Skip to content

fix(security): Prevent GitHub script injection in update-tox workflow #7862

fix(security): Prevent GitHub script injection in update-tox workflow

fix(security): Prevent GitHub script injection in update-tox workflow #7862

Triggered via pull request April 29, 2026 11:46
Status Success
Total duration 4m 44s
Artifacts 14

test-integrations-flags.yml

on: pull_request
Matrix: Flags
All Flags tests passed
2s
All Flags tests passed
Fit to window
Zoom out
Zoom in

Annotations

7 warnings
Flags (3.7, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Flags (3.10, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Flags (3.12, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Flags (3.8, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Flags (3.14t, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Flags (3.14, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Flags (3.13, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/

Artifacts

Produced during runtime
Name Size Digest
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-flags
116 KB
sha256:10b3dfd6f1dc444bd5003217e5fd91e5411b1bed635a4fbd864df2355c0d823f
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-flags
117 KB
sha256:faae6eef371a6d7735cc7a38780af11a4f162f130b9fe1dc47abbebb6093633c
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-flags
117 KB
sha256:adca2ab24325c8a2b848a1ef98fb55d1ca270f765ef4b50e627eb1bff1ad8dcc
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-flags
116 KB
sha256:c84021eeb9deff1e6149b9d37d8ccb62444ab89c300aaa1202c8acd2ea6ee1d7
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-flags
117 KB
sha256:f35886c204abc2c39ac4f50c17a78b21c5e623ca49831350ecaadff0c04a22fb
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-flags
117 KB
sha256:499224745723978289f8810ba1ac892b3f7029b10a4d0f1e471035f58db40e79
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-flags
117 KB
sha256:c5b2f1057222370500a68efa2f6ceb75d328a5095e78c8e4a8bbcb8cb6d881aa
codecov-test-results-fix-github-script-injection-vuln-1594-test-flags
228 Bytes
sha256:5d9b1544eb1c4173b4cebd33385eefe46e960b0e0ae3e53481eda519500181ca
codecov-test-results-fix-github-script-injection-vuln-1594-test-flags
229 Bytes
sha256:e6959b2317720f78c62f2c6e42b560575b62ca227b71c1a8d6cfc6895c777f27
codecov-test-results-fix-github-script-injection-vuln-1594-test-flags
231 Bytes
sha256:9267be8b2f97880cd7d2aa2d43f9653f95d88d944748fbc1f6355e2cce9e00ac
codecov-test-results-fix-github-script-injection-vuln-1594-test-flags
230 Bytes
sha256:c9e3c4596b744ce9fc7e3f27560b6bd75eeae564dd01e08b4e65b79f02f9c214
codecov-test-results-fix-github-script-injection-vuln-1594-test-flags
230 Bytes
sha256:f9ea891cefea1865694c3e857831affc2d8edf9df7288b182e60e76b30c2b025
codecov-test-results-fix-github-script-injection-vuln-1594-test-flags
231 Bytes
sha256:e4e6e71c8bcb35146f72f83cd68a92020fbe9f3d35151d84aae80de7821a5948
codecov-test-results-fix-github-script-injection-vuln-1594-test-flags
230 Bytes
sha256:d7d6d49a898cab671604abedef671b93d8731384708db07fb39bdcceafe262f9