chore(deps): update github actions (major) #47
Triggered via pull request
September 25, 2026 04:07
renovate-bot
synchronize
#112
Status
Failure
Total duration
45s
Artifacts
–
github_actions_scan.yml Required
on: pull_request_target
Annotations
3 errors, 7 warnings, and 5 notices
|
zizmor-output
Process completed with exit code 1.
|
|
dangerous-triggers:
.github/workflows/skills-validate.yml#L17
skills-validate.yml:17: use of fundamentally insecure workflow trigger: pull_request_target is almost always used insecurely
|
|
dangerous-triggers:
.github/workflows/assign-prs.yml#L17
assign-prs.yml:17: use of fundamentally insecure workflow trigger: pull_request_target is almost always used insecurely
|
|
Workflow execution policy warning (evaluate mode):
google-gh-automation/workflows/.github/workflows/github_actions_scan.yml#L1
On November 2, 2026, GitHub will restrict `pull_request_target` on public repositories by default. To continue allowing the event trigger, configure an Actions policy. Learn more: https://gh.io/securely-using-pull_request_target#default-policy-for-pull_request_target
|
|
zizmor-config
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: google-github-actions/auth@c200f3691d83b41bf9bbd8638997a462592937ed. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
zizmor-upload
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: google-github-actions/auth@c200f3691d83b41bf9bbd8638997a462592937ed. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
excessive-permissions:
.github/workflows/skills-validate.yml#L30
skills-validate.yml:30: overly broad permissions: default permissions used due to no permissions: block
|
|
excessive-permissions:
.github/workflows/markdown-checks.yml#L22
markdown-checks.yml:22: overly broad permissions: default permissions used due to no permissions: block
|
|
excessive-permissions:
.github/workflows/json-lint.yml#L22
json-lint.yml:22: overly broad permissions: default permissions used due to no permissions: block
|
|
excessive-permissions:
.github/workflows/header-check.yml#L22
header-check.yml:22: overly broad permissions: default permissions used due to no permissions: block
|
|
check-changes
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
zizmor-config
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
zizmor-scan
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
zizmor-upload
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
|
zizmor-output
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|