Skip to content

[main] Upgrade to latest dependencies #698

[main] Upgrade to latest dependencies

[main] Upgrade to latest dependencies #698

Triggered via pull request January 28, 2025 13:44
Status Success
Total duration 4m 35s
Artifacts

knative-security.yaml

on: pull_request
analyze  /  Analyze CodeQL
4m 23s
analyze / Analyze CodeQL
analyze  /  Check Unicode CC
21s
analyze / Check Unicode CC
analyze  /  Go vulnerability Detection
44s
analyze / Go vulnerability Detection
Fit to window
Zoom out
Zoom in

Annotations

9 errors and 3 warnings
analyze / Go vulnerability Detection
eventmesh.BuildEventMesh calls gentype.alsoLister[*knative.dev/eventing/pkg/apis/eventing/v1.Trigger, *knative.dev/eventing/pkg/apis/eventing/v1.TriggerList].List[*knative.dev/eventing/pkg/apis/eventing/v1.Trigger *knative.dev/eventing/pkg/apis/eventing/v1.TriggerList], which eventually calls http.Client.Do
analyze / Go vulnerability Detection
eventmesh.Endpoint.GetEventMesh calls versioned.NewForConfig, which eventually calls x509.CertPool.AppendCertsFromPEM
analyze / Go vulnerability Detection
eventmesh.decodeSpec calls bytes.Buffer.ReadFrom, which eventually calls x509.Certificate.Verify
analyze / Go vulnerability Detection
eventmesh.decodeSpec calls bytes.Buffer.ReadFrom, which eventually calls x509.Certificate.VerifyHostname
analyze / Go vulnerability Detection
eventmesh.NewStrictHandler calls x509.HostnameError.Error
analyze / Go vulnerability Detection
eventmesh.startWebServer calls kncloudevents.HTTPEventReceiver.StartListen, which eventually calls x509.ParseCertificate
analyze / Go vulnerability Detection
eventmesh.startWebServer calls kncloudevents.HTTPEventReceiver.StartListen, which eventually calls x509.ParseECPrivateKey
analyze / Go vulnerability Detection
eventmesh.startWebServer calls kncloudevents.HTTPEventReceiver.StartListen, which eventually calls x509.ParsePKCS1PrivateKey
analyze / Go vulnerability Detection
eventmesh.startWebServer calls kncloudevents.HTTPEventReceiver.StartListen, which eventually calls x509.ParsePKCS8PrivateKey
analyze / Check Unicode CC
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
analyze / Go vulnerability Detection
Restore cache failed: Dependencies file is not found in /home/runner/work/backstage-plugins/backstage-plugins. Supported file pattern: go.sum
analyze / Analyze CodeQL
Restore cache failed: Dependencies file is not found in /home/runner/work/backstage-plugins/backstage-plugins. Supported file pattern: go.sum