Skip to content

Fix/amp 31205/pidc security test report fix #173

Fix/amp 31205/pidc security test report fix

Fix/amp 31205/pidc security test report fix #173

Triggered via pull request October 1, 2026 18:54
Status Failure
Total duration 3m 1s
Artifacts 2

security.yml

on: pull_request
Resolve target ref
2s
Resolve target ref
OWASP Dependency-Check (Maven + npm)
2m 50s
OWASP Dependency-Check (Maven + npm)
Trivy (Container Image)
33s
Trivy (Container Image)
Fit to window
Zoom out
Zoom in

Annotations

13 errors, 5 warnings, and 3 notices
Trivy (Container Image)
Process completed with exit code 1.
OWASP Dependency-Check (Maven + npm)
Process completed with exit code 1.
OWASP Dependency-Check (Maven + npm)
OWASP Dependency-Check found vulnerabilities above the CVSS threshold.
OWASP Dependency-Check (Maven + npm)
Process completed with exit code 1.
OWASP Dependency-Check (Maven + npm)
reampv2: 2 critical + 12 high npm vulnerabilities. Run 'npm audit' in amp/TEMPLATE/reampv2 for details.
OWASP Dependency-Check (Maven + npm)
dev: 1 critical + 16 high npm vulnerabilities. Run 'npm audit' in amp/TEMPLATE/ampTemplate/gisModule/dev for details.
OWASP Dependency-Check (Maven + npm)
dev: 1 critical + 6 high npm vulnerabilities. Run 'npm audit' in amp/TEMPLATE/ampTemplate/dashboard/dev for details.
OWASP Dependency-Check (Maven + npm)
gis-layers-manager: 0 critical + 9 high npm vulnerabilities. Run 'npm audit' in amp/TEMPLATE/ampTemplate/gis-layers-manager for details.
OWASP Dependency-Check (Maven + npm)
amp-settings: 0 critical + 5 high npm vulnerabilities. Run 'npm audit' in amp/TEMPLATE/ampTemplate/amp-settings for details.
OWASP Dependency-Check (Maven + npm)
amp-translate: 0 critical + 3 high npm vulnerabilities. Run 'npm audit' in amp/TEMPLATE/ampTemplate/amp-translate for details.
OWASP Dependency-Check (Maven + npm)
amp-filter: 0 critical + 5 high npm vulnerabilities. Run 'npm audit' in amp/TEMPLATE/ampTemplate/amp-filter for details.
OWASP Dependency-Check (Maven + npm)
amp-boilerplate: 0 critical + 4 high npm vulnerabilities. Run 'npm audit' in amp/TEMPLATE/ampTemplate/amp-boilerplate for details.
OWASP Dependency-Check (Maven + npm)
Process completed with exit code 1.
Trivy (Container Image)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Trivy (Container Image)
No files were found with the provided path: trivy-results.sarif. No artifacts will be uploaded.
Trivy (Container Image)
Docker build failed; skipping Trivy image scan
OWASP Dependency-Check (Maven + npm)
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/setup-node@v4, actions/upload-artifact@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
OWASP Dependency-Check (Maven + npm)
reamp (excluded from gate): 16 critical + 10 high known unfixable CVEs in build tooling (webpack 1 / babel 6). Requires migration to webpack 5 + babel 7.
Resolve target ref
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
Trivy (Container Image)
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
OWASP Dependency-Check (Maven + npm)
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"

Artifacts

Produced during runtime
Name Size Digest
npm-audit-reports
54.9 KB
sha256:9ebbe18345c10751c8d79c29798ea9a8d23c1df9c5324325f16893b1bb7fe1b7
owasp-dependency-check-report
3.42 MB
sha256:4e4eed60f3ae5c73ab1e8a79d325ac653c66409b6db856ba93ccbfca461d1a19