Skip to content

ci

ci #1612

Triggered via schedule January 13, 2025 10:02
Status Success
Total duration 1m 13s
Artifacts 4

ci.yml

on: schedule
Matrix: annotations
Matrix: image
Matrix: threshold
Fit to window
Zoom out
Zoom in

Annotations

14 errors, 41 warnings, and 2 notices
annotations (alpine:3.9)
CVE-2021-23840 - HIGH severity - openssl: integer overflow in CipherUpdate vulnerability in libcrypto1.1
annotations (alpine:3.9)
CVE-2021-3450 - HIGH severity - openssl: CA certificate check bypass with X509_V_FLAG_X509_STRICT vulnerability in libcrypto1.1
annotations (alpine:3.9)
CVE-2021-23840 - HIGH severity - openssl: integer overflow in CipherUpdate vulnerability in libssl1.1
annotations (alpine:3.9)
CVE-2021-3450 - HIGH severity - openssl: CA certificate check bypass with X509_V_FLAG_X509_STRICT vulnerability in libssl1.1
threshold (alpine:3.10)
Container image is unhealthy. Following your desired severity threshold (HIGH), the job has been marked as failed.
annotations (moby/buildkit:master)
CVE-2024-45338 - HIGH severity - golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html vulnerability in golang.org/x/net
annotations (moby/buildkit:master)
CVE-2024-34156 - HIGH severity - encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion vulnerability in stdlib
annotations (moby/buildkit:master)
CVE-2024-34156 - HIGH severity - encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion vulnerability in stdlib
annotations (moby/buildkit:master)
CVE-2024-34156 - HIGH severity - encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion vulnerability in stdlib
annotations (moby/buildkit:master)
CVE-2024-34156 - HIGH severity - encoding/gob: golang: Calling Decoder.Decode on a message which contains deeply nested structures can cause a panic due to stack exhaustion vulnerability in stdlib
annotations (moby/buildkit:master)
CVE-2024-45338 - HIGH severity - golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html vulnerability in golang.org/x/net
annotations (moby/buildkit:master)
CVE-2024-45338 - HIGH severity - golang.org/x/net/html: Non-linear parsing of case-insensitive content in golang.org/x/net/html vulnerability in golang.org/x/net
threshold (moby/buildkit:master)
Container image is unhealthy. Following your desired severity threshold (HIGH), the job has been marked as failed.
threshold (alpine:3.9)
Container image is unhealthy. Following your desired severity threshold (HIGH), the job has been marked as failed.
annotations (alpine:latest)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
annotations (alpine:latest)
Dockerfile not provided. Skipping sarif scan result.
image (alpine:latest)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
image (alpine:latest)
Dockerfile not provided. Skipping sarif scan result.
annotations (alpine:3.9)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
annotations (alpine:3.9)
Dockerfile not provided. Skipping sarif scan result.
annotations (alpine:3.9)
CVE-2020-1971 - MEDIUM severity - openssl: EDIPARTYNAME NULL pointer de-reference vulnerability in libcrypto1.1
annotations (alpine:3.9)
CVE-2021-23841 - MEDIUM severity - openssl: NULL pointer dereference in X509_issuer_and_serial_hash() vulnerability in libcrypto1.1
annotations (alpine:3.9)
CVE-2021-3449 - MEDIUM severity - openssl: NULL pointer dereference in signature_algorithms processing vulnerability in libcrypto1.1
annotations (alpine:3.9)
CVE-2020-1971 - MEDIUM severity - openssl: EDIPARTYNAME NULL pointer de-reference vulnerability in libssl1.1
annotations (alpine:3.9)
CVE-2021-23841 - MEDIUM severity - openssl: NULL pointer dereference in X509_issuer_and_serial_hash() vulnerability in libssl1.1
annotations (alpine:3.9)
CVE-2021-3449 - MEDIUM severity - openssl: NULL pointer dereference in signature_algorithms processing vulnerability in libssl1.1
annotations (alpine:3.9)
CVE-2020-28928 - MEDIUM severity - In musl libc through 1.2.1, wcsnrtombs mishandles particular combinati ... vulnerability in musl
annotations (alpine:3.9)
CVE-2020-28928 - MEDIUM severity - In musl libc through 1.2.1, wcsnrtombs mishandles particular combinati ... vulnerability in musl-utils
image (alpine:3.9)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
image (alpine:3.9)
Dockerfile not provided. Skipping sarif scan result.
threshold (alpine:3.10)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
threshold (alpine:3.10)
Dockerfile not provided. Skipping sarif scan result.
annotations (moby/buildkit:master)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
annotations (moby/buildkit:master)
Dockerfile not provided. Skipping sarif scan result.
annotations (moby/buildkit:master)
CVE-2024-24791 - MEDIUM severity - net/http: Denial of service due to improper 100-continue handling in net/http vulnerability in stdlib
annotations (moby/buildkit:master)
CVE-2024-34155 - MEDIUM severity - go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion vulnerability in stdlib
annotations (moby/buildkit:master)
CVE-2024-34158 - MEDIUM severity - go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion vulnerability in stdlib
annotations (moby/buildkit:master)
CVE-2024-24791 - MEDIUM severity - net/http: Denial of service due to improper 100-continue handling in net/http vulnerability in stdlib
annotations (moby/buildkit:master)
CVE-2024-34155 - MEDIUM severity - go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion vulnerability in stdlib
annotations (moby/buildkit:master)
CVE-2024-34158 - MEDIUM severity - go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion vulnerability in stdlib
annotations (moby/buildkit:master)
CVE-2024-24791 - MEDIUM severity - net/http: Denial of service due to improper 100-continue handling in net/http vulnerability in stdlib
annotations (moby/buildkit:master)
CVE-2024-34155 - MEDIUM severity - go/parser: golang: Calling any of the Parse functions containing deeply nested literals can cause a panic/stack exhaustion vulnerability in stdlib
annotations (moby/buildkit:master)
CVE-2024-34158 - MEDIUM severity - go/build/constraint: golang: Calling Parse on a "// +build" build tag line with deeply nested expressions can cause a panic due to stack exhaustion vulnerability in stdlib
image (moby/buildkit:master)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
image (moby/buildkit:master)
Dockerfile not provided. Skipping sarif scan result.
threshold (moby/buildkit:master)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
threshold (moby/buildkit:master)
Dockerfile not provided. Skipping sarif scan result.
threshold (alpine:3.9)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
threshold (alpine:3.9)
Dockerfile not provided. Skipping sarif scan result.
threshold (alpine:latest)
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
threshold (alpine:latest)
Dockerfile not provided. Skipping sarif scan result.
tarball
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
tarball
Dockerfile not provided. Skipping sarif scan result.
sarif
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
build-scan-push
ubuntu-latest pipelines will use ubuntu-24.04 soon. For more details, see https://github.com/actions/runner-images/issues/10636
annotations (alpine:3.9)
CVE-2021-23839 - LOW severity - openssl: incorrect SSLv2 rollback protection vulnerability in libcrypto1.1
annotations (alpine:3.9)
CVE-2021-23839 - LOW severity - openssl: incorrect SSLv2 rollback protection vulnerability in libssl1.1

Artifacts

Produced during runtime
Name Size
crazy-max~ghaction-container-scan~2505WV.dockerbuild
31.8 KB
crazy-max~ghaction-container-scan~4XF902.dockerbuild
14.8 KB
crazy-max~ghaction-container-scan~M4IRUE.dockerbuild
15.3 KB
crazy-max~ghaction-container-scan~WQI496.dockerbuild
15 KB