[DX-4553] Optimize Integration Tests Workflow - #23164
Quality Gate failed
Failed conditions
7 Security Hotspots
C Security Rating on New Code (required ≥ A)
See analysis details on SonarQube
Catch issues before they fail your Quality Gate with our IDE extension
SonarQube for IDE
Annotations
Check warning on line 183 in .github/workflows/ccip-system-tests.yaml
cl-sonarqube-production / SonarQube Code Analysis
Dependency versions are not predictable. Use a lock-file enforcing command instead.
[S8545] Go dependencies should be locked to verified versions
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23164&issues=fb9b5117-b341-476b-8cef-6d3ed5e3ac0c&open=fb9b5117-b341-476b-8cef-6d3ed5e3ac0c
Check warning on line 654 in .github/workflows/integration-tests.yml
cl-sonarqube-production / SonarQube Code Analysis
Only pass required secrets to this workflow.
[S7635] Passing the full secrets context to reusable workflows is security-sensitive
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23164&issues=2cd4ed6b-6ac3-4ded-a461-c7bad9fbff09&open=2cd4ed6b-6ac3-4ded-a461-c7bad9fbff09
Check warning on line 205 in .github/workflows/cre-regression-system-tests.yaml
cl-sonarqube-production / SonarQube Code Analysis
Dependency versions are not predictable. Use a lock-file enforcing command instead.
[S8545] Go dependencies should be locked to verified versions
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23164&issues=e774d1f3-b905-41e0-a4d9-e47f021f6350&open=e774d1f3-b905-41e0-a4d9-e47f021f6350
Check warning on line 127 in .github/workflows/ccip-system-tests.yaml
cl-sonarqube-production / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23164&issues=1c7f3766-1ebb-4649-b55c-5db056b1fb3b&open=1c7f3766-1ebb-4649-b55c-5db056b1fb3b
Check warning on line 537 in .github/workflows/integration-tests.yml
cl-sonarqube-production / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23164&issues=f67b9a27-a540-4cba-8f83-77e60df11316&open=f67b9a27-a540-4cba-8f83-77e60df11316
Check warning on line 39 in .github/workflows/run-nightly-in-memory-integration-tests.yml
cl-sonarqube-production / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23164&issues=6a01bd78-dba8-4170-9b19-40cd212d0303&open=6a01bd78-dba8-4170-9b19-40cd212d0303
Check warning on line 104 in .github/workflows/integration-in-memory-tests.yml
cl-sonarqube-production / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23164&issues=0d9d29a6-e333-479a-a574-7cc0c9397dbe&open=0d9d29a6-e333-479a-a574-7cc0c9397dbe
Check warning on line 136 in .github/workflows/integration-in-memory-tests.yml
cl-sonarqube-production / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23164&issues=c27a9213-797d-4b06-b73b-48630bb76fb5&open=c27a9213-797d-4b06-b73b-48630bb76fb5
Check warning on line 233 in .github/workflows/ccip-system-tests.yaml
cl-sonarqube-production / SonarQube Code Analysis
Use full commit SHA hash for this dependency.
[S7637] Using external GitHub actions and workflows without a commit reference is security-sensitive
See more on https://sonarqube.main.prod.cldev.sh/project/issues?id=smartcontractkit_chainlink&pullRequest=23164&issues=95298662-c51e-41d1-8578-d1794cb2e235&open=95298662-c51e-41d1-8578-d1794cb2e235