Skip to content

Scans Failing Due To Vulnerable Dependencies (AST-151094)#1478

Merged
cx-aniket-shinde merged 39 commits into
mainfrom
other/scan-and-workflow
Apr 29, 2026
Merged

Scans Failing Due To Vulnerable Dependencies (AST-151094)#1478
cx-aniket-shinde merged 39 commits into
mainfrom
other/scan-and-workflow

Conversation

@cx-aniket-shinde
Copy link
Copy Markdown
Contributor

By submitting this pull request, you agree to the terms within the Checkmarx Code of Conduct. Please review the contributing guidelines for guidance on creating high-quality pull requests.

Description

Please provide a summary of the changes and the related issue. Include relevant motivation and context.

Type of Change

  • Bug fix (non-breaking change which fixes an issue)
  • New feature (non-breaking change which adds functionality)
  • Breaking change (fix or feature that would cause existing functionality to not work as expected)
  • Documentation update

Related Issues

Link any related issues or tickets.

Checklist

  • I have performed a self-review of my code
  • I have added tests that prove my fix is effective or that my feature works
  • I have added necessary documentation (if appropriate)
  • Any dependent changes have been merged and published in downstream modules
  • I have updated the CLI help for new/changed functionality in this PR (if applicable)
  • All active GitHub checks for tests, formatting, and security are passing
  • The correct base branch is being used

Screenshots (if applicable)

Add screenshots to help explain your changes.

Additional Notes

Add any other relevant information.

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Apr 22, 2026

Logo
Checkmarx One – Scan Summary & Detailsbebfae30-c699-4e59-865e-359ff12b4c1b


Fixed Issues (5) Great job! The following issues were fixed in this Pull Request
Severity Issue Source File / Package
HIGH CVE-2024-25621 Go-github.com/containerd/containerd/v2-v2.1.2
HIGH CVE-2026-24051 Go-go.opentelemetry.io/otel/sdk-v1.39.0
HIGH CVE-2026-39883 Go-go.opentelemetry.io/otel/sdk-v1.39.0
HIGH CVE-2026-40890 Go-github.com/gomarkdown/markdown-v0.0.0-20241102151059-6bc1ffdc6e8c
MEDIUM CVE-2025-64329 Go-github.com/containerd/containerd/v2-v2.1.2

@cx-anurag-dalke cx-anurag-dalke changed the title Scans failing due to vulnerable dependencies Scans failing due to vulnerable dependencies ( AST-148814) Apr 22, 2026
@cx-aniket-shinde cx-aniket-shinde changed the title Scans failing due to vulnerable dependencies ( AST-148814) Scans failing due to vulnerable dependencies (AST-148814) Apr 22, 2026
@cx-aniket-shinde cx-aniket-shinde changed the title Scans failing due to vulnerable dependencies (AST-148814) Scans Failing Due To Vulnerable Dependencies (AST-148814) Apr 22, 2026
cx-aniket-shinde and others added 22 commits April 22, 2026 18:01
…RL not set) (#1483)

The notify job references secrets.CXONE_SCAN_WEBHOOK_URL which does not
exist in this repo or at org level, causing the step to fail silently.

Ref: https://checkmarx.atlassian.net/browse/CISO-920
Ref: https://checkmarx.atlassian.net/browse/CISO-815
Updated nightly-parallel.yml to pin actions/download-artifact to a full commit SHA
instead of version tag, complying with repository security policy requiring all
actions to be pinned to full-length commit SHAs.

This resolves the CI error: "The action actions/download-artifact@v4 is not allowed
in Checkmarx/ast-cli because all actions must be pinned to a full-length commit SHA."

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
Updated ai-code-review.yml to pin the Checkmarx/plugins-release-workflow reusable
workflow to a full commit SHA instead of using @main tag, complying with repository
security policy.

This resolves CI failures caused by unpinned workflow references.

Co-Authored-By: Claude Haiku 4.5 <noreply@anthropic.com>
@cx-aniket-shinde cx-aniket-shinde changed the title Scans Failing Due To Vulnerable Dependencies (AST-148814) Scans Failing Due To Vulnerable Dependencies (AST-151094) Apr 28, 2026
@cx-aniket-shinde cx-aniket-shinde merged commit 4a8a40d into main Apr 29, 2026
7 of 8 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants