Skip to content

fix(ci): apply security patches in production image build #57

fix(ci): apply security patches in production image build

fix(ci): apply security patches in production image build #57

Triggered via push August 14, 2026 13:30
Status Failure
Total duration 5m 8s
Artifacts 2

release.yml

on: push
Build distributions
1m 44s
Build distributions
Matrix: code-security
Matrix: encryption
Matrix: python-matrix
Matrix: reproducibility-build
Browser accessibility release gate
5m 4s
Browser accessibility release gate
Pi extension release gate
51s
Pi extension release gate
Production image release gate
2m 29s
Production image release gate
Repair GitHub Release
0s
Repair GitHub Release
Matrix: installed-artifact-platform-smoke
Python 3.9 installed release artifacts
0s
Python 3.9 installed release artifacts
Compare independent distribution builders
0s
Compare independent distribution builders
Generate public release evidence
0s
Generate public release evidence
Publish to PyPI
0s
Publish to PyPI
Publish GitHub Release
0s
Publish GitHub Release
Fit to window
Zoom out
Zoom in

Annotations

3 errors and 14 warnings
Build distributions
Process completed with exit code 1.
Production image release gate
Failed minimum severity level. Found vulnerabilities with level 'high' or higher
Browser accessibility release gate
Process completed with exit code 1.
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL javascript-typescript release gate
Feature flags do not specify a default CLI version. Falling back to the CLI version shipped with the Action. This is 2.26.2.
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. As a result, it will not be opted into any experimental features. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
Feature flags do not specify a default CLI version. Falling back to the CLI version shipped with the Action. This is 2.26.2.
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. As a result, it will not be opted into any experimental features. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest

Artifacts

Produced during runtime
Name Size Digest
reproducibility-builder-a
5.09 MB
sha256:1929482a932490d8ecaa2a55d03ee4c4d6d65d8c2508664d5342a016dd4606c4
reproducibility-builder-b
5.09 MB
sha256:d541f3cf0c95accd5de91bf136d99f65d09f662cf60a1a0b4310968f1ab123cf