Feat: Prune unused tool definitions from inference requests #1193
security-scans.yaml
on: pull_request
Dependency Review
4s
Shell Script Lint
11s
YAML Lint
8s
Python Security (Bandit)
11s
Dockerfile Lint (Hadolint)
13s
Trivy Filesystem Scan
27s
Verify Action Pinning
7s
Matrix: codeql
Annotations
10 warnings
|
Verify Action Pinning
Found actions not pinned to SHA commits:
|
|
YAML Lint:
.github/workflows/build.yaml#L122
122:151 [line-length] line too long (189 > 150 characters)
|
|
YAML Lint:
.github/workflows/release-binaries.yaml#L77
77:151 [line-length] line too long (168 > 150 characters)
|
|
Dockerfile Lint (Hadolint):
authbridge/cmd/authbridge-proxy/Dockerfile#L36
Use WORKDIR to switch to a directory
|
|
Dockerfile Lint (Hadolint):
authbridge/cmd/authbridge-praxis/Dockerfile#L182
Use WORKDIR to switch to a directory
|
|
Dockerfile Lint (Hadolint):
authbridge/cmd/authbridge-envoy/Dockerfile#L28
Use WORKDIR to switch to a directory
|
|
Dockerfile Lint (Hadolint):
authbridge/cmd/authbridge-cpex/Dockerfile#L144
Use WORKDIR to switch to a directory
|
|
Dockerfile Lint (Hadolint):
authbridge/cmd/authbridge-cpex/Dockerfile#L61
Set the SHELL option -o pipefail before RUN with a pipe in it. If you are using /bin/sh in an alpine image or if your shell is symlinked to busybox then consider explicitly setting your SHELL to /bin/ash, or disable this check
|
|
CodeQL Analysis (go)
1 issue was detected with this workflow: Please specify an on.push hook to analyze and see code scanning alerts from the default branch on the Security tab.
|
|
CodeQL Analysis (python)
1 issue was detected with this workflow: Please specify an on.push hook to analyze and see code scanning alerts from the default branch on the Security tab.
|