Skip to content

chore(deps): bump the github-actions group with 7 updates - #960

Merged
guibranco merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-93c82d5a1a
Jul 10, 2026
Merged

chore(deps): bump the github-actions group with 7 updates#960
guibranco merged 1 commit into
mainfrom
dependabot/github_actions/github-actions-93c82d5a1a

chore(deps): bump the github-actions group with 7 updates

1b31ece
Select commit
Loading
Failed to load commit list.
SonarQubeCloud / SonarCloud Code Analysis failed Jul 10, 2026 in 33s

Quality Gate failed

Failed conditions
E Security Rating on New Code (required ≥ A)

See analysis details on SonarQube Cloud

Catch issues before they fail your Quality Gate with our IDE extension SonarQube for IDE

Annotations

Check warning on line 37 in .github/workflows/release.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

"PASSWORD" detected here, make sure this is not a hard-coded credential.

See more on https://sonarcloud.io/project/issues?id=guibranco_CrispyWaffle&issues=AZ9MgONgbXNPmtFB6CUt&open=AZ9MgONgbXNPmtFB6CUt&pullRequest=960

Check warning on line 174 in .github/workflows/release.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Avoid expanding secrets in a run block.

See more on https://sonarcloud.io/project/issues?id=guibranco_CrispyWaffle&issues=AZ9MgONgbXNPmtFB6CUq&open=AZ9MgONgbXNPmtFB6CUq&pullRequest=960

Check warning on line 170 in .github/workflows/release.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.

See more on https://sonarcloud.io/project/issues?id=guibranco_CrispyWaffle&issues=AZ9MgONgbXNPmtFB6CUr&open=AZ9MgONgbXNPmtFB6CUr&pullRequest=960

Check failure on line 255 in .github/workflows/release.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Use full commit SHA hash for this dependency.

See more on https://sonarcloud.io/project/issues?id=guibranco_CrispyWaffle&issues=AZ9MgONgbXNPmtFB6CUs&open=AZ9MgONgbXNPmtFB6CUs&pullRequest=960

Check warning on line 22 in .github/workflows/build.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

"PASSWORD" detected here, make sure this is not a hard-coded credential.

See more on https://sonarcloud.io/project/issues?id=guibranco_CrispyWaffle&issues=AZ9MgOLDbXNPmtFB6CUp&open=AZ9MgOLDbXNPmtFB6CUp&pullRequest=960

Check failure on line 63 in .github/workflows/build.yml

See this annotation in the file changed.

@sonarqubecloud sonarqubecloud / SonarCloud Code Analysis

Avoid executing downloaded artifacts directly without verification.

See more on https://sonarcloud.io/project/issues?id=guibranco_CrispyWaffle&issues=AZ9MgOLDbXNPmtFB6CUo&open=AZ9MgOLDbXNPmtFB6CUo&pullRequest=960