Skip to content

Add security plans for gh-aspnet-webapp and sample-web-app

cd91e2b
Select commit
Loading
Failed to load commit list.
Merged

Add security plans for gh-aspnet-webapp and sample-web-app #118

Add security plans for gh-aspnet-webapp and sample-web-app
cd91e2b
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Feb 5, 2026 in 3s

2 new alerts including 2 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 2 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 43 in .github/workflows/cicd.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'CI/CD for Azure Web App' step
Uses Step
uses 'azure/login' with ref 'v2', not a pinned commit hash

Check warning on line 52 in .github/workflows/cicd.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'CI/CD for Azure Web App' step
Uses Step
uses 'azure/webapps-deploy' with ref 'v3', not a pinned commit hash