Bump actions/checkout from 7.0.0 to 7.0.1 - #171
Quality Gate failed
Failed conditions
C Security Rating on New Code (required ≥ A)
See analysis details on SonarQube Cloud
Catch issues before they fail your Quality Gate with our IDE extension
SonarQube for IDE
Annotations
Check warning on line 35 in .github/workflows/bandit.yml
sonarqubecloud / SonarCloud Code Analysis
Omitting "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD8sGHH9ap446poU&open=AZ-ReD8sGHH9ap446poU&pullRequest=171
Check warning on line 105 in .github/workflows/aur.yml
sonarqubecloud / SonarCloud Code Analysis
Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD9bGHH9ap446poX&open=AZ-ReD9bGHH9ap446poX&pullRequest=171
Check warning on line 32 in .github/workflows/ruff.yml
sonarqubecloud / SonarCloud Code Analysis
Using dependencies without locking resolved versions is security-sensitive.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD9qGHH9ap446poZ&open=AZ-ReD9qGHH9ap446poZ&pullRequest=171
Check warning on line 102 in .github/workflows/release.yml
sonarqubecloud / SonarCloud Code Analysis
Using dependencies without locking resolved versions is security-sensitive.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD5OGHH9ap446poI&open=AZ-ReD5OGHH9ap446poI&pullRequest=171
Check warning on line 104 in .github/workflows/appimage.yml
sonarqubecloud / SonarCloud Code Analysis
Not disabling redirects might allow for redirections to insecure websites. Make sure it is safe here.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD6aGHH9ap446poR&open=AZ-ReD6aGHH9ap446poR&pullRequest=171
Check warning on line 42 in .github/workflows/gh-pages.yml
sonarqubecloud / SonarCloud Code Analysis
Using dependencies without locking resolved versions is security-sensitive.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD59GHH9ap446poM&open=AZ-ReD59GHH9ap446poM&pullRequest=171
Check warning on line 34 in .github/workflows/bandit.yml
sonarqubecloud / SonarCloud Code Analysis
Using dependencies without locking resolved versions is security-sensitive.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD8sGHH9ap446poT&open=AZ-ReD8sGHH9ap446poT&pullRequest=171
Check warning on line 114 in .github/workflows/aur.yml
sonarqubecloud / SonarCloud Code Analysis
Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD9bGHH9ap446poY&open=AZ-ReD9bGHH9ap446poY&pullRequest=171
Check warning on line 35 in .github/workflows/bandit.yml
sonarqubecloud / SonarCloud Code Analysis
Using dependencies without locking resolved versions is security-sensitive.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD8sGHH9ap446poV&open=AZ-ReD8sGHH9ap446poV&pullRequest=171
Check warning on line 65 in .github/workflows/appimage.yml
sonarqubecloud / SonarCloud Code Analysis
Using dependencies without locking resolved versions is security-sensitive.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD6aGHH9ap446poP&open=AZ-ReD6aGHH9ap446poP&pullRequest=171
Check warning on line 84 in .github/workflows/aur-source.yml
sonarqubecloud / SonarCloud Code Analysis
Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD9IGHH9ap446poW&open=AZ-ReD9IGHH9ap446poW&pullRequest=171
Check warning on line 102 in .github/workflows/release.yml
sonarqubecloud / SonarCloud Code Analysis
Using dependencies without locking resolved versions is security-sensitive.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD5OGHH9ap446poJ&open=AZ-ReD5OGHH9ap446poJ&pullRequest=171
Check warning on line 33 in .github/workflows/ruff.yml
sonarqubecloud / SonarCloud Code Analysis
Omitting "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD9qGHH9ap446poa&open=AZ-ReD9qGHH9ap446poa&pullRequest=171
Check warning on line 43 in .github/workflows/gh-pages.yml
sonarqubecloud / SonarCloud Code Analysis
Omitting "--only-binary :all:" can lead to the execution of setup scripts. Make sure it is safe here.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD59GHH9ap446poN&open=AZ-ReD59GHH9ap446poN&pullRequest=171
Check warning on line 144 in .github/workflows/release.yml
sonarqubecloud / SonarCloud Code Analysis
Using dependencies without locking resolved versions is security-sensitive.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD5OGHH9ap446poL&open=AZ-ReD5OGHH9ap446poL&pullRequest=171
Check warning on line 33 in .github/workflows/ruff.yml
sonarqubecloud / SonarCloud Code Analysis
Using dependencies without locking resolved versions is security-sensitive.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD9qGHH9ap446pob&open=AZ-ReD9qGHH9ap446pob&pullRequest=171
Check warning on line 66 in .github/workflows/appimage.yml
sonarqubecloud / SonarCloud Code Analysis
Using dependencies without locking resolved versions is security-sensitive.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD6aGHH9ap446poQ&open=AZ-ReD6aGHH9ap446poQ&pullRequest=171
Check warning on line 43 in .github/workflows/gh-pages.yml
sonarqubecloud / SonarCloud Code Analysis
Using dependencies without locking resolved versions is security-sensitive.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD59GHH9ap446poO&open=AZ-ReD59GHH9ap446poO&pullRequest=171
Check warning on line 143 in .github/workflows/release.yml
sonarqubecloud / SonarCloud Code Analysis
Using dependencies without locking resolved versions is security-sensitive.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD5OGHH9ap446poK&open=AZ-ReD5OGHH9ap446poK&pullRequest=171
Check warning on line 87 in .github/workflows/package-smoke.yml
sonarqubecloud / SonarCloud Code Analysis
Not enforcing HTTPS here might allow for redirections to insecure websites. Make sure it is safe here.
See more on https://sonarcloud.io/project/issues?id=dseichter_Workdir&issues=AZ-ReD62GHH9ap446poS&open=AZ-ReD62GHH9ap446poS&pullRequest=171