Skip to content

Refine bandit version constraint for better dependency management

b91e652
Select commit
Loading
Failed to load commit list.
Merged

Fix corrupted workflow files and implement comprehensive security scanning #69

Refine bandit version constraint for better dependency management
b91e652
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Dec 27, 2025 in 3s

1 new alert including 1 medium severity security vulnerability

New alerts in code changed by this pull request

Security Alerts:

  • 1 medium

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 24 in .github/workflows/auto-sec-scan.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow Medium

Unpinned 3rd party Action 'Security Scan on PR' step
Uses Step
uses 'snok/install-poetry' with ref 'v1', not a pinned commit hash