fix(release): make pr mode tag on merge instead of on the pre-bump commit #1108
security-scan.yml
on: pull_request
Secrets + CVE
/
gitleaks (secrets)
17s
Secrets + CVE
/
osv-scanner (CVE)
12s
Secrets + CVE
/
opengrep (SAST)
1m 13s
Secrets + CVE
/
zizmor (GitHub Actions security)
19s
Secrets + CVE
/
snyk (deps)
5s
Secrets + CVE
/
trufflehog (secrets, deep history)
Secrets + CVE
/
Scans ran
3s
Annotations
2 warnings and 1 notice
|
Secrets + CVE / zizmor (GitHub Actions security)
zizmor found 39 GitHub Actions security finding(s) — see the Security tab (SARIF). Set fail-on-actions: true to make this blocking.
|
|
Secrets + CVE / opengrep (SAST)
OpenGrep errored (exit 7) — not failing the scan.
|
|
Secrets + CVE / snyk (deps)
SNYK_TOKEN not set — skipping Snyk scan (soft pass).
|