Skip to content

Security Scanning & Compliance #60

Security Scanning & Compliance

Security Scanning & Compliance #60

Triggered via schedule September 16, 2025 02:26
Status Failure
Total duration 55s
Artifacts 1

security-scanning.yml

on: schedule
Matrix: Container Security Scan
Matrix: Infrastructure Security Scan
Code Security Scan
2s
Code Security Scan
Kubernetes Security Scan
2s
Kubernetes Security Scan
Secrets Scan
14s
Secrets Scan
Compliance Check
2s
Compliance Check
Penetration Testing
0s
Penetration Testing
Security Policy Enforcement
5s
Security Policy Enforcement
Generate Security Report
2s
Generate Security Report
Fit to window
Zoom out
Zoom in

Annotations

54 errors and 16 warnings
Compliance Check
This request has been automatically failed because it uses a deprecated version of `actions/upload-artifact: v3`. Learn more: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/
Security Policy Enforcement
Process completed with exit code 127.
Kubernetes Security Scan
Unable to resolve action fairwindsops/polaris-action, repository not found
Code Security Scan
This request has been automatically failed because it uses a deprecated version of `actions/upload-artifact: v3`. Learn more: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/
Container Security Scan (docker/Dockerfile.scraping)
Path does not exist: trivy-results-docker/Dockerfile.scraping.sarif
Container Security Scan (docker/Dockerfile.scraping)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
Container Security Scan (docker/Dockerfile.scraping)
Process completed with exit code 1.
Container Security Scan (docker/Dockerfile.ml-training)
Path does not exist: trivy-results-docker/Dockerfile.ml-training.sarif
Container Security Scan (docker/Dockerfile.ml-training)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
Container Security Scan (docker/Dockerfile.ml-training)
The operation was canceled.
Container Security Scan (docker/Dockerfile.ml-training)
The strategy configuration was canceled because "container-security-scan.docker_Dockerfile_scrapin" failed
Infrastructure Security Scan (azure)
Resource not accessible by integration
Infrastructure Security Scan (azure)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
Infrastructure Security Scan (azure)
CKV_AZURE_141: "Ensure AKS local admin account is disabled"
Infrastructure Security Scan (azure)
CKV_AZURE_168: "Ensure Azure Kubernetes Cluster (AKS) nodes should use a minimum number of 50 pods."
Infrastructure Security Scan (azure)
CKV_AZURE_112: "Ensure that key vault key is backed by HSM"
Infrastructure Security Scan (azure)
CKV_AZURE_40: "Ensure that the expiration date is set on all keys"
Infrastructure Security Scan (azure)
CKV_AZURE_237: "Ensure dedicated data endpoints are enabled."
Infrastructure Security Scan (azure)
CKV_AZURE_165: "Ensure geo-replicated container registries to match multi-region container deployments."
Infrastructure Security Scan (azure)
CKV_AZURE_233: "Ensure Azure Container Registry (ACR) is zone redundant"
Infrastructure Security Scan (azure)
CKV_AZURE_42: "Ensure the key vault is recoverable"
Infrastructure Security Scan (azure)
CKV_AZURE_110: "Ensure that key vault enables purge protection"
Infrastructure Security Scan (azure)
CKV_AZURE_160: "Ensure that HTTP (port 80) access is restricted from the internet"
Infrastructure Security Scan (gcp)
Resource not accessible by integration
Infrastructure Security Scan (gcp)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
Infrastructure Security Scan (gcp)
CKV_GCP_111: "Ensure GCP PostgreSQL logs SQL statements"
Infrastructure Security Scan (gcp)
CKV_GCP_110: "Ensure pgAudit is enabled for your GCP PostgreSQL database"
Infrastructure Security Scan (gcp)
CKV_GCP_79: "Ensure SQL database is using latest Major version"
Infrastructure Security Scan (gcp)
CKV_GCP_43: "Ensure KMS encryption keys are rotated within a period of 90 days"
Infrastructure Security Scan (gcp)
CKV_GCP_61: "Enable VPC Flow Logs and Intranode Visibility"
Infrastructure Security Scan (gcp)
CKV_GCP_13: "Ensure client certificate authentication to Kubernetes Engine Clusters is disabled"
Infrastructure Security Scan (gcp)
CKV_GCP_21: "Ensure Kubernetes Clusters are configured with Labels"
Infrastructure Security Scan (gcp)
CKV_GCP_69: "Ensure the GKE Metadata Server is Enabled"
Infrastructure Security Scan (gcp)
CKV_GCP_65: "Manage Kubernetes RBAC users with Google Groups for GKE"
Infrastructure Security Scan (gcp)
CKV_GCP_74: "Ensure that private_ip_google_access is enabled for Subnet"
Infrastructure Security Scan (gcp)
The strategy configuration was canceled because "infrastructure-security-scan.azure" failed
Container Security Scan (docker/Dockerfile.api)
Path does not exist: trivy-results-docker/Dockerfile.api.sarif
Container Security Scan (docker/Dockerfile.api)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
Container Security Scan (docker/Dockerfile.api)
The operation was canceled.
Container Security Scan (docker/Dockerfile.api)
The strategy configuration was canceled because "container-security-scan.docker_Dockerfile_scrapin" failed
Infrastructure Security Scan (aws)
Resource not accessible by integration
Infrastructure Security Scan (aws)
CodeQL Action major versions v1 and v2 have been deprecated. Please update all occurrences of the CodeQL Action in your workflow files to v3. For more information, see https://github.blog/changelog/2025-01-10-code-scanning-codeql-action-v2-is-now-deprecated/
Infrastructure Security Scan (aws)
CKV_AWS_382: "Ensure no security groups allow egress from 0.0.0.0:0 to port -1"
Infrastructure Security Scan (aws)
CKV_AWS_23: "Ensure every security group and rule has a description"
Infrastructure Security Scan (aws)
CKV_AWS_338: "Ensure CloudWatch log groups retains logs for at least 1 year"
Infrastructure Security Scan (aws)
CKV_AWS_158: "Ensure that CloudWatch Log Group is encrypted by KMS"
Infrastructure Security Scan (aws)
CKV_AWS_39: "Ensure Amazon EKS public endpoint disabled"
Infrastructure Security Scan (aws)
CKV_AWS_38: "Ensure Amazon EKS public endpoint not accessible to 0.0.0.0/0"
Infrastructure Security Scan (aws)
CKV_AWS_337: "Ensure SSM parameters are using KMS CMK"
Infrastructure Security Scan (aws)
CKV_AWS_337: "Ensure SSM parameters are using KMS CMK"
Infrastructure Security Scan (aws)
CKV_AWS_338: "Ensure CloudWatch log groups retains logs for at least 1 year"
Infrastructure Security Scan (aws)
CKV_AWS_158: "Ensure that CloudWatch Log Group is encrypted by KMS"
Infrastructure Security Scan (aws)
The strategy configuration was canceled because "infrastructure-security-scan.azure" failed
Generate Security Report
This request has been automatically failed because it uses a deprecated version of `actions/download-artifact: v3`. Learn more: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/. This request has been automatically failed because it uses a deprecated version of `actions/upload-artifact: v3`. Learn more: https://github.blog/changelog/2024-04-16-deprecation-notice-v3-of-the-artifact-actions/
Secrets Scan
🛑 Leaks detected, see job summary for details
Container Security Scan (docker/Dockerfile.scraping)
Resource not accessible by integration
Container Security Scan (docker/Dockerfile.scraping)
Resource not accessible by integration
Container Security Scan (docker/Dockerfile.ml-training)
Resource not accessible by integration
Container Security Scan (docker/Dockerfile.ml-training)
Resource not accessible by integration
Infrastructure Security Scan (azure)
Resource not accessible by integration
Infrastructure Security Scan (azure)
Resource not accessible by integration
Infrastructure Security Scan (azure)
Resource not accessible by integration
Infrastructure Security Scan (gcp)
Resource not accessible by integration
Infrastructure Security Scan (gcp)
Resource not accessible by integration
Infrastructure Security Scan (gcp)
Resource not accessible by integration
Container Security Scan (docker/Dockerfile.api)
Resource not accessible by integration
Container Security Scan (docker/Dockerfile.api)
Resource not accessible by integration
Infrastructure Security Scan (aws)
Resource not accessible by integration
Infrastructure Security Scan (aws)
Resource not accessible by integration
Infrastructure Security Scan (aws)
Resource not accessible by integration

Artifacts

Produced during runtime
Name Size Digest
gitleaks-results.sarif
8.29 KB
sha256:c8987c1be82635876974f2711eb531987c000dbf982528922a329e9fd430a13a