Skip to content

fix(deps): update module mellium.im/xmpp to v0.22.0 [security] #982

fix(deps): update module mellium.im/xmpp to v0.22.0 [security]

fix(deps): update module mellium.im/xmpp to v0.22.0 [security] #982

Triggered via pull request October 12, 2024 15:19
Status Failure
Total duration 6m 5s
Artifacts 1

analysis.yml

on: pull_request
Scorecards  /  Security Scorecards
34s
Scorecards / Security Scorecards
Sonatype Nancy  /  Sonatype Nancy
5m 20s
Sonatype Nancy / Sonatype Nancy
Semgrep Scan  /  semgrep
26s
Semgrep Scan / semgrep
Dependency Review  /  Scan dependencies for license compliance
14s
Dependency Review / Scan dependencies for license compliance
Trivy  /  Filesystem
38s
Trivy / Filesystem
Trivy  /  Container
0s
Trivy / Container
FOSSA  /  Find license compliance and security issues
FOSSA / Find license compliance and security issues
Matrix: CodeQL
Fit to window
Zoom out
Zoom in

Annotations

2 errors and 8 warnings
Sonatype Nancy / Sonatype Nancy
Command failed: go env GOPATH go: downloading go1.23.2 (linux/amd64) go: download go1.23.2: golang.org/[email protected]: Get "https://storage.googleapis.com/proxy-golang-org-prod/779d42f80b1a6dfc-golang.org:toolchain-v0.0.1-go1.23.2.linux-amd64.zip?Expires=1728832206&GoogleAccessId=gcs-urlsigner-prod%40golang-modproxy.iam.gserviceaccount.com&Signature=t%2BXr8X1orFPtshn68RINPaMJJZzQtoQI3PZ%2FegnyMrE47VosiJCNvWTfZ9VFCNdzItc1EKJohg6KAnSgQPeAPHX1oNUoi%2Bw6e34nSh5y3mhhnHq1GZLQ0r0xD8v7wtyqftq9lHEU7mfX3IwzuQXlPrksJd5UmMtjBf%2BR3Y9I1Iq5GM6NPp8ivdBEX4r2WJ4TrZohmtVH5lf%2FC7zzeRvgndc0auSQr4UcOAMERGLRJNQdgANMV0%2Fue9bNnvXA%2Fa%2Fch%2FQ2IgLqiHfzqQwVaD0%2Fzz3R%2Ba3hnN5qU6kltJ18u8PI00sJxKpm4bbMQNJHH79gJKwkrYbXf9AZvTsTLBPYVg%3D%3D": dial tcp 54.185.253.63:443: connect: connection refused
Dependency Review / Scan dependencies for license compliance
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
Semgrep Scan / semgrep
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
Scorecards / Security Scorecards
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab, actions/upload-artifact@0b7f8abb1508181956e8e162db84b466c27e18ce, github/codeql-action/upload-sarif@c3b6fce4ee2ca25bc1066aa3bf73962fda0e8898. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
Trivy / Filesystem
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab, actions/upload-artifact@0b7f8abb1508181956e8e162db84b466c27e18ce, github/codeql-action/upload-sarif@c3b6fce4ee2ca25bc1066aa3bf73962fda0e8898. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
CodeQL (go) / CodeQL Analysis
The following actions use a deprecated Node.js version and will be forced to run on node20: actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab, github/codeql-action/init@f0a12816612c7306b485a22cb164feb43c6df818, github/codeql-action/autobuild@f0a12816612c7306b485a22cb164feb43c6df818, github/codeql-action/analyze@f0a12816612c7306b485a22cb164feb43c6df818. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
CodeQL (go) / CodeQL Analysis
The "paths"/"paths-ignore" fields of the config only have effect for JavaScript, Python, and Ruby
Sonatype Nancy / Sonatype Nancy
The following actions use a deprecated Node.js version and will be forced to run on node20: step-security/harden-runner@1b05615854632b887b69ae1be8cbefe72d3ae423, actions/checkout@8e5e7e5ab8b370d6c329ec480221332ada57f0ab. For more info: https://github.blog/changelog/2024-03-07-github-actions-all-actions-will-run-on-node20-instead-of-node16-by-default/
Deprecation notice: v1, v2, and v3 of the artifact actions
The following artifacts were uploaded using a version of actions/upload-artifact that is scheduled for deprecation: "SARIF file". Please update your workflow to use v4 of the artifact actions. Learn more: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/

Artifacts

Produced during runtime
Name Size
SARIF file
38.9 KB