Fix CVEs in release-0.23 #7159
linting.yml
on: pull_request
No "Apply suggestions from code review" Commits
3s
Check branch dependencies
1m 14s
Submariner K8s API Code Generation
1m 50s
Protobuf Code Generation
54s
Commit Message(s)
16s
Go
3m 33s
Dependency Licenses
3m 4s
Markdown Links (modified files)
14s
Markdown
14s
Package Documentation
1m 19s
Shell
20s
Variant Analysis
4m 2s
Vulnerability Scanning
1m 5s
YAML
20s
Embedded YAMLs up-to-date
2m 3s
Annotations
1 error and 5 warnings
|
Go
Process completed with exit code 2.
|
|
No "Apply suggestions from code review" Commits
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: tim-actions/commit-message-checker-with-regex@094fc16ff83d04e2ec73edb5eaf6aa267db33791, tim-actions/get-pr-commits@198af03565609bb4ed924d1260247b4881f09e7d. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Variant Analysis
Starting April 2026, the CodeQL Action will skip computing file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses.
To opt out of this change, set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true`. Alternatively, create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository's settings.
|
|
Variant Analysis
1 issue was detected with this workflow: Please specify an on.push hook to analyze and see code scanning alerts from the default branch on the Security tab.
|
|
Variant Analysis
Feature flags do not specify a default CLI version. Falling back to the CLI version shipped with the Action. This is 2.26.1.
|
|
Variant Analysis
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. As a result, it will not be opted into any experimental features. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
|