Skip to content

fix(security): Prevent GitHub script injection in update-tox workflow #3189

fix(security): Prevent GitHub script injection in update-tox workflow

fix(security): Prevent GitHub script injection in update-tox workflow #3189

Triggered via pull request April 29, 2026 11:46
Status Success
Total duration 4m 15s
Artifacts 10

test-integrations-mcp.yml

on: pull_request
Matrix: MCP
All MCP tests passed
4s
All MCP tests passed
Fit to window
Zoom out
Zoom in

Annotations

5 warnings
MCP (3.14, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
MCP (3.10, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
MCP (3.14t, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
MCP (3.12, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
MCP (3.13, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/

Artifacts

Produced during runtime
Name Size Digest
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-mcp
116 KB
sha256:44c71fcdde8c47f71ce4f263b9b39b6a8f1d14f30cbb055467e083d6339b23b0
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-mcp
114 KB
sha256:32eef7820713d1d707dfe50b4a914b9f1882699bb2c2b89829e031e5080545d0
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-mcp
116 KB
sha256:a1d6f9e003c85a37121a9b78881c8cea1973742fecfdce3836ef5c0061e0c238
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-mcp
115 KB
sha256:80c68d4acba9567f08596217c9f09bb1444d98987e192cec60ef59b8fc554f2b
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-mcp
115 KB
sha256:7665d75eaa6ccd436d99bd77506ba54511ef47f4d50b56c973494fdb260a7213
codecov-test-results-fix-github-script-injection-vuln-1594-test-mcp
239 Bytes
sha256:fdb8b0abeba2aa4fe9391fb750f48d55452aed0e6dae3dc2cc38590bec55075b
codecov-test-results-fix-github-script-injection-vuln-1594-test-mcp
232 Bytes
sha256:b6cdbc1ad3e38a9ddafc933869ec02ea5609e0603a4e204aac2cd31905162f9d
codecov-test-results-fix-github-script-injection-vuln-1594-test-mcp
232 Bytes
sha256:45658e48d69d7eb4d82d7017eb57a673dfc96124cc5a28bf52a271580420c13f
codecov-test-results-fix-github-script-injection-vuln-1594-test-mcp
231 Bytes
sha256:1f3196af41549605f2556715c5384a41e81bcfc3b18bd161a8709c88bb378cba
codecov-test-results-fix-github-script-injection-vuln-1594-test-mcp
232 Bytes
sha256:cae278a12e37d80485d088e844cdd04e398edd6eec797fe32c383c91b7b9edea