Improve dense table readability with sticky headers and column presets - #1107
Merged
Merged
Annotations
10 errors, 11 warnings, and 1 notice
|
Enforce vulnerability SLAs
high tar: node-tar: Uncontrolled recursion in mapHas/filesFilter allows uncatchable stack-overflow DoS via crafted long-path tar with member selection (open 66d, SLA 30d) https://github.com/advisories/GHSA-r292-9mhp-454m
|
|
Enforce vulnerability SLAs
high tar: node-tar: Negative tar entry size causes infinite loop in archive replace (open 69d, SLA 30d) https://github.com/advisories/GHSA-8x88-c5mf-7j5w
|
|
Enforce vulnerability SLAs
high adm-zip: adm-zip: Crafted ZIP file triggers 4GB memory allocation (open 80d, SLA 30d) https://github.com/advisories/GHSA-xcpc-8h2w-3j85
|
|
Enforce vulnerability SLAs
high tar: Race Condition in node-tar Path Reservations via Unicode Ligature Collisions on macOS APFS (open 250d, SLA 30d) https://github.com/advisories/GHSA-r6q2-hw4h-h46w
|
|
Enforce vulnerability SLAs
high tar: node-tar Symlink Path Traversal via Drive-Relative Linkpath (open 201d, SLA 30d) https://github.com/advisories/GHSA-9ppj-qmqm-q256
|
|
Enforce vulnerability SLAs
high tar: tar has Hardlink Path Traversal via Drive-Relative Linkpath (open 207d, SLA 30d) https://github.com/advisories/GHSA-qffp-2rhf-9h96
|
|
Enforce vulnerability SLAs
high tar: Arbitrary File Read/Write via Hardlink Target Escape Through Symlink Chain in node-tar Extraction (open 222d, SLA 30d) https://github.com/advisories/GHSA-83g3-92jg-28cx
|
|
Enforce vulnerability SLAs
high tar: node-tar is Vulnerable to Arbitrary File Overwrite and Symlink Poisoning via Insufficient Path Sanitization (open 254d, SLA 30d) https://github.com/advisories/GHSA-8qq5-rm4j-mr97
|
|
Enforce vulnerability SLAs
high tar: node-tar Vulnerable to Arbitrary File Creation/Overwrite via Hardlink Path Traversal (open 243d, SLA 30d) https://github.com/advisories/GHSA-34x7-hfp2-rc4v
|
|
Enforce vulnerability SLAs
critical tar: node-tar: Decompression/parse DoS via unlimited input (open 69d, SLA 7d) https://github.com/advisories/GHSA-23hp-3jrh-7fpw
|
|
Complete job
Node.js 20 is deprecated. The following actions target Node.js 20 but are being forced to run on Node.js 24: pnpm/action-setup@v4. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
Enforce vulnerability SLAs
moderate react-router: React Router: Arbitrary Constructor Injection via deserializeErrors() in React Router SSR Hydration (below --fail-on high) https://github.com/advisories/GHSA-337j-9hxr-rhxg
|
|
Enforce vulnerability SLAs
moderate react-router: React Router: Open redirect via backslash in <Link> and useNavigate (CVE-2025-68470 bypass) (below --fail-on high) https://github.com/advisories/GHSA-wrjc-x8rr-h8h6
|
|
Enforce vulnerability SLAs
moderate tar: node-tar: Uncaught Exception DoS via NUL byte in PAX path/linkpath records (below --fail-on high) https://github.com/advisories/GHSA-gvwx-54wh-qm9j
|
|
Enforce vulnerability SLAs
moderate tar: node-tar: Process crash via PAX numeric path type confusion (below --fail-on high) https://github.com/advisories/GHSA-w8wr-v893-vjvp
|
|
Enforce vulnerability SLAs
moderate tar: node-tar applies PAX size override to intermediary GNU long-name/long-link headers, causing tar parser interpretation differential (file smuggling) (below --fail-on high) https://github.com/advisories/GHSA-vmf3-w455-68vh
|
|
Enforce vulnerability SLAs
moderate uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided (below --fail-on high) https://github.com/advisories/GHSA-w5hq-g745-h8pq
|
|
Enforce vulnerability SLAs
high adm-zip: adm-zip: Uncontrolled memory allocation via the declared uncompressed size (DoS) (SLA due in 20d) https://github.com/advisories/GHSA-7q85-xj36-vmfc
|
|
Enforce vulnerability SLAs
high js-yaml: js-yaml: maxTotalMergeKeys does not limit CPU use for empty merge sources (SLA due in 11d) https://github.com/advisories/GHSA-2883-xcg3-v3hh
|
|
Enforce vulnerability SLAs
high toml: toml-node: Prototype Pollution Leads to `Object.prototype` Corruption via `__proto__` Key-Path Desynchronization (SLA due in 5d) https://github.com/advisories/GHSA-v5mp-jgw5-2x6j
|
|
Enforce vulnerability SLAs
high toml: toml-node: Uncontrolled Recursion (SLA due in 5d) https://github.com/advisories/GHSA-82x6-q7mm-w9cf
|
|
"The ubuntu-latest label will migrate to Ubuntu 26 beginning October 19, 2026. For more information, see https://github.com/actions/runner-images/issues/14748"
|
background
wait
wait-all
cancel
parallel
Loading