-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:24
-
Dependency advisory GHSA-rgw5-rvv9-x895:pkg:e2d26d120652434b1043ffdf applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: frontend/package-lock.json
-
zizmor reported unpinned-uses · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:21
-
Dependency advisory GHSA-73wf-gq98-2v4g:pkg:978489779fc1a775f3f91fab applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: frontend/package-lock.json
-
Dependency advisory GHSA-rgw5-rvv9-x895:pkg:b8b4e108ab4269d091ad76f5 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: frontend/package-lock.json
-
Dependency advisory GHSA-w9m9-85wc-3x92:pkg:789fe9d4eb26f7c51d684509 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: frontend/package-lock.json
-
zizmor reported artipacked · zizmor 1.28.0
The code has a known weakness, though this scan does not show that anyone can exploit it here.
Policy reason: zizmor-known-workflow-rule · Execution scope: automation
Source: .github/workflows/ci.yml:20-21
-
Dependency advisory GHSA-c83g-rgw3-j3cx:pkg:55c4a668cc988d5ceedbfbf6 applies · osv-scanner 2.4.0
A dependency has a published security issue, though this scan does not show that the project exposes it to an attacker.
Policy reason: osv-structured-advisory · Execution scope: unknown
Source: frontend/package-lock.json