Skip to content

Security Guard

Security Guard #1855

Triggered via pull request April 3, 2026 18:37
Status Success
Total duration 8m 59s
Artifacts 6

security-guard.lock.yml

on: pull_request
Fit to window
Zoom out
Zoom in

Annotations

2 errors, 12 warnings, and 1 notice
safe_outputs
✗ Message 1 (add_comment) failed: Resource not accessible by integration
safe_outputs
Failed to add comment: Resource not accessible by integration
activation
File workflows/security-guard.md contains front matter which will be ignored in runtime import
activation
Template-like syntax detected and escaped. This is a defense-in-depth measure to prevent potential template injection if content is processed by downstream template engines. GitHub's markdown rendering does not evaluate template syntax.
activation
Template-like syntax detected and escaped. This is a defense-in-depth measure to prevent potential template injection if content is processed by downstream template engines. GitHub's markdown rendering does not evaluate template syntax.
agent
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
agent
Failed to process file /tmp/gh-aw/mcp-logs/rpc-messages.jsonl: EACCES: permission denied, open '/tmp/gh-aw/mcp-logs/rpc-messages.jsonl'
agent
Failed to process file /tmp/gh-aw/mcp-logs/mcp-gateway.log: EACCES: permission denied, open '/tmp/gh-aw/mcp-logs/mcp-gateway.log'
agent
GitHub MCP lockdown mode enabled for public repository. This prevents the GitHub token from accessing private repositories.
detection
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
safe_outputs
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
safe_outputs
1 message(s) failed to process
safe_outputs
Template-like syntax detected and escaped. This is a defense-in-depth measure to prevent potential template injection if content is processed by downstream template engines. GitHub's markdown rendering does not evaluate template syntax.
conclusion
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/download-artifact@018cc2cf5baa6db3ef3c5f8a56943fffe632ef53. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
agent
Safe Outputs MCP Server Startup Log

Artifacts

Produced during runtime
Name Size Digest
agent-artifacts
309 KB
sha256:3cc9b6473d66f6a9948dd1cddac22f4b65e292e489bfcb41b8d9d4d87bd8da62
agent-output
1.99 KB
sha256:6b40b6e76efeedd5eaaf1a499b4f015d3985b7d217a67954c8ccce5b83bc4d9a
prompt Expired
6.33 KB
sha256:6fbe7f70d5578a67011e39a8c5315073607a6e6fd8275e5f3ec5eabfc8d3312b
safe-output
1.97 KB
sha256:0ff488f449bf8990abb4719a2d36248c356abac7e2acc1afe886b734247da826
safe-output-items
162 Bytes
sha256:2cd61fd2c688285f9c62f7562170cda1569138504b2a128f0f05b75f0706cbe6
threat-detection.log
19 KB
sha256:72f9dac932f040af45172935d7ab9b1bc4c0879ff178acd5f2b9f12efbac1b6f