Skip to content

gh-actions: sbom and build attestation #1512

gh-actions: sbom and build attestation

gh-actions: sbom and build attestation #1512

Triggered via push November 18, 2025 13:59
Status Failure
Total duration 3m 13s
Artifacts 1

go.yml

on: push
Fit to window
Zoom out
Zoom in

Annotations

15 errors and 3 notices
🔐 Security checker
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/
🧭 Lint: intra/core/brsa/pss.go#L126
do not define dynamic errors, use wrapped static errors instead: "errors.New(\"rsa: internal error: inconsistent length\")" (err113)
🧭 Lint: intra/core/brsa/pss.go#L62
do not define dynamic errors, use wrapped static errors instead: "errors.New(\"crypto/rsa: key size too small for PSS signature\")" (err113)
🧭 Lint: intra/core/brsa/pss.go#L56
do not define dynamic errors, use wrapped static errors instead: "errors.New(\"crypto/rsa: input must be hashed with given hash\")" (err113)
🧭 Lint: intra/core/brsa/common.go#L106
do not define dynamic errors, use wrapped static errors instead: "errors.New(\"rsa: internal error\")" (err113)
🧭 Lint: intra/core/async.go#L95
do not define dynamic errors, use wrapped static errors instead: "errors.New(who + \" fn panicked\")" (err113)
🧭 Lint: intra/backend/ipn_wgkeygen.go#L99
do not define dynamic errors, use wrapped static errors instead: "errors.New(\"keys must decode to exactly 32 bytes\")" (err113)
🧭 Lint: intra/backend/ipn_wgkeygen.go#L96
do not define dynamic errors, use wrapped static errors instead: "fmt.Errorf(\"invalid key: %v\", err)" (err113)
🧭 Lint: intra/backend/ipn_pipkeygen.go#L374
do not define dynamic errors, use wrapped static errors instead: "fmt.Errorf(\"cannot decode key exponent: %v\", err)" (err113)
🧭 Lint: intra/backend/ipn_pipkeygen.go#L367
do not define dynamic errors, use wrapped static errors instead: "fmt.Errorf(\"cannot decode key modulus: %v\", err)" (err113)
🧭 Lint: intra/backend/ipn_pipkeygen.go#L362
do not define dynamic errors, use wrapped static errors instead: "fmt.Errorf(\"cannot unmarshal public key: %v\", err)" (err113)
🧬 Build
HttpError: Resource not accessible by integration - https://docs.github.com/rest/dependency-graph/dependency-submission#create-a-snapshot-of-dependencies-for-a-repository at /home/runner/work/_actions/advanced-security/spdx-dependency-submission-action/v0.1.1/webpack:/spdx-to-dependency-graph-action/node_modules/@octokit/request/dist-node/index.js:125:1 at processTicksAndRejections (node:internal/process/task_queues:95:5) at Object.L [as submitSnapshot] (/home/runner/work/_actions/advanced-security/spdx-dependency-submission-action/v0.1.1/webpack:/spdx-to-dependency-graph-action/node_modules/@github/dependency-submission-toolkit/dist/index.cjs:29:1)
🧬 Build
Response body: { "message": "Resource not accessible by integration", "documentation_url": "https://docs.github.com/rest/dependency-graph/dependency-submission#create-a-snapshot-of-dependencies-for-a-repository", "status": "403" }
🧬 Build
HTTP Status 403 for request POST https://api.github.com/repos/celzero/firestack/dependency-graph/snapshots
🧬 Build
{ "manifests": { "celzero/firestack 1.0.0": { "resolved": { "pkg:golang/github.com/patrickmn/go-cache@v2.1.0+incompatible": { "package_url": "pkg:golang/github.com/patrickmn/go-cache@v2.1.0+incompatible", "relationship": "direct", "dependencies": [] }, "pkg:golang/github.com/cloudflare/circl@v1.6.1": { "package_url": "pkg:golang/github.com/cloudflare/circl@v1.6.1", "relationship": "direct", "dependencies": [] }, "pkg:golang/github.com/jedisct1/go-dnsstamps@v0.0.0-20200621175006-302248eecc94": { "package_url": "pkg:golang/github.com/jedisct1/go-dnsstamps@v0.0.0-20200621175006-302248eecc94", "relationship": "direct", "dependencies": [] }, "pkg:golang/golang.org/x/crypto@v0.39.0": { "package_url": "pkg:golang/golang.org/x/crypto@v0.39.0", "relationship": "direct", "dependencies": [] }, "pkg:golang/github.com/noql-net/certpool@v0.0.0-20240719060413-a5ed62ecc62a": { "package_url": "pkg:golang/github.com/noql-net/certpool@v0.0.0-20240719060413-a5ed62ecc62a", "relationship": "direct", "dependencies": [] }, "pkg:golang/git.schwanenlied.me/yawning/x448.git@v0.0.0-20170617130356-01b048fb03d6": { "package_url": "pkg:golang/git.schwanenlied.me/yawning/x448.git@v0.0.0-20170617130356-01b048fb03d6", "relationship": "direct", "dependencies": [] }, "pkg:golang/github.com/snawoot/go-http-digest-auth-client@v1.1.3": { "package_url": "pkg:golang/github.com/snawoot/go-http-digest-auth-client@v1.1.3", "relationship": "direct", "dependencies": [] }, "pkg:golang/gvisor.dev/gvisor@v0.0.0-20250816201027-ba3b9ca85f20": { "package_url": "pkg:golang/gvisor.dev/gvisor@v0.0.0-20250816201027-ba3b9ca85f20", "relationship": "direct", "dependencies": [] }, "pkg:golang/golang.org/x/sync@v0.15.0": { "package_url": "pkg:golang/golang.org/x/sync@v0.15.0", "relationship": "direct", "dependencies": [] }, "pkg:golang/golang.zx2c4.com/wintun@v0.0.0-20230126152724-0fa3db229ce2": { "package_url": "pkg:golang/golang.zx2c4.com/wintun@v0.0.0-20230126152724-0fa3db229ce2", "relationship": "direct", "dependencies": [] }, "pkg:golang/golang.org/x/text@v0.26.0": { "package_url": "pkg:golang/golang.org/x/text@v0.26.0", "relationship": "direct", "dependencies": [] }, "pkg:golang/github.com/jedisct1/xsecretbox@v0.0.0-20190909160646-b731c21297f9": { "package_url": "pkg:golang/github.com/jedisct1/xsecretbox@v0.0.0-20190909160646-b731c21297f9", "relationship": "direct", "dependencies": [] }, "pkg:golang/github.com/cisco/go-tls-syntax@v0.0.0-20200617162716-46b0cfb76b9b": { "package_url": "pkg:golang/github.com/cisco/go-tls-syntax@v0.0.0-20200617162716-46b0cfb76b9b", "relationship": "direct", "dependencies": [] }, "pkg:golang/github.com/miekg/dns@v1.1.66": { "package_url": "pkg:golang/github.com/miekg/dns@v1.1.66", "relationship": "direct", "dependencies": [] }, "pkg:golang/gith
🧬 Build
Submitting snapshot...
🧬 Build
success

Artifacts

Produced during runtime
Name Size Digest
sbom Expired
39.1 KB
sha256:1942ac1de0adb17d5e4ee499020958e332916f87986426206d10f9e28e6f1fec