Skip to content

Update ZAP integration to use the correct GitHub Actions repository#52

Merged
CalinL merged 1 commit intomainfrom
feature/update25
Apr 22, 2025
Merged

Update ZAP integration to use the correct GitHub Actions repository#52
CalinL merged 1 commit intomainfrom
feature/update25

Conversation

@CalinL
Copy link
Contributor

@CalinL CalinL commented Apr 22, 2025

No description provided.

@github-actions
Copy link

github-actions bot commented Apr 22, 2025

Dependency Review

The following issues were found:
  • ✅ 0 vulnerable package(s)
  • ✅ 0 package(s) with incompatible licenses
  • ✅ 0 package(s) with invalid SPDX license definitions
  • ⚠️ 1 package(s) with unknown licenses.
See the Details below.

Snapshot Warnings

⚠️: No snapshots were found for the head SHA 7e135ee.
Ensure that dependencies are being submitted on PR branches and consider enabling retry-on-snapshot-warnings. See the documentation for more information and troubleshooting advice.

License Issues

.github/workflows/DAST-ZAP-Zed-Attach-Proxy-Checkmarx.yml

PackageVersionLicenseIssue Type
githubabcs-devops/zap-to-ghasmainNullUnknown License
Allowed Licenses: MIT, Apache-2.0, GPL-3.0

OpenSSF Scorecard

PackageVersionScoreDetails
actions/githubabcs-devops/zap-to-ghas main UnknownUnknown

Scanned Files

  • .github/workflows/DAST-ZAP-Zed-Attach-Proxy-Checkmarx.yml

@CalinL CalinL merged commit 832b08d into main Apr 22, 2025
14 checks passed
@CalinL CalinL deleted the feature/update25 branch April 22, 2025 15:50
run: |
ls
- uses: SvanBoxel/zaproxy-to-ghas@main
- uses: githubabcs-devops/zap-to-ghas@main

Check warning

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'DAST - Zed Attack Proxy (ZAP) Full Scan' step
Uses Step
uses 'githubabcs-devops/zap-to-ghas' with ref 'main', not a pinned commit hash
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant