Skip to content

chore(deps): update bridgecrewio/checkov-action digest to 9201a8e #2055

chore(deps): update bridgecrewio/checkov-action digest to 9201a8e

chore(deps): update bridgecrewio/checkov-action digest to 9201a8e #2055

Triggered via pull request April 30, 2026 15:02
Status Success
Total duration 2m 49s
Artifacts 9

scans.yml

on: pull_request
Fit to window
Zoom out
Zoom in

Annotations

6 warnings
gitleaks
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: gitleaks/gitleaks-action@ff98106e4c7b2bc287b24eaf42907196329070c7. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L36
When installing a package, its pin version should be defined
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L46
When installing a package, its pin version should be defined
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L94
When installing a package, its pin version should be defined
[MEDIUM] Apt Get Install Pin Version Not Defined: Dockerfile#L94
When installing a package, its pin version should be defined
msdo
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: microsoft/security-devops-action@08976cb623803b1b36d7112d4ff9f59eae704de0. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/

Artifacts

Produced during runtime
Name Size Digest
OSV Scanner SARIF file Expired
589 Bytes
sha256:7be1af86257c66414d394f4caa50981811392524ccf3ffa791b822bb0b98663b
gitleaks-results.sarif
6.64 KB
sha256:e881eaf809a4abf4ed7b7e34f36def14d5eab34da533f61495517255189d2349
megalinter-reports
693 KB
sha256:3b1e5846f187ab1e1b8e159ed80e2131e556c12344fdc54f52920d36e33453ee
new-json-results Expired
241 Bytes
sha256:bcd864475d705f0fb1e0881b498bafda0fa386f825fc3650bb0c2b4e2b102e9c
old-json-results Expired
241 Bytes
sha256:d407ef9844b5ac69b543972266c18f98fa1ae1f62f1a4dfcae1e98f00238e4a5
python-example-app-syft.spdx.json
17.8 KB
sha256:541b0093ffa37bbac84577b42a10c65763003ed9dfe0bed7d3919cce2f641523
yxtay~python-example-app~CER6FS.dockerbuild
20 KB
sha256:85c87707a2bc0901e2003b0339560143be9cc029df92cca36652798d65c8f126
yxtay~python-example-app~KFJTEK.dockerbuild
19.9 KB
sha256:4d02752a53903419d016f9c148415b6a6d2ef6a989055d4983cb1955a3ad129c
yxtay~python-example-app~KK7IP3.dockerbuild
20.3 KB
sha256:78855470f28f1ebd5a6e1ea456e3d8e509e3c11f22a191242dd251fca803a9fc