Dci demo #137
security.yml
on: pull_request
Secret Detection (Gitleaks)
15s
Dependency Scan
54s
Static Analysis (Semgrep)
2m 20s
API Auth Audit
9s
Container Scan (Trivy)
0s
Annotations
6 warnings
|
Secret Detection (Gitleaks)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|
|
Dependency Scan
pip-audit found vulnerabilities (see output above)
|
|
Dependency Scan
Fiona/GDAL excluded (require native GDAL/libgdal-dev build dependencies)
|
|
|
|
Dependency Scan
Skipping VCS/URL dependencies (cannot be audited):
|
|
Static Analysis (Semgrep)
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
|