feat: use go-spiffe SDK directly instead of spiffe-helper sidecar #731
security-scans.yaml
on: pull_request
Dependency Review
7s
Shell Script Lint
11s
YAML Lint
15s
Helm Chart Lint
10s
Dockerfile Lint (Hadolint)
13s
Trivy Filesystem Scan
15s
CodeQL Analysis (Go)
4m 47s
Verify Action Pinning
5s
Annotations
9 warnings
|
Verify Action Pinning
Found actions not pinned to SHA commits:
|
|
YAML Lint:
charts/operator/crds/agent.rossoctl.dev_authorizationpolicies.yaml#L111
111:151 [line-length] line too long (162 > 150 characters)
|
|
YAML Lint:
charts/operator/crds/agent.rossoctl.dev_authorizationpolicies.yaml#L99
99:151 [line-length] line too long (162 > 150 characters)
|
|
YAML Lint:
charts/operator/crds/agent.rossoctl.dev_agentcards.yaml#L399
399:151 [line-length] line too long (162 > 150 characters)
|
|
YAML Lint:
charts/operator/crds/agent.rossoctl.dev_agentcards.yaml#L387
387:151 [line-length] line too long (162 > 150 characters)
|
|
YAML Lint:
charts/operator/crds/agent.rossoctl.dev_agentruntimes.yaml#L500
500:151 [line-length] line too long (162 > 150 characters)
|
|
YAML Lint:
charts/operator/crds/agent.rossoctl.dev_agentruntimes.yaml#L488
488:151 [line-length] line too long (162 > 150 characters)
|
|
YAML Lint:
.github/workflows/project.yml#L23
23:1 [empty-lines] too many blank lines (1 > 0)
|
|
CodeQL Analysis (Go)
1 issue was detected with this workflow: Please specify an on.push hook to analyze and see code scanning alerts from the default branch on the Security tab.
|