Skip to content

fix(security): close conversation hijacking, profile mass assignment, avatar MIME trust #21

fix(security): close conversation hijacking, profile mass assignment, avatar MIME trust

fix(security): close conversation hijacking, profile mass assignment, avatar MIME trust #21

Triggered via pull request August 16, 2026 02:52
Status Success
Total duration 34s
Artifacts 1

threatcrush-scan.yml

on: pull_request
Scan for credentials and vulnerable patterns
31s
Scan for credentials and vulnerable patterns
Fit to window
Zoom out
Zoom in

Annotations

2 warnings
Scan for credentials and vulnerable patterns
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: actions/checkout@v4, actions/github-script@v7, actions/setup-node@v4, actions/upload-artifact@v4, github/codeql-action/upload-sarif@v3. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
Scan for credentials and vulnerable patterns
CodeQL Action v3 will be deprecated in December 2026. Please update all occurrences of the CodeQL Action in your workflow files to v4. For more information, see https://github.blog/changelog/2025-10-28-upcoming-deprecation-of-codeql-action-v3/

Artifacts

Produced during runtime
Name Size Digest
threatcrush-sarif
6.02 KB
sha256:5b8d0c0a364fed4aabd7e6bbb5016fec389dc7b591bef49b6de4fa133494630f