Skip to content

feat: prod-readiness PR 3 of 5 — supply chain & bundle integrity #76

feat: prod-readiness PR 3 of 5 — supply chain & bundle integrity

feat: prod-readiness PR 3 of 5 — supply chain & bundle integrity #76

Triggered via pull request April 28, 2026 09:16
Status Success
Total duration 33s
Artifacts 1

security.yml

on: pull_request
OSV-Scanner (SCA)
7s
OSV-Scanner (SCA)
Trivy (filesystem + container scan)
28s
Trivy (filesystem + container scan)
Semgrep (SAST)
28s
Semgrep (SAST)
Gitleaks (secret scan)
12s
Gitleaks (secret scan)
jscpd (duplication < 3% on touched code)
15s
jscpd (duplication < 3% on touched code)
SBOM (SPDX + CycloneDX)
8s
SBOM (SPDX + CycloneDX)
Fit to window
Zoom out
Zoom in

Artifacts

Produced during runtime
Name Size Digest
sbom
31 KB
sha256:218d976b30895295541949e64c70bbb24ed0c7adff92b6dbb9e9cd0d83708d54