Skip to content

security: pin dependencies and restrict token permissions #169

security: pin dependencies and restrict token permissions

security: pin dependencies and restrict token permissions #169

Triggered via pull request May 1, 2026 13:05
Status Success
Total duration 1m 34s
Artifacts

security.yml

on: pull_request
Vulnerability Scanning
19s
Vulnerability Scanning
Matrix: CodeQL Analysis
Fit to window
Zoom out
Zoom in

Annotations

1 warning
CodeQL Analysis (go)
Starting April 2026, the CodeQL Action will skip computing file coverage information on pull requests to improve analysis performance. File coverage information will still be computed on non-PR analyses. To opt out of this change, set the `CODEQL_ACTION_FILE_COVERAGE_ON_PRS` environment variable to `true`. Alternatively, create a custom repository property with the name `github-codeql-file-coverage-on-prs` and the type "True/false", then set this property to `true` in the repository's settings.