0 to 0.1.4 #47

Bump aquasecurity/tfsec-sarif-action from 0.1.0 to 0.1.4
c057366
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Apr 22, 2025 in 2s

1 new alert including 1 medium severity security vulnerability

New alerts in code changed by this pull request

Security Alerts:

  • 1 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 29 in .github/workflows/IACS-AquaSecurity-tfsec.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'IaC Scanning (Terraform) with Aqua Security tfsec' step
Uses Step
uses 'aquasecurity/tfsec-sarif-action' with ref 'v0.1.4', not a pinned commit hash