Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Refactor around GHA and npm pinning #154

Merged
merged 4 commits into from
Aug 8, 2024
Merged

Refactor around GHA and npm pinning #154

merged 4 commits into from
Aug 8, 2024

Conversation

wesley-dean-gsa
Copy link
Contributor

This pins a few missing GitHub Actions dependencies and instructs the Pa11y workflow to grab the dedDepenedencies (which includes pa11y-ci).

security considerations

This ought to resolve the remaining warnings about unpinned dependencies.

Copy link

github-actions bot commented Aug 7, 2024

🦙 MegaLinter status: ⚠️ WARNING

Descriptor Linter Files Fixed Errors Elapsed time
✅ ACTION actionlint 4 0 0.06s
⚠️ CSS scss-lint 2 1 2.97s
✅ JAVASCRIPT prettier 6 0 0 1.11s
✅ JSON jsonlint 7 0 0.21s
✅ JSON npm-package-json-lint yes no 0.5s
✅ JSON prettier 7 0 0 1.53s
✅ JSON v8r 7 0 10.49s
✅ MARKDOWN markdownlint 20 0 0 2.07s
✅ MARKDOWN markdown-link-check 20 0 11.99s
✅ MARKDOWN markdown-table-formatter 20 0 0 0.39s
✅ REPOSITORY checkov yes no 15.79s
✅ REPOSITORY gitleaks yes no 0.3s
✅ REPOSITORY git_diff yes no 0.23s
⚠️ REPOSITORY grype yes 2 14.49s
✅ REPOSITORY secretlint yes no 2.66s
⚠️ REPOSITORY trivy yes 1 8.97s
✅ REPOSITORY trivy-sbom yes no 1.65s
✅ REPOSITORY trufflehog yes no 4.16s
⚠️ SPELL cspell 20 1 3.15s
✅ YAML prettier 14 0 0 1.36s
✅ YAML v8r 11 0 13.37s
✅ YAML yamllint 14 0 0.7s

See detailed report in MegaLinter reports

MegaLinter is graciously provided by OX Security

Copy link

github-actions bot commented Aug 7, 2024

Pa11y testing results ``` Welcome to Pa11y

Running Pa11y on URL https://federalist-a2423046-fe43-4e75-a2ef-2651e5e123ca.sites.pages.cloud.gov/preview/gsa-tts/tts.gsa.gov//pin-gha/

Results for URL: https://federalist-a2423046-fe43-4e75-a2ef-2651e5e123ca.sites.pages.cloud.gov/preview/gsa-tts/tts.gsa.gov//pin-gha/

• Error: This element has insufficient contrast at this conformance level. Expected a contrast ratio of at least 4.5:1, but text in this element has a contrast ratio of 3.68:1. Recommendation: change background to #63686c.
├── WCAG2AA.Principle1.Guideline1_4.1_4_3.G18.Fail
├── #main-content > section:nth-child(3) > div > div > div:nth-child(2) > p
└──

For over 50 years, GSA has been...

• Error: Duplicate id attribute value "svg-bedding" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-bedding
└── <path d="M17 10.13a33.86 33.86 ...

• Error: Duplicate id attribute value "svg-camping" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-camping
└── <path fill-rule="evenodd" d="m1...

• Error: Duplicate id attribute value "svg-chevron_left" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-chevron_left
└── <path d="M0 0h24v24H0z" fill="n...

• Error: Duplicate id attribute value "svg-chevron_right" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-chevron_right
└── <path d="M0 0h24v24H0z" fill="n...

• Error: Duplicate id attribute value "svg-clothes" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-clothes
└── <path d="M15.7 2.37 15 2.3V4a3 ...

• Error: Duplicate id attribute value "svg-construction_worker" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-construction_worker
└── <circle cx="10.5" cy="4.5" r="1...

• Error: Duplicate id attribute value "svg-flickr" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-flickr
└── <path d="M6.459 17a4.444 4.444 ...

• Error: Duplicate id attribute value "svg-flooding" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-flooding
└── <path d="M17 18.16a6 6 0 0 0-2....

• Error: Duplicate id attribute value "svg-github" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-github
└── <path d="M12 2a10 10 0 0 0-3.16...

• Error: Duplicate id attribute value "svg-hospital" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-hospital
└── <path d="M19 3H5a2 2 0 0 0-2 2v...

• Error: Duplicate id attribute value "svg-hurricane" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-hurricane
└── <path d="M19 12a7 7 0 0 0-6.34-...

• Error: Duplicate id attribute value "svg-identification" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-identification
└── <path d="M11 14.14C11 13.38 9.3...

• Error: Duplicate id attribute value "svg-instagram" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-instagram
└── <path d="M8.273 3.063c-.958.045...

• Error: Duplicate id attribute value "svg-linkedin" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-linkedin
└── <path d="M19.667 3A1.322 1.322 ...

• Error: Duplicate id attribute value "svg-navigate_far_before" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-navigate_far_before
└── <path d="M11.41 7.41 10 6l-6 6 ...

• Error: Duplicate id attribute value "svg-navigate_far_next" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-navigate_far_next
└── <path d="m14 6-1.41 1.41L17.17 ...

• Error: Duplicate id attribute value "svg-rain" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-rain
└── <path d="M17.51 7A5.62 5.62 0 0...

• Error: Duplicate id attribute value "svg-severe_weather" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-severe_weather
└── <...

• Error: Duplicate id attribute value "svg-snow" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-snow
└── <path d="m20.76 14.07-.66-1.34-...

• Error: Duplicate id attribute value "svg-sort_arrow" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-sort_arrow
└── <path d="M15.17 15 13 17.17V6.8...

• Error: Duplicate id attribute value "svg-tornado" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-tornado
└── <path d="M13 16v-2h2.77c.08-.32...

• Error: Duplicate id attribute value "svg-twitter" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-twitter
└── <path d="M19.912 7.925v.527A11....

• Error: Duplicate id attribute value "svg-x" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-x
└── <path d="M13.522 10.775 19.48 4...

• Error: Duplicate id attribute value "svg-youtube" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-youtube
└── <path d="M19.816 5.389a2.469 2....

25 Errors

Copy link

github-actions bot commented Aug 7, 2024

Pa11y testing results ``` Welcome to Pa11y

Running Pa11y on URL https://federalist-a2423046-fe43-4e75-a2ef-2651e5e123ca.sites.pages.cloud.gov/preview/gsa-tts/tts.gsa.gov//pin-gha/

Results for URL: https://federalist-a2423046-fe43-4e75-a2ef-2651e5e123ca.sites.pages.cloud.gov/preview/gsa-tts/tts.gsa.gov//pin-gha/

• Error: This element has insufficient contrast at this conformance level. Expected a contrast ratio of at least 4.5:1, but text in this element has a contrast ratio of 3.68:1. Recommendation: change background to #63686c.
├── WCAG2AA.Principle1.Guideline1_4.1_4_3.G18.Fail
├── #main-content > section:nth-child(3) > div > div > div:nth-child(2) > p
└──

For over 50 years, GSA has been...

• Error: Duplicate id attribute value "svg-bedding" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-bedding
└── <path d="M17 10.13a33.86 33.86 ...

• Error: Duplicate id attribute value "svg-camping" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-camping
└── <path fill-rule="evenodd" d="m1...

• Error: Duplicate id attribute value "svg-chevron_left" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-chevron_left
└── <path d="M0 0h24v24H0z" fill="n...

• Error: Duplicate id attribute value "svg-chevron_right" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-chevron_right
└── <path d="M0 0h24v24H0z" fill="n...

• Error: Duplicate id attribute value "svg-clothes" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-clothes
└── <path d="M15.7 2.37 15 2.3V4a3 ...

• Error: Duplicate id attribute value "svg-construction_worker" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-construction_worker
└── <circle cx="10.5" cy="4.5" r="1...

• Error: Duplicate id attribute value "svg-flickr" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-flickr
└── <path d="M6.459 17a4.444 4.444 ...

• Error: Duplicate id attribute value "svg-flooding" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-flooding
└── <path d="M17 18.16a6 6 0 0 0-2....

• Error: Duplicate id attribute value "svg-github" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-github
└── <path d="M12 2a10 10 0 0 0-3.16...

• Error: Duplicate id attribute value "svg-hospital" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-hospital
└── <path d="M19 3H5a2 2 0 0 0-2 2v...

• Error: Duplicate id attribute value "svg-hurricane" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-hurricane
└── <path d="M19 12a7 7 0 0 0-6.34-...

• Error: Duplicate id attribute value "svg-identification" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-identification
└── <path d="M11 14.14C11 13.38 9.3...

• Error: Duplicate id attribute value "svg-instagram" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-instagram
└── <path d="M8.273 3.063c-.958.045...

• Error: Duplicate id attribute value "svg-linkedin" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-linkedin
└── <path d="M19.667 3A1.322 1.322 ...

• Error: Duplicate id attribute value "svg-navigate_far_before" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-navigate_far_before
└── <path d="M11.41 7.41 10 6l-6 6 ...

• Error: Duplicate id attribute value "svg-navigate_far_next" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-navigate_far_next
└── <path d="m14 6-1.41 1.41L17.17 ...

• Error: Duplicate id attribute value "svg-rain" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-rain
└── <path d="M17.51 7A5.62 5.62 0 0...

• Error: Duplicate id attribute value "svg-severe_weather" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-severe_weather
└── <...

• Error: Duplicate id attribute value "svg-snow" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-snow
└── <path d="m20.76 14.07-.66-1.34-...

• Error: Duplicate id attribute value "svg-sort_arrow" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-sort_arrow
└── <path d="M15.17 15 13 17.17V6.8...

• Error: Duplicate id attribute value "svg-tornado" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-tornado
└── <path d="M13 16v-2h2.77c.08-.32...

• Error: Duplicate id attribute value "svg-twitter" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-twitter
└── <path d="M19.912 7.925v.527A11....

• Error: Duplicate id attribute value "svg-x" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-x
└── <path d="M13.522 10.775 19.48 4...

• Error: Duplicate id attribute value "svg-youtube" found on the web page.
├── WCAG2AA.Principle4.Guideline4_1.4_1_1.F77
├── #svg-youtube
└── <path d="M19.816 5.389a2.469 2....

25 Errors

@wesley-dean-gsa wesley-dean-gsa marked this pull request as ready for review August 7, 2024 18:46
@wesley-dean-gsa wesley-dean-gsa requested a review from a team as a code owner August 7, 2024 18:46
@wesley-dean-gsa wesley-dean-gsa merged commit 294ee12 into main Aug 8, 2024
12 checks passed
@wesley-dean-gsa wesley-dean-gsa deleted the pin-gha branch August 8, 2024 16:48
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants