Skip to content

fix(security): Prevent GitHub script injection in update-tox workflow #3189

fix(security): Prevent GitHub script injection in update-tox workflow

fix(security): Prevent GitHub script injection in update-tox workflow #3189

Triggered via pull request April 29, 2026 11:46
Status Success
Total duration 6m 27s
Artifacts 12
Matrix: AI Workflow
All AI Workflow tests passed
2s
All AI Workflow tests passed
Fit to window
Zoom out
Zoom in

Annotations

6 warnings
AI Workflow (3.11, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
AI Workflow (3.10, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
AI Workflow (3.9, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
AI Workflow (3.12, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
AI Workflow (3.13, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
AI Workflow (3.14, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/

Artifacts

Produced during runtime
Name Size Digest
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-ai_workflow
115 KB
sha256:539dd0c56ef61927c77aade818b50b18ec5f0af49bb859fff6efe90a93b4e2a7
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-ai_workflow
115 KB
sha256:f56bf5e057a31619db141d8e3fff136748acbfcf7ca6c7f802e838136e5e8fb4
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-ai_workflow
115 KB
sha256:583ddf7a841e9e6b73a0bef58cd23e03aa82e55147fae4dfe1f2c7cb6baf9029
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-ai_workflow
115 KB
sha256:2e1e8f1cf9b67da067fae8f3bc6459d2c32cf3bbf2acf7111bbab08b405646c0
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-ai_workflow
115 KB
sha256:e65884abe49f13ed9a446bd8a6eeff7d85e0a9204d29a6b6fa5b31c0566a9a1b
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-ai_workflow
115 KB
sha256:1e93eb873048649aff12d110d78f610040fcb1941fd1cde6e4d8132ba87d75e4
codecov-test-results-fix-github-script-injection-vuln-1594-test-ai_workflow
241 Bytes
sha256:f66cbea87789ae0f3b3c823370f9e7ea586b227e918c18bfece8000b77447c39
codecov-test-results-fix-github-script-injection-vuln-1594-test-ai_workflow
230 Bytes
sha256:d4f085720715c1af22d68985faaec6726e29687d8e43b3497f176e062b57d936
codecov-test-results-fix-github-script-injection-vuln-1594-test-ai_workflow
231 Bytes
sha256:8b1033a87dc1674459a5ba75a24dc7566403cc5b0d2b587026274bbe5589e1cd
codecov-test-results-fix-github-script-injection-vuln-1594-test-ai_workflow
232 Bytes
sha256:39da65d2f90006b95ab11d4780a22c52dac0a9316d3b59de65cb9c52b4f54920
codecov-test-results-fix-github-script-injection-vuln-1594-test-ai_workflow
232 Bytes
sha256:9da06b1e957d99d00fd408fe58ea5860cb1df610a8d2133747f10608773a074c
codecov-test-results-fix-github-script-injection-vuln-1594-test-ai_workflow
230 Bytes
sha256:a9b46e250a0af42ecf25cd846a57cdcc7ede3f765ee4cefe712e352c3db24043