Skip to content

fix(build): remediate CVEs, enforce equality pinning, repair Dependabot config #532

fix(build): remediate CVEs, enforce equality pinning, repair Dependabot config

fix(build): remediate CVEs, enforce equality pinning, repair Dependabot config #532

Triggered via pull request April 5, 2026 01:07
Status Failure
Total duration 2m 59s
Artifacts 16

pr-validation.yml

on: pull_request
Spell Check  /  Spell Check
21s
Spell Check / Spell Check
Markdown Lint  /  Markdown Lint
15s
Markdown Lint / Markdown Lint
Table Format  /  Table Format Check
16s
Table Format / Table Format Check
Frontmatter Validation  /  Validate Markdown Frontmatter
20s
Frontmatter Validation / Validate Markdown Frontmatter
ms.date Freshness Check  /  Check ms.date Freshness
15s
ms.date Freshness Check / Check ms.date Freshness
PSScriptAnalyzer  /  PSScriptAnalyzer
16s
PSScriptAnalyzer / PSScriptAnalyzer
YAML Lint  /  actionlint
12s
YAML Lint / actionlint
Link Language Check  /  Link Language Check
12s
Link Language Check / Link Language Check
Markdown Link Check  /  Check Markdown Links
10s
Markdown Link Check / Check Markdown Links
Dependency Review  /  Review Dependencies
42s
Dependency Review / Review Dependencies
Dependency Pinning  /  Validate SHA Pinning Compliance
22s
Dependency Pinning / Validate SHA Pinning Compliance
Dataviewer Frontend Tests  /  Lint, Type-check, Test and Build
1m 14s
Dataviewer Frontend Tests / Lint, Type-check, Test and Build
Pytest Tests  /  Pytest
2m 54s
Pytest Tests / Pytest
Dataviewer Backend Pytest  /  Pytest Dataviewer Backend
1m 3s
Dataviewer Backend Pytest / Pytest Dataviewer Backend
Python Lint  /  Ruff Lint and Format Check
12s
Python Lint / Ruff Lint and Format Check
Terraform Lint  /  TFLint
17s
Terraform Lint / TFLint
Terraform Validation  /  Terraform Validation
11s
Terraform Validation / Terraform Validation
Terraform Tests  /  Terraform Tests
13s
Terraform Tests / Terraform Tests
Go Lint  /  Go Lint
23s
Go Lint / Go Lint
Go Tests  /  Go Tests
25s
Go Tests / Go Tests
Matrix: CodeQL Analysis / CodeQL Analysis
Matrix: Pester Tests / pester
Fit to window
Zoom out
Zoom in

Annotations

12 errors, 32 warnings, and 1 notice
Dependency Pinning / Validate SHA Pinning Compliance
Process completed with exit code 1.
Dependency Review / Review Dependencies
Dependency review detected vulnerable packages.
Pester Tests / PowerShell Tests (ubuntu-latest)
actionlint found 1 error(s). Fix the issues above.
Pester Tests / PowerShell Tests (ubuntu-latest)
actionlint found 2 error(s). Fix the issues above.
Pester Tests / PowerShell Tests (ubuntu-latest)
actionlint found 1 error(s). Fix the issues above.
Pester Tests / PowerShell Tests (ubuntu-latest)
actionlint found 1 error(s). Fix the issues above.
Pester Tests / PowerShell Tests (ubuntu-latest)
tflint is not installed or not in PATH
ms.date Freshness Check / Check ms.date Freshness
No files were found with the provided path: logs/msdate-freshness-results.json. No artifacts will be uploaded.
PSScriptAnalyzer / PSScriptAnalyzer
No files were found with the provided path: logs/. No artifacts will be uploaded.
Frontmatter Validation / Validate Markdown Frontmatter
No files were found with the provided path: logs/frontmatter-validation-results.json. No artifacts will be uploaded.
Dependency Pinning / Validate SHA Pinning Compliance: evaluation/sil/docker/requirements-lerobot-eval.txt#L9
Unpinned pip dependency: av@>=14.0.0,<17.0.0 (Severity: warning)
Dependency Pinning / Validate SHA Pinning Compliance: evaluation/sil/docker/requirements-lerobot-eval.txt#L8
Unpinned pip dependency: mlflow@>=2.8.0,<4.0.0 (Severity: warning)
Dependency Pinning / Validate SHA Pinning Compliance: evaluation/sil/docker/requirements-lerobot-eval.txt#L7
Unpinned pip dependency: azureml-mlflow@>=1.59.0,<2.0.0 (Severity: warning)
Dependency Pinning / Validate SHA Pinning Compliance: evaluation/sil/docker/requirements-lerobot-eval.txt#L6
Unpinned pip dependency: matplotlib@>=3.10.0,<4.0.0 (Severity: warning)
Dependency Pinning / Validate SHA Pinning Compliance: evaluation/sil/docker/requirements-lerobot-eval.txt#L5
Unpinned pip dependency: azure-ai-ml@>=1.24.0,<2.0.0 (Severity: warning)
Dependency Pinning / Validate SHA Pinning Compliance: evaluation/sil/docker/requirements-lerobot-eval.txt#L4
Unpinned pip dependency: azure-identity@>=1.21.0,<2.0.0 (Severity: warning)
Dependency Pinning / Validate SHA Pinning Compliance: evaluation/sil/docker/requirements-lerobot-eval.txt#L3
Unpinned pip dependency: azure-storage-blob@>=12.24.0,<13.0.0 (Severity: warning)
Dependency Pinning / Validate SHA Pinning Compliance: evaluation/sil/docker/requirements-lerobot-eval.txt#L2
Unpinned pip dependency: pyarrow@>=19.0.0,<24.0.0 (Severity: warning)
Dependency Pinning / Validate SHA Pinning Compliance: evaluation/sil/docker/requirements-lerobot-eval.txt#L1
Unpinned pip dependency: lerobot@>=0.3.0,<0.5.0 (Severity: warning)
Dependency Pinning / Validate SHA Pinning Compliance: data-management/viewer/pyproject.toml#L51
Unpinned pip dependency: datasetanalysistool@[dev,azure,huggingface,hdf5,export] (Severity: warning)
Dependency Review / Review Dependencies
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/dependency-review-action@2031cfc080254a8a887f58cffee85186f0e49e48. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
OpenSSF Scorecard Warning
npm/react-loadable-ssr-addon-v5-slorber has an OpenSSF Scorecard of 2.7, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/jake has an OpenSSF Scorecard of 2.6, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/cookie-signature has an OpenSSF Scorecard of 2.3, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/lucide-react has an OpenSSF Scorecard of 2.8, which is less than this repository's threshold of 3.
OpenSSF Scorecard Warning
npm/idb has an OpenSSF Scorecard of 2.6, which is less than this repository's threshold of 3.
Dataviewer Frontend Tests / Lint, Type-check, Test and Build: data-management/viewer/frontend/src/main.tsx#L36
Fast refresh only works when a file has exports. Move your component(s) to a separate file
Dataviewer Frontend Tests / Lint, Type-check, Test and Build: data-management/viewer/frontend/src/components/annotation-workspace/useAnnotationWorkspaceVideoSync.ts#L100
React Hook useCallback has an unnecessary dependency: 'fps'. Either exclude it or remove the dependency array
Dataviewer Frontend Tests / Lint, Type-check, Test and Build: data-management/viewer/frontend/src/components/annotation-workspace/AnnotationWorkspacePlaybackCard.tsx#L116
React Hook useEffect has a missing dependency: 'frameImageUrl'. Either include it or remove the dependency array
CodeQL Analysis / CodeQL Analysis (python)
Starting April 2026, the CodeQL Action will skip computing file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. To opt out of this change, set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true`. Alternatively, create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository's settings.
CodeQL Analysis / CodeQL Analysis (python)
1 issue was detected with this workflow: Please specify an on.push hook to analyze and see code scanning alerts from the default branch on the Security tab.
CodeQL Analysis / CodeQL Analysis (javascript-typescript)
Starting April 2026, the CodeQL Action will skip computing file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. To opt out of this change, set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true`. Alternatively, create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository's settings.
CodeQL Analysis / CodeQL Analysis (javascript-typescript)
1 issue was detected with this workflow: Please specify an on.push hook to analyze and see code scanning alerts from the default branch on the Security tab.
Pytest Tests / Pytest
Failed to save: Unable to reserve cache with key setup-uv-2-x86_64-unknown-linux-gnu-ubuntu-24.04-unknown-pruned-b501651745abdb534f279ecec728252dbdc70ebcaf6e5b9eab0535e38a38c710, another job may be creating this cache.
Pester Tests / PowerShell Tests (ubuntu-latest)
No changed markdown files detected

Artifacts

Produced during runtime
Name Size Digest
coverage-report-ubuntu-latest
14.1 KB
sha256:ef881c517c2bff75af89eace4bf9da4a71e4eb98353d5c48c21248a2d251b214
dependency-pinning-results
973 Bytes
sha256:67795c1b75e41e2d09e936088f4624c84489c17fdff20fece96a808f589567ba
go-lint-results
291 Bytes
sha256:633b17a92c50399c52543e0d5106c3f744934d3438c4fcbb36f82985f0b54188
go-test-results
314 Bytes
sha256:b20148f9e73255a1592d17458e24630b784bf503bfac21877373b86a855c66ce
link-lang-check-results
303 Bytes
sha256:f0927ee95de418654847a9e043f7a92357a15744f36e3ad774a4c4fd0ea7f2cd
pester-results-ubuntu-latest
34.2 KB
sha256:5ed1be3cfacc336a2ac2ffbd6b3a0beecb8efb58db980ef37e79d0301f9dbaa6
pytest-coverage-xml
2.76 KB
sha256:f9726acbaa96409ad207ad92f04df30d47a08e4ea201d337395ca9c53e375db3
pytest-dataviewer-coverage-xml
11.6 KB
sha256:990d6fa71748b84e0d877bae6ef9a97a60e29f7e22481fc455b77710aa0e9dc1
python-lint-results
390 Bytes
sha256:c4988e8500bd7f2b5b9f25a670fe465f6882bcb196da6f7da033f323ef415c7c
spell-check-results
7.78 KB
sha256:c2bc3ac5613f6e0525fa3a2dfb48d7b06a1bfc30bd9f938467e5bb07a42cd556
table-format-results
237 Bytes
sha256:1e0d01a59becd8ed0bb695a54dad46b5584053bf3b41353cc79b7f32ddec3273
terraform-test-results
588 Bytes
sha256:7d4ad6b91a48a99fee47daa7a3f5a6af16e7588daf04292739bfe52bcd692e44
terraform-validation-results
474 Bytes
sha256:aa5ae098bcdde0ae49a9a856f555f256b6a8044524f0cd2982c81dc47def01ad
tflint-results
176 Bytes
sha256:7911f7838f69c629ed5cbe1b7cfb1b77f5ecf975a6cb04c497474e64cfe91fa3
vitest-coverage-xml
38.3 KB
sha256:0c64c44966cba98f6315f89ffbfb7bb47fe88ad7b4db5a4c529e84e3cbf99e8e
yaml-lint-results
266 Bytes
sha256:e92a8028579b17e617c7c36e81d1f42147836313fba2c27808c900e668e9c4e8