WARNING: THIS SITE IS A MIRROR OF GITHUB.COM / IT CANNOT LOGIN OR REGISTER ACCOUNTS / THE CONTENTS ARE PROVIDED AS-IS / THIS SITE ASSUMES NO RESPONSIBILITY FOR ANY DISPLAYED CONTENT OR LINKS / IF YOU FOUND SOMETHING MAY NOT GOOD FOR EVERYONE, CONTACT ADMIN AT ilovescratch@foxmail.com
Skip to content

feat(ci): delete layotto-ci #293

feat(ci): delete layotto-ci

feat(ci): delete layotto-ci #293

Triggered via pull request August 15, 2025 09:46
@huqiuxianghuqiuxiang
opened #1124
Status Success
Total duration 3m 47s
Artifacts

cloud_code_scan.yml

on: pull_request_target
Fit to window
Zoom out
Zoom in

Annotations

12 warnings
stc
存在【命令中特殊元素的不当处理('命令注入')】漏洞(CVE-2023-26125) 文件: http://github.com/huqiuxiang/layotto/blob/delete-aci/go.mod 组件: github.com/gin-gonic/gin, 版本: 1.7.0 细节/建议版本:1.9.1
stc
存在【具有不可达退出条件的循环(“无限循环”)】漏洞(CVE-2020-14040) 文件: http://github.com/huqiuxiang/layotto/blob/delete-aci/demo/state/k8s/go.mod 组件: golang.org/x/text, 版本: 0.3.0 细节/建议版本:0.3.8
stc
存在【SQL注入】漏洞(CVE-2024-27289) 文件: http://github.com/huqiuxiang/layotto/blob/delete-aci/go.mod 组件: github.com/jackc/pgx/v4, 版本: 4.6.0 细节/建议版本:4.18.2
stc
存在【HTTP请求解释不一致('HTTP请求/响应走私')】漏洞(CVE-2020-28483) 文件: http://github.com/huqiuxiang/layotto/blob/delete-aci/go.mod 组件: github.com/gin-gonic/gin, 版本: 1.7.0 细节/建议版本:1.9.1
stc
存在【访问控制不当】漏洞(CVE-2024-45337) 文件: http://github.com/huqiuxiang/layotto/blob/delete-aci/components/go.mod 组件: golang.org/x/crypto, 版本: 0.1.0 细节/建议版本:0.35.0
stc
存在【访问控制不当】漏洞(CVE-2024-45337) 文件: http://github.com/huqiuxiang/layotto/blob/delete-aci/go.mod 组件: golang.org/x/crypto, 版本: 0.3.0 细节/建议版本:0.35.0
stc
存在【访问控制不当】漏洞(CVE-2024-45337) 文件: http://github.com/huqiuxiang/layotto/blob/delete-aci/demo/go.mod 组件: golang.org/x/crypto, 版本: 0.0.0-20210921155107-089bfa567519 细节/建议版本:0.35.0
stc
存在【整数溢出或回绕】漏洞(CVE-2024-27304) 文件: http://github.com/huqiuxiang/layotto/blob/delete-aci/go.mod 组件: github.com/jackc/pgproto3/v2, 版本: 2.0.1 细节/建议版本:2.3.3
stc
存在【整数溢出或回绕】漏洞(CVE-2024-27304) 文件: http://github.com/huqiuxiang/layotto/blob/delete-aci/go.mod 组件: github.com/jackc/pgx/v4, 版本: 4.6.0 细节/建议版本:4.18.2
stc
详情请查看:https://cybersec.antgroup.com/property/codeBase/share?id=23848&stoken=ZnUE871tqke1D6FgJxWw18VTBflTeX0Y (link valid for 3 days)
sca
请注意, 项目依赖的 caniuse-lite:1.0.30001632 组件,使用的licence可能与本项目冲突: Creative Commons Attribution 4.0
sca
详情请查看:https://devops.cloud.alipay.com/project/19500036/82705569/pipeline/details 可以加入钉钉群:31912621 来申请查看权限