perf(ci): PGO build for the x64-linux release binary (#634) #407
security-scan.yml
on: push
Secrets + CVE
/
gitleaks (secrets)
12s
Secrets + CVE
/
osv-scanner (CVE)
13s
Secrets + CVE
/
opengrep (SAST)
1m 32s
Secrets + CVE
/
zizmor (GitHub Actions security)
20s
Secrets + CVE
/
trufflehog (secrets, deep history)
Secrets + CVE
/
snyk (deps)
4s
Annotations
2 warnings and 1 notice
|
Secrets + CVE / zizmor (GitHub Actions security)
zizmor found 125 GitHub Actions security finding(s) — see the Security tab (SARIF). Set fail-on-actions: true to make this blocking.
|
|
Secrets + CVE / opengrep (SAST)
OpenGrep errored (exit 7) — not failing the scan.
|
|
Secrets + CVE / snyk (deps)
SNYK_TOKEN not set — skipping Snyk scan (soft pass).
|