Add note about advanced security #51
scan.yml
on: push
gosec
26s
govulncheck
20s
tfsec
23s
bandit
20s
chekov-terraform
27s
chekov-bicep
38s
codeql-go
37s
codeql-python
1m 49s
pip-audit
14s
Annotations
17 errors and 16 warnings
pip-audit
Process completed with exit code 1.
|
govulncheck
package slices is not in GOROOT (/opt/hostedtoolcache/go/1.19.0/x64/src/slices)
|
govulncheck
Process completed with exit code 1.
|
bandit
Process completed with exit code 1.
|
chekov-terraform
CKV_AWS_53: "Ensure S3 bucket has block public ACLS enabled"
|
chekov-terraform
CKV_AWS_56: "Ensure S3 bucket has 'restrict_public_buckets' enabled"
|
chekov-terraform
CKV_AWS_55: "Ensure S3 bucket has ignore public ACLs enabled"
|
chekov-terraform
CKV_AWS_54: "Ensure S3 bucket has block public policy enabled"
|
chekov-terraform
CKV2_AWS_62: "Ensure S3 buckets should have event notifications enabled"
|
chekov-terraform
CKV_AWS_21: "Ensure all data stored in the S3 bucket have versioning enabled"
|
chekov-terraform
CKV2_AWS_61: "Ensure that an S3 bucket has a lifecycle configuration"
|
chekov-terraform
CKV_AWS_18: "Ensure the S3 bucket has access logging enabled"
|
chekov-terraform
CKV_AWS_145: "Ensure that S3 buckets are encrypted with KMS by default"
|
chekov-terraform
CKV2_AWS_6: "Ensure that S3 bucket has a Public Access block"
|
chekov-bicep
CKV_AZURE_42: "Ensure the key vault is recoverable"
|
chekov-bicep
CKV_AZURE_189: "Ensure that Azure Key Vault disables public network access"
|
chekov-bicep
CKV_AZURE_109: "Ensure that key vault allows firewall rules settings"
|
pip-audit
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
|
govulncheck
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
|
bandit
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3, actions/setup-python@v4, github/codeql-action/upload-sarif@v2. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
|
bandit
CodeQL Action v2 will be deprecated on December 5th, 2024. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2024-01-12-code-scanning-deprecation-of-codeql-action-v2/
|
tfsec
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3, github/codeql-action/upload-sarif@v2. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
|
tfsec
CodeQL Action v2 will be deprecated on December 5th, 2024. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2024-01-12-code-scanning-deprecation-of-codeql-action-v2/
|
chekov-terraform
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3, github/codeql-action/upload-sarif@v2. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
|
gosec
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3, github/codeql-action/upload-sarif@v2. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
|
gosec
CodeQL Action v2 will be deprecated on December 5th, 2024. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2024-01-12-code-scanning-deprecation-of-codeql-action-v2/
|
chekov-terraform
CodeQL Action v2 will be deprecated on December 5th, 2024. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2024-01-12-code-scanning-deprecation-of-codeql-action-v2/
|
codeql-go
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3, github/codeql-action/init@v2, github/codeql-action/autobuild@v2, github/codeql-action/analyze@v2. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
|
codeql-go
CodeQL Action v2 will be deprecated on December 5th, 2024. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2024-01-12-code-scanning-deprecation-of-codeql-action-v2/
|
chekov-bicep
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3, github/codeql-action/upload-sarif@v2. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
|
chekov-bicep
CodeQL Action v2 will be deprecated on December 5th, 2024. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2024-01-12-code-scanning-deprecation-of-codeql-action-v2/
|
codeql-python
Node.js 16 actions are deprecated. Please update the following actions to use Node.js 20: actions/checkout@v3, github/codeql-action/init@v2, github/codeql-action/autobuild@v2, github/codeql-action/analyze@v2. For more information see: https://github.blog/changelog/2023-09-22-github-actions-transitioning-from-node-16-to-node-20/.
|
codeql-python
CodeQL Action v2 will be deprecated on December 5th, 2024. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2024-01-12-code-scanning-deprecation-of-codeql-action-v2/
|