Skip to content

Bump softprops/action-gh-release from 2.2.2 to 2.6.1 #97

Bump softprops/action-gh-release from 2.2.2 to 2.6.1

Bump softprops/action-gh-release from 2.2.2 to 2.6.1 #97

Triggered via pull request March 16, 2026 03:57
Status Failure
Total duration 53s
Artifacts

ci.yml

on: pull_request
Matrix: Go Build & Test
Python Test & Lint
34s
Python Test & Lint
Security Regression Tests
42s
Security Regression Tests
Test Count Drift Check
41s
Test Count Drift Check
Dependency Vulnerability Audit
49s
Dependency Vulnerability Audit
Documentation Validation
4s
Documentation Validation
Shell Script Lint
9s
Shell Script Lint
Validate YAML configs
7s
Validate YAML configs
Verify action & container pins
6s
Verify action & container pins
Supply Chain & SBOM Verification
29s
Supply Chain & SBOM Verification
Release Branch Hardened Gate
0s
Release Branch Hardened Gate
Fit to window
Zoom out
Zoom in

Annotations

10 errors and 8 warnings
Dependency Vulnerability Audit
tool.main calls signal.NotifyContext, which eventually calls os.ReadDir
Dependency Vulnerability Audit
registry: govulncheck found vulnerabilities
Dependency Vulnerability Audit
securectl.apiDelete calls http.Client.Do, which eventually calls url.URL.Parse
Dependency Vulnerability Audit
registry.main calls http.Server.ListenAndServe, which eventually calls url.ParseRequestURI
Dependency Vulnerability Audit
securectl.apiDelete calls http.Client.Do, which eventually calls url.Parse
Dependency Vulnerability Audit
registry.main calls signal.NotifyContext, which eventually calls os.ReadDir
Dependency Vulnerability Audit
airlock: govulncheck found vulnerabilities
Dependency Vulnerability Audit
airlock.main calls http.Server.ListenAndServe, which eventually calls url.ParseRequestURI
Dependency Vulnerability Audit
airlock.main calls http.Server.ListenAndServe, which eventually calls url.Parse
Dependency Vulnerability Audit
airlock.main calls signal.NotifyContext, which eventually calls os.ReadDir
Supply Chain & SBOM Verification
Restore cache failed: Dependencies file is not found in /home/runner/work/SecAI_OS/SecAI_OS. Supported file pattern: go.mod
Python Test & Lint
services/quarantine/quarantine/watcher.py:178: [MEDIUM] Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
Python Test & Lint
services/quarantine/quarantine/pipeline.py:1437: [MEDIUM] Audit url open for permitted schemes. Allowing use of file:/ or custom schemes is often unexpected.
Python Test & Lint
services/agent/agent/sandbox.py:403: [MEDIUM] Probable insecure usage of temp file/directory.
Python Test & Lint
services/agent/agent/app.py:555: [MEDIUM] Chmod setting a permissive mask 0o660 on file (sock_path).
Security Regression Tests
Restore cache failed: Dependencies file is not found in /home/runner/work/SecAI_OS/SecAI_OS. Supported file pattern: go.mod
Test Count Drift Check
Restore cache failed: Dependencies file is not found in /home/runner/work/SecAI_OS/SecAI_OS. Supported file pattern: go.mod
Dependency Vulnerability Audit
Restore cache failed: Dependencies file is not found in /home/runner/work/SecAI_OS/SecAI_OS. Supported file pattern: go.mod