Skip to content

feat(security): trust chain — workspace trust, config trust, MCP approval #99

feat(security): trust chain — workspace trust, config trust, MCP approval

feat(security): trust chain — workspace trust, config trust, MCP approval #99

Triggered via pull request March 23, 2026 01:16
Status Success
Total duration 3m 1s
Artifacts

devsecops.yml

on: pull_request
Secret Scanning (gitleaks)
7s
Secret Scanning (gitleaks)
License & Ban Check (cargo-deny)
2m 57s
License & Ban Check (cargo-deny)
Dependency Audit (cargo-audit)
0s
Dependency Audit (cargo-audit)
Clippy Security Lints
0s
Clippy Security Lints
Trivy Vulnerability Scan
0s
Trivy Vulnerability Scan
Weekly SBOM
0s
Weekly SBOM
Fit to window
Zoom out
Zoom in

Annotations

2 warnings
Secret Scanning (gitleaks)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
License & Ban Check (cargo-deny)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/