CRIT
generic-api-key
Detected a Generic API Key, potentially exposing access to various services and sensitive…
pkg/container/testdata/docker-pull-opti…:4
HIGH
SEC093
[SEC093] Go: exec.Command with non-literal: exec.Command(<var>) — variable command name a…
pkg/gh/gh.go:20
HIGH
SEC093
[SEC093] Go: exec.Command with non-literal: exec.Command(<var>) — variable command name a…
pkg/container/host_environment.go:301
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
pkg/container/host_environment.go:285
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
pkg/container/container_types.go:51
HIGH
SEC085
[SEC085] JS: child_process.exec with non-literal: child_process.exec with user-derived in…
pkg/common/executor.go:136
HIGH
MINED016
[MINED016] Go Error Ignored: _, err := fn() with err not checked. Go anti-pattern.
pkg/container/docker_images.go:58
HIGH
MINED016
[MINED016] Go Error Ignored: _, err := fn() with err not checked. Go anti-pattern.
pkg/common/file.go:25
HIGH
MINED016
[MINED016] Go Error Ignored: _, err := fn() with err not checked. Go anti-pattern.
pkg/artifactcache/storage.go:45
HIGH
SEC029
[SEC029] Server-Side Request Forgery (SSRF) — outbound HTTP from user input: Outbound HTT…
cmd/notices.go:83
HIGH
MINED118
Dockerfile FROM `node:12-buster-slim` not pinned by digest
pkg/runner/testdata/actions/docker-loca…:2
HIGH
MINED118
Dockerfile FROM `node:16-buster-slim` not pinned by digest
pkg/runner/testdata/actions/docker-loca…:2
HIGH
MINED118
Dockerfile FROM `ubuntu:18.04` not pinned by digest
pkg/runner/testdata/actions/action1/Doc…:1
HIGH
MINED118
Dockerfile FROM `alpine:3` not pinned by digest
pkg/runner/testdata/actions-environment…:1
HIGH
MINED118
Dockerfile FROM `debian:bullseye-slim` not pinned by digest
pkg/runner/testdata/docker-action-host-…:1
HIGH
MINED118
Dockerfile FROM `ubuntu:latest` not pinned by digest
pkg/runner/testdata/localdockerimagetes…:1
HIGH
MINED118
Dockerfile FROM `alpine:3.21` not pinned by digest
.github/actions/choco/Dockerfile:1
HIGH
MINED115
Action `actions/setup-go` pinned to mutable ref `@v6`
.github/workflows/release.yml:20
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/release.yml:17
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/codespell.yml:21
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v7`
.github/workflows/checks.yml:170
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v7`
.github/workflows/checks.yml:164
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v7`
.github/workflows/checks.yml:158
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v7`
.github/workflows/checks.yml:152
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v7`
.github/workflows/checks.yml:146
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v7`
.github/workflows/checks.yml:140
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v7`
.github/workflows/checks.yml:134
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v7`
.github/workflows/checks.yml:128
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v7`
.github/workflows/checks.yml:122
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v7`
.github/workflows/checks.yml:116
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v7`
.github/workflows/checks.yml:110
HIGH
MINED115
Action `actions/upload-artifact` pinned to mutable ref `@v7`
.github/workflows/checks.yml:104
HIGH
MINED115
Action `actions/setup-go` pinned to mutable ref `@v6`
.github/workflows/checks.yml:94
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/checks.yml:93
HIGH
MINED115
Action `actions/setup-go` pinned to mutable ref `@v6`
.github/workflows/checks.yml:77
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/checks.yml:74
HIGH
MINED115
Action `actions/setup-go` pinned to mutable ref `@v6`
.github/workflows/checks.yml:44
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/checks.yml:39
HIGH
MINED115
Action `actions/setup-go` pinned to mutable ref `@v6`
.github/workflows/checks.yml:21
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/checks.yml:18
HIGH
MINED115
Action `actions/setup-go` pinned to mutable ref `@v6`
.github/workflows/promote.yml:24
HIGH
MINED115
Action `actions/checkout` pinned to mutable ref `@v6`
.github/workflows/promote.yml:13
HIGH
GHSA-vrm6-8vpv-qv8q
undici: GHSA-vrm6-8vpv-qv8q
pkg/runner/testdata/actions/node12/pack…
HIGH
GHSA-v9p9-hfj2-hcw8
undici: GHSA-v9p9-hfj2-hcw8
pkg/runner/testdata/actions/node12/pack…
HIGH
GO-2026-5039
stdlib: GO-2026-5039
go.mod
HIGH
GO-2026-5038
stdlib: GO-2026-5038
go.mod
HIGH
GO-2026-5037
stdlib: GO-2026-5037
go.mod
HIGH
GO-2026-4986
stdlib: GO-2026-4986
go.mod
HIGH
GO-2026-4982
stdlib: GO-2026-4982
go.mod
HIGH
GO-2026-4981
stdlib: GO-2026-4981
go.mod
HIGH
GO-2026-4980
stdlib: GO-2026-4980
go.mod
HIGH
GO-2026-4977
stdlib: GO-2026-4977
go.mod
HIGH
GO-2026-4976
stdlib: GO-2026-4976
go.mod
HIGH
GO-2026-4971
stdlib: GO-2026-4971
go.mod
HIGH
GO-2026-4947
stdlib: GO-2026-4947
go.mod
HIGH
GO-2026-4946
stdlib: GO-2026-4946
go.mod
HIGH
GO-2026-4918
stdlib: GO-2026-4918
go.mod
HIGH
GO-2026-4870
stdlib: GO-2026-4870
go.mod
HIGH
GO-2026-4869
stdlib: GO-2026-4869
go.mod
HIGH
GO-2026-4865
stdlib: GO-2026-4865
go.mod
HIGH
GO-2026-4864
stdlib: GO-2026-4864
go.mod
HIGH
GO-2026-4603
stdlib: GO-2026-4603
go.mod
HIGH
GO-2026-4602
stdlib: GO-2026-4602
go.mod
HIGH
GO-2026-4601
stdlib: GO-2026-4601
go.mod
HIGH
GO-2026-4342
stdlib: GO-2026-4342
go.mod
HIGH
GO-2026-4341
stdlib: GO-2026-4341
go.mod
HIGH
GO-2026-4340
stdlib: GO-2026-4340
go.mod
HIGH
GO-2026-4337
stdlib: GO-2026-4337
go.mod
HIGH
GO-2025-4175
stdlib: GO-2025-4175
go.mod
HIGH
GO-2025-4155
stdlib: GO-2025-4155
go.mod
HIGH
GO-2025-4015
stdlib: GO-2025-4015
go.mod
HIGH
GO-2025-4014
stdlib: GO-2025-4014
go.mod
HIGH
GO-2025-4013
stdlib: GO-2025-4013
go.mod
HIGH
GO-2025-4012
stdlib: GO-2025-4012
go.mod
HIGH
GO-2025-4011
stdlib: GO-2025-4011
go.mod
HIGH
GO-2025-4010
stdlib: GO-2025-4010
go.mod
HIGH
GO-2025-4009
stdlib: GO-2025-4009
go.mod
HIGH
GO-2025-4008
stdlib: GO-2025-4008
go.mod
HIGH
GO-2025-4007
stdlib: GO-2025-4007
go.mod
HIGH
GO-2025-4006
stdlib: GO-2025-4006
go.mod
HIGH
GO-2025-3955
stdlib: GO-2025-3955
go.mod
HIGH
GO-2026-5024
golang.org/x/sys: GO-2026-5024
go.mod
HIGH
GO-2026-5030
golang.org/x/net: GO-2026-5030
go.mod
HIGH
GO-2026-5029
golang.org/x/net: GO-2026-5029
go.mod
HIGH
GO-2026-5028
golang.org/x/net: GO-2026-5028
go.mod
HIGH
GO-2026-5027
golang.org/x/net: GO-2026-5027
go.mod
HIGH
GO-2026-5026
golang.org/x/net: GO-2026-5026
go.mod
HIGH
GO-2026-5025
golang.org/x/net: GO-2026-5025
go.mod
HIGH
GO-2026-5033
golang.org/x/crypto: GO-2026-5033
go.mod
HIGH
GO-2026-5023
golang.org/x/crypto: GO-2026-5023
go.mod
HIGH
GO-2026-5021
golang.org/x/crypto: GO-2026-5021
go.mod
HIGH
GO-2026-5020
golang.org/x/crypto: GO-2026-5020
go.mod
HIGH
GO-2026-5019
golang.org/x/crypto: GO-2026-5019
go.mod
HIGH
GO-2026-5018
golang.org/x/crypto: GO-2026-5018
go.mod
HIGH
GO-2026-5017
golang.org/x/crypto: GO-2026-5017
go.mod
HIGH
GO-2026-5016
golang.org/x/crypto: GO-2026-5016
go.mod
HIGH
GO-2026-5015
golang.org/x/crypto: GO-2026-5015
go.mod
HIGH
GO-2026-5014
golang.org/x/crypto: GO-2026-5014
go.mod
HIGH
GO-2026-5013
golang.org/x/crypto: GO-2026-5013
go.mod
HIGH
GO-2026-5006
golang.org/x/crypto: GO-2026-5006
go.mod
HIGH
GO-2026-5005
golang.org/x/crypto: GO-2026-5005
go.mod
HIGH
GHSA-389r-gv7p-r3rp
github.com/go-git/go-git/v5: GHSA-389r-gv7p-r3rp
go.mod
HIGH
GO-2026-4910
github.com/go-git/go-git/v5: GO-2026-4910
go.mod
HIGH
GO-2026-4909
github.com/go-git/go-git/v5: GO-2026-4909
go.mod
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
pkg/container/host_environment.go:285
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
pkg/container/container_types.go:51
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
pkg/common/executor.go:136
MED
SEC091
[SEC091] Go: net/http server without timeouts: HTTP server without ReadHeaderTimeout/Read…
pkg/artifacts/server.go:294
MED
DKR003
Dockerfile base image uses the latest tag
pkg/runner/testdata/localdockerimagetes…:1
MED
DKR007
Docker build context has no .dockerignore
.dockerignore
MED
GHSA-w5hq-g745-h8pq
uuid: GHSA-w5hq-g745-h8pq
pkg/runner/testdata/actions/node12/pack…
MED
GHSA-g9mf-h72j-4rw9
undici: GHSA-g9mf-h72j-4rw9
pkg/runner/testdata/actions/node12/pack…
MED
GHSA-4992-7rv2-5pvq
undici: GHSA-4992-7rv2-5pvq
pkg/runner/testdata/actions/node12/pack…
MED
GHSA-2mjp-6q6p-2qxm
undici: GHSA-2mjp-6q6p-2qxm
pkg/runner/testdata/actions/node12/pack…
MED
GHSA-w5pp-99ch-qj29
github.com/go-git/go-git/v5: GHSA-w5pp-99ch-qj29
go.mod
MED
GHSA-crhj-59gh-8x96
github.com/go-git/go-git/v5: GHSA-crhj-59gh-8x96
go.mod
MED
GHSA-3xc5-wrhm-f963
github.com/go-git/go-git/v5: GHSA-3xc5-wrhm-f963
go.mod
MED
DKR001
Docker final stage has no non-root USER
pkg/runner/testdata/localdockerimagetes…:1
MED
DKR001
Docker final stage has no non-root USER
pkg/runner/testdata/docker-action-host-…:1
MED
DKR001
Docker final stage has no non-root USER
pkg/runner/testdata/actions-environment…:1
MED
DKR001
Docker final stage has no non-root USER
pkg/runner/testdata/actions/docker-loca…:2
MED
DKR001
Docker final stage has no non-root USER
pkg/runner/testdata/actions/docker-loca…:2
MED
DKR001
Docker final stage has no non-root USER
pkg/runner/testdata/actions/action1/Doc…:1
MED
DKR001
Docker final stage has no non-root USER
.github/actions/choco/Dockerfile:1
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
pkg/model/planner.go:129
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
pkg/common/file.go:29
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
pkg/artifactcache/storage.go:51
LOW
DEPCUR-NPM
npm package `@actions/github` is minor version(s) behind (9.0.0 -> 9.1.1)
pkg/runner/testdata/actions/node12/pack…
LOW
DEPCUR-NPM
npm package `@actions/github` is minor version(s) behind (9.0.0 -> 9.1.1)
pkg/runner/testdata/actions/node16/pack…
LOW
DEPCUR-NPM
npm package `@actions/github` is minor version(s) behind (9.0.0 -> 9.1.1)
pkg/runner/testdata/actions/node20/pack…
LOW
GHSA-m7cr-m3pv-hgrp
github.com/go-git/go-git/v5: GHSA-m7cr-m3pv-hgrp
go.mod
LOW
AIC003
Duplicated implementation block across source files
pkg/runner/testdata/uses-composite-chec…:1
LOW
AIC003
Duplicated implementation block across source files
pkg/runner/testdata/uses-composite-chec…:1
LOW
AIC003
Duplicated implementation block across source files
pkg/runner/testdata/actions/node16/inde…:1
LOW
AIC003
Duplicated implementation block across source files
pkg/runner/step_run.go:114
LOW
AIC003
Duplicated implementation block across source files
pkg/runner/local_repository_cache.go:44
LOW
AIC003
Duplicated implementation block across source files
pkg/runner/job_executor.go:160
LOW
AIC003
Duplicated implementation block across source files
pkg/container/host_environment.go:85
LOW
DKR010
Dockerfile leaves apt package indexes in the image layer
pkg/runner/testdata/docker-action-host-…:4
LOW
DKR011
Dockerfile installs recommended OS packages
pkg/runner/testdata/docker-action-host-…:4
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
pkg/runner/job_executor.go:109
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
pkg/container/host_environment.go:328
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
pkg/common/context.go:11
INFO
MINED071
[MINED071] Go Panic Call: panic() crashes the process. Should return error in most cases.
pkg/exprparser/functions.go:122
INFO
MINED071
[MINED071] Go Panic Call: panic() crashes the process. Should return error in most cases.
pkg/artifacts/server.go:103
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
pkg/artifacts/server.go:100
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
install.sh:164
INFO
DEPCUR-NPM
npm package `@actions/core` is patch version(s) behind (3.0.0 -> 3.0.1)
pkg/runner/testdata/actions/node12/pack…
INFO
DEPCUR-NPM
npm package `@actions/core` is patch version(s) behind (3.0.0 -> 3.0.1)
pkg/runner/testdata/actions/node16/pack…
INFO
DEPCUR-NPM
npm package `@actions/core` is patch version(s) behind (3.0.0 -> 3.0.1)
pkg/runner/testdata/actions/node20/pack…