fix(deps): complete sha2 0.11 upgrade #7387
security-scan.yml Required
on: pull_request
Detect changed scope
5s
gitleaks (secret scan)
osv-scan
19s
dependency-review
13s
trivy-fs
23s
scorecard
13s
Annotations
5 warnings and 2 notices
|
OpenSSF Scorecard Warning
cargo/version_check has an OpenSSF Scorecard of 2.8, which is less than this repository's threshold of 3.
|
|
OpenSSF Scorecard Warning
cargo/codespan-reporting has an OpenSSF Scorecard of 1.9, which is less than this repository's threshold of 3.
|
|
OpenSSF Scorecard Warning
cargo/cfg_aliases has an OpenSSF Scorecard of 2.5, which is less than this repository's threshold of 3.
|
|
OpenSSF Scorecard Warning
cargo/bit-set has an OpenSSF Scorecard of 2.1, which is less than this repository's threshold of 3.
|
|
OpenSSF Scorecard Warning
cargo/allocator-api2 has an OpenSSF Scorecard of 2.5, which is less than this repository's threshold of 3.
|
|
Detect changed scope
changed-scope could not read a complete PR file list; scanning everything.
|
|
osv-scan
OSV hard gate scans direct manifest and lockfile evidence with --no-resolve so external transitive registry resolver stalls cannot hold the required-check queue indefinitely. The job is capped at 25 minutes; if this budget is exceeded, rerun after the upstream registry/service recovers or inspect the uploaded debug artifacts.
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
osv-scan-debug
|
1 KB |
sha256:7f30787f78479d0fcbca965372d0e908bb7a68ab0aaaf495000b8a5a6426fb9b
|
|