Skip to content

[StepSecurity] ci: Harden GitHub Actions #5147

[StepSecurity] ci: Harden GitHub Actions

[StepSecurity] ci: Harden GitHub Actions #5147

Re-run triggered October 28, 2024 18:44
Status Failure
Total duration 2m 13s
Artifacts

build.yml

on: pull_request
Config  /  ...  /  Convert platforms CSV to JSON
7s
Config / Convert CSV to JSON / Convert platforms CSV to JSON
Artifact key
10s
Artifact key
Docker secrets
8s
Docker secrets
Foundry secrets
8s
Foundry secrets
Diagnostics  /  Diagnostics
25s
Diagnostics / Diagnostics
Metadata  /  Calculate variables
12s
Metadata / Calculate variables
Build pre-installed test image  /  Build image
Build pre-installed test image / Build image
Build normal test image  /  Build image
Build normal test image / Build image
Test pre-installed image  /  Test image
Test pre-installed image / Test image
Test normal image  /  Test image
Test normal image / Test image
Matrix: Build platform
Waiting for pending jobs
Publish image  /  Load and push multi-arch image
Publish image / Load and push multi-arch image
Matrix: Bill of Materials
Waiting for pending jobs
Publish docs  /  publish
Publish docs / publish
Fit to window
Zoom out
Zoom in

Annotations

4 errors and 12 warnings
Docker secrets
Process completed with exit code 1.
Foundry secrets
Process completed with exit code 1.
Artifact key
Process completed with exit code 1.
Lint / Lint sources
Process completed with exit code 1.
Docker secrets
Set the DOCKER_USERNAME secret.
Docker secrets
Set the DOCKER_PASSWORD secret.
Docker secrets
egress-policy is set to block (default) and allowed-endpoints is empty. No outbound traffic will be allowed for job steps.
Foundry secrets
Set the FOUNDRY_USERNAME secret.
Foundry secrets
Set the FOUNDRY_PASSWORD secret.
Foundry secrets
egress-policy is set to block (default) and allowed-endpoints is empty. No outbound traffic will be allowed for job steps.
Config / Convert CSV to JSON / Convert platforms CSV to JSON
egress-policy is set to block (default) and allowed-endpoints is empty. No outbound traffic will be allowed for job steps.
Artifact key
egress-policy is set to block (default) and allowed-endpoints is empty. No outbound traffic will be allowed for job steps.
Artifact key
Set the ARTIFACT_KEY secret.
Lint / Lint sources: .github/workflows/scorecards.yml#L31
31:84 [comments] too few spaces before comment
Lint / Lint sources: .github/workflows/label-automerge.yml#L22
22:84 [comments] too few spaces before comment
Lint / Lint sources
Restore cache failed: Dependencies file is not found in /home/runner/work/foundryvtt-docker/foundryvtt-docker. Supported file pattern: go.sum