CHEF-31147: Added config for grype hab pkg scan #3
ci-main-pull-request-stub-1.0.8.yml
on: pull_request
Detect custom properties
6s
Echo stub version
3s
call-ci-main-pr-check-pipeline
/
Checkout repository
5s
call-ci-main-pr-check-pipeline
/
Pre-compilation checks
5s
call-ci-main-pr-check-pipeline
/
Build/compilation and unit tests (CI)
47s
call-ci-main-pr-check-pipeline
/
...
/
Export SBOM from GitHub Dependency Graph API
10s
call-ci-main-pr-check-pipeline
/
...
/
Blackduck SCA Scan (PURPLE)
0s
call-ci-main-pr-check-pipeline
/
...
/
Generate MSFT SBOM
0s
call-ci-main-pr-check-pipeline
/
...
/
license_scout
0s
call-ci-main-pr-check-pipeline
/
...
/
Complexity and SLOC generation
24s
call-ci-main-pr-check-pipeline
/
Language-specific pre-compilation steps and linting
0s
call-ci-main-pr-check-pipeline
/
Language-agnostic pre-compilation steps
0s
call-ci-main-pr-check-pipeline
/
...
/
Trufflehog
15s
call-ci-main-pr-check-pipeline
/
Grype scan
1m 22s
call-ci-main-pr-check-pipeline
/
...
/
Grype scan (Linux)
1m 7s
call-ci-main-pr-check-pipeline
/
...
/
Grype scan (Windows)
2m 17s
call-ci-main-pr-check-pipeline
/
...
/
Grype scan (MacOS)
0s
call-ci-main-pr-check-pipeline
/
...
/
BlackDuck Polaris SAST scan
call-ci-main-pr-check-pipeline
/
...
/
Grype vulnerability scan
call-ci-main-pr-check-pipeline
/
Creating packaged binaries
3s
call-ci-main-pr-check-pipeline
/
Detect SBOM version for application
0s
Matrix: call-ci-main-pr-check-pipeline / Unit tests
call-ci-main-pr-check-pipeline
/
...
/
irfan
call-ci-main-pr-check-pipeline
/
Creating Habitat packages
2s
call-ci-main-pr-check-pipeline
/
Publishing Habitat packages to Builder
0s
call-ci-main-pr-check-pipeline
/
Publishing packages
0s
call-ci-main-pr-check-pipeline
/
Grype scan of Habitat packages
0s
call-ci-main-pr-check-pipeline
/
Grype scan of Habitat packages (Windows)
0s
Annotations
3 errors and 6 warnings
|
call-ci-main-pr-check-pipeline / Grype scan Habitat packages from bldr.habitat.sh / Grype scan (Linux)
Process completed with exit code 1.
|
|
call-ci-main-pr-check-pipeline / Grype scan
Process completed with exit code 1.
|
|
call-ci-main-pr-check-pipeline / Grype scan Habitat packages from bldr.habitat.sh / Grype scan (Windows)
Process completed with exit code 1.
|
|
Detect custom properties
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
call-ci-main-pr-check-pipeline / Generating SBOM / Export SBOM from GitHub Dependency Graph API
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
call-ci-main-pr-check-pipeline / Source code complexity checks / Complexity and SLOC generation
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
call-ci-main-pr-check-pipeline / Grype scan Habitat packages from bldr.habitat.sh / Grype scan (Linux)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
call-ci-main-pr-check-pipeline / Grype scan
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
|
call-ci-main-pr-check-pipeline / Grype scan Habitat packages from bldr.habitat.sh / Grype scan (Windows)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 2nd, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
|
Artifacts
Produced during runtime
| Name | Size | Digest | |
|---|---|---|---|
|
chef-chef-cli-20260421151336-GitHub-sbom.json
|
2.12 KB |
sha256:0ae6dbfed928a1c37cde49e3d964702006848a8839b7c2dd98b75d040138b027
|
|
|
chef-chef-cli-334-merge-20260421151353-scc-complexity.html
Expired
|
8.58 KB |
sha256:6a077ead05870910ba958c344d489bec79e9980fcc5e375504cf28b53a7dd5b2
|
|
|
chef-chef-cli-334-merge-20260421151353-scc-complexity.json
Expired
|
10.7 KB |
sha256:9c2897eec8c0ad61ee1b2eccab3adf035d2e2df59013d4d4505a50ceaf1b116c
|
|
|
chef-chef-cli-334-merge-20260421151353-scc-complexity.txt
Expired
|
768 Bytes |
sha256:d3b7d4012c57f98ca9474c19bd5e9f3851057abe7267be9ef722917d29e75445
|
|
|
chef-chef-cli-334-merge-6.1.30-20260421151336-GitHub-sbom.csv
|
1.22 KB |
sha256:6f1a4990cdb20e1d5459a7560c4642b4404f12a10b9c814d8e9daed6acb2e645
|
|
|
grype-scan-chef-cli-20260421-151450
|
5.79 KB |
sha256:49f07a2d8b883e1eb39548caa3fb92d45c67b7bc0579fe9001b72997744c5f86
|
|
|
grype-scan-linux-chef-cli-20260421-151342
|
9.26 KB |
sha256:95cac6738ff04c211746b8e04d94dc532efa950814e675a955fe5c9e2f1ba39c
|
|
|
grype-scan-windows-chef-cli-20260421-151346
|
6.68 KB |
sha256:fc308862abc0a964450c4c936c54064558360139c40fc3a101c35aa8f2f45c35
|
|