Skip to content

fix(security): Prevent GitHub script injection in update-tox workflow #13183

fix(security): Prevent GitHub script injection in update-tox workflow

fix(security): Prevent GitHub script injection in update-tox workflow #13183

Triggered via pull request April 29, 2026 11:46
Status Success
Total duration 4m 57s
Artifacts 18
Matrix: GraphQL
All GraphQL tests passed
3s
All GraphQL tests passed
Fit to window
Zoom out
Zoom in

Annotations

9 warnings
GraphQL (3.11, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
GraphQL (3.6, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
GraphQL (3.9, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
GraphQL (3.8, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
GraphQL (3.12, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
GraphQL (3.10, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
GraphQL (3.14, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
GraphQL (3.13, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
GraphQL (3.14t, ubuntu-22.04)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: getsentry/codecov-action@fda17cfc37e16a0cc23f61685813390bfee7daf3. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/

Artifacts

Produced during runtime
Name Size Digest
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-graphql
116 KB
sha256:4c9ff7e3553cb1eb178a7a2b4d79e1c7b01429b4255a199b8c29964a4e073b53
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-graphql
115 KB
sha256:1014649f1c8458618d7a3c00069f2ad414df6433beb82bc3070e8fd2c141c79d
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-graphql
115 KB
sha256:c9a3086cd9ac2bc93d7d2e10117772664d19d1a890ea0fc168983011854bb64c
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-graphql
115 KB
sha256:5ca213e286342c9a042b338ed240816522d421fc031131219b5a7b900137da33
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-graphql
115 KB
sha256:3bf638b2adba9ca9677cbe32d69ac281842c80bd2d561348cd30ad0078d49ad9
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-graphql
115 KB
sha256:9e7dcc7b69ca66358329faa897bb8d04627510029f4f1f53619840e0e06a44fb
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-graphql
115 KB
sha256:0d8d18268cf9e78c88922f3a1408c7dd38dcdc0eb2c626cd28d8c057ef9ad025
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-graphql
115 KB
sha256:7e701963bea66ada12485dd8c5dc93efaba48ccbf6ee0f6d480e8c4f19a5266b
codecov-coverage-results-fix-github-script-injection-vuln-1594-test-graphql
116 KB
sha256:2690046f9108493c8d70c34f26e9e0f1b262af98789e6a7579dc47ef29e38445
codecov-test-results-fix-github-script-injection-vuln-1594-test-graphql
232 Bytes
sha256:d7135d6b28350da070fb8d41103a166ce4447b6599326beaa7be12515fa222d9
codecov-test-results-fix-github-script-injection-vuln-1594-test-graphql
230 Bytes
sha256:18690e8cb094260b6f95385a902a7d65f5a04fb5a3c68714f95acaaa3e5a4cb7
codecov-test-results-fix-github-script-injection-vuln-1594-test-graphql
232 Bytes
sha256:069696b630a6974685968bee4553e9ad6b8537b26db67e557f89c2a11db6bc60
codecov-test-results-fix-github-script-injection-vuln-1594-test-graphql
232 Bytes
sha256:83c38c7456d9979cc74b170f90f4ef0a16dcd57040a2c33a671bb8b91fad544f
codecov-test-results-fix-github-script-injection-vuln-1594-test-graphql
230 Bytes
sha256:056b83c66c8d7b76b2085c71e066fa1199e2ef7231e1ff6259ab31c1ba2c031e
codecov-test-results-fix-github-script-injection-vuln-1594-test-graphql
238 Bytes
sha256:d144192c710b90d9b6e85d1ae0b225a5f11525afa457472886d37907ecf319ff
codecov-test-results-fix-github-script-injection-vuln-1594-test-graphql
238 Bytes
sha256:63a8bbb051c6afe55537e82e58c956172471051379a25495630c8955ac561b82
codecov-test-results-fix-github-script-injection-vuln-1594-test-graphql
237 Bytes
sha256:0f2e2c9eda53e35d9de443662ec3a2746a04dc717832975d02544537f763af16
codecov-test-results-fix-github-script-injection-vuln-1594-test-graphql
231 Bytes
sha256:52a3c153abc8047315e5165219dfe51c2d3903caf415a580b9cc8abf2a0c403f