Skip to content

fix(frontend): resolve npm vulnerabilities for Trivy (picomatch, brac… #5

fix(frontend): resolve npm vulnerabilities for Trivy (picomatch, brac…

fix(frontend): resolve npm vulnerabilities for Trivy (picomatch, brac… #5

Triggered via pull request March 27, 2026 21:55
@xkd9xkd9
synchronize #1
develop
Status Success
Total duration 36s
Artifacts 2

code-scans.yaml

on: pull_request
Trivy Vulnerability Scan
32s
Trivy Vulnerability Scan
Bandit security scan
11s
Bandit security scan
Fit to window
Zoom out
Zoom in

Annotations

2 warnings
Bandit security scan
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/setup-python@v5, actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Trivy Vulnerability Scan
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/cache@0400d5f644dc74513175e3cd8d07132dd4860809, actions/checkout@v4, actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/

Artifacts

Produced during runtime
Name Size Digest
bandit-report
700 Bytes
sha256:d719010f91058801abf1c8902aca35c3c9d637f5b76c2c7c302af5a0009a78fe
trivy-report
466 Bytes
sha256:28f3da649ed744b407865358dca06b8383b2aa75736108bb6c997be6aa4a74ba