Skip to content

fix(release): pin grype evidence scanner #86

fix(release): pin grype evidence scanner

fix(release): pin grype evidence scanner #86

Triggered via push September 8, 2026 11:58
Status Success
Total duration 12m 0s
Artifacts 7

release.yml

on: push
Build distributions
9m 15s
Build distributions
Matrix: code-security
Matrix: encryption
Matrix: python-matrix
Matrix: reproducibility-build
Browser accessibility release gate
7m 25s
Browser accessibility release gate
Pi extension release gate
41s
Pi extension release gate
Production image release gate
3m 13s
Production image release gate
Repair GitHub Release
0s
Repair GitHub Release
Matrix: installed-artifact-platform-smoke
Python 3.9 installed release artifacts
34s
Python 3.9 installed release artifacts
Compare independent distribution builders
15s
Compare independent distribution builders
Generate public release evidence
13s
Generate public release evidence
Publish to PyPI
1m 12s
Publish to PyPI
Publish GitHub Release
9s
Publish GitHub Release
Fit to window
Zoom out
Zoom in

Annotations

14 warnings and 1 notice
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL javascript-typescript release gate
Feature flags do not specify a default CLI version. Falling back to the CLI version shipped with the Action. This is 2.26.4.
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. As a result, it will not be opted into any experimental features. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL javascript-typescript release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
Feature flags do not specify a default CLI version. Falling back to the CLI version shipped with the Action. This is 2.26.4.
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. As a result, it will not be opted into any experimental features. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
CodeQL python release gate
This run of the CodeQL Action does not have permission to access the CodeQL Action API endpoints. This could be because the Action is running on a pull request from a fork. If not, please ensure the workflow has at least the 'security-events: read' permission. Details: Resource not accessible by integration - https://docs.github.com/rest
Publish to PyPI
Generating and uploading digital attestations

Artifacts

Produced during runtime
Name Size Digest
build-environment-evidence
20.7 KB
sha256:e34f82d08c9bc7664fe2b408d9ec1aaa92101cf0c0836b2e8b81bd1ba8f1d9f9
independent-reproducibility
559 Bytes
sha256:edf26335a74e55257f9a547bea474250aca29ec0b1efa1e863383695f4e9b3d9
production-image-evidence
484 KB
sha256:6be7c183824c721339c9437970b5815e75cdd34f97a7537a2f8c71776786f0cb
public-release-evidence
508 KB
sha256:ba5ecce80e7dbcbc74d697946d2ac66bba645e86f90f5b7cfd2924918209f57e
python-package-distributions
5.57 MB
sha256:953bd39715a7389d55ab325baf2edaae344c1af29f9eac5d02269fb971b5f890
reproducibility-builder-a
5.57 MB
sha256:eb023a4a4080e480fca129439228b171092c97fa537166ae824bdaa7f48b75a4
reproducibility-builder-b
5.57 MB
sha256:675afa99608d4f04f3287a104153b2ae5d8ebea8aaedaec6cdf368721edf2a46