Skip to content

Fix CVEs in release-0.23 #7159

Fix CVEs in release-0.23

Fix CVEs in release-0.23 #7159

Triggered via pull request August 24, 2026 03:59
Status Failure
Total duration 4m 5s
Artifacts

linting.yml

on: pull_request
No "Apply suggestions from code review" Commits
3s
No "Apply suggestions from code review" Commits
Check branch dependencies
1m 14s
Check branch dependencies
Submariner K8s API Code Generation
1m 50s
Submariner K8s API Code Generation
Protobuf Code Generation
54s
Protobuf Code Generation
Commit Message(s)
16s
Commit Message(s)
Go
3m 33s
Go
Dependency Licenses
3m 4s
Dependency Licenses
Markdown Links (modified files)
14s
Markdown Links (modified files)
Markdown
14s
Markdown
Package Documentation
1m 19s
Package Documentation
Shell
20s
Shell
Variant Analysis
4m 2s
Variant Analysis
Vulnerability Scanning
1m 5s
Vulnerability Scanning
YAML
20s
YAML
Embedded YAMLs up-to-date
2m 3s
Embedded YAMLs up-to-date
Fit to window
Zoom out
Zoom in

Annotations

1 error and 5 warnings
Go
Process completed with exit code 2.
No "Apply suggestions from code review" Commits
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: tim-actions/commit-message-checker-with-regex@094fc16ff83d04e2ec73edb5eaf6aa267db33791, tim-actions/get-pr-commits@198af03565609bb4ed924d1260247b4881f09e7d. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Variant Analysis
Starting April 2026, the CodeQL Action will skip computing file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. To opt out of this change, set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true`. Alternatively, create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository's settings.
Variant Analysis
1 issue was detected with this workflow: Please specify an on.push hook to analyze and see code scanning alerts from the default branch on the Security tab.
Variant Analysis
Feature flags do not specify a default CLI version. Falling back to the CLI version shipped with the Action. This is 2.26.1.
Variant Analysis
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. As a result, it will not be opted into any experimental features. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest