Skip to content

Hotfix v1.6.1: SEC-001 path disclosure fix, pypdf CVE, CI grype/audit… #74

Hotfix v1.6.1: SEC-001 path disclosure fix, pypdf CVE, CI grype/audit…

Hotfix v1.6.1: SEC-001 path disclosure fix, pypdf CVE, CI grype/audit… #74

Triggered via push August 14, 2026 15:46
Status Failure
Total duration 6m 36s
Artifacts 6

release.yml

on: push
Build distributions
5m 46s
Build distributions
Matrix: code-security
Matrix: encryption
Matrix: python-matrix
Matrix: reproducibility-build
Browser accessibility release gate
1m 36s
Browser accessibility release gate
Pi extension release gate
48s
Pi extension release gate
Production image release gate
3m 6s
Production image release gate
Repair GitHub Release
0s
Repair GitHub Release
Matrix: installed-artifact-platform-smoke
Python 3.9 installed release artifacts
30s
Python 3.9 installed release artifacts
Compare independent distribution builders
16s
Compare independent distribution builders
Generate public release evidence
9s
Generate public release evidence
Publish to PyPI
0s
Publish to PyPI
Publish GitHub Release
Publish GitHub Release
Fit to window
Zoom out
Zoom in

Annotations

1 error and 14 warnings
Generate public release evidence
Process completed with exit code 2.
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL javascript-typescript release gate
Feature flags do not specify a default CLI version. Falling back to the CLI version shipped with the Action. This is 2.26.2.
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. As a result, it will not be opted into any experimental features. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
Feature flags do not specify a default CLI version. Falling back to the CLI version shipped with the Action. This is 2.26.2.
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. As a result, it will not be opted into any experimental features. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest

Artifacts

Produced during runtime
Name Size Digest
build-environment-evidence
20.6 KB
sha256:7d3e4d8b04016b97fdb19e658a78a560f19a8345ae4a4adef79b703de261ec4c
independent-reproducibility
561 Bytes
sha256:4257a8a5f59fe081444811764b236731791f8a027f66d86d7f402620e7f1c86c
production-image-evidence
476 KB
sha256:38053deff55a1aed670c19c916413feb6506cf0d96eb37259786bcb8dd1cc162
python-package-distributions
4.54 MB
sha256:008d134d62a8d67dff6f00686ef2e9fd5561bfa199154244d01abda62a965af3
reproducibility-builder-a
4.54 MB
sha256:ae3624389942d262f85c968a17cfb44c2025c543da0bf0d651a951e0056c7fb2
reproducibility-builder-b
4.54 MB
sha256:37b482e5a5a10a1938e0643251639cd460466e87438f73dbaac16d2c884f21ca