Skip to content

chore: modernize CI and packaging#14600

Open
HTRamsey wants to merge 1 commit into
mavlink:masterfrom
HTRamsey:chore/ci-packaging-refresh
Open

chore: modernize CI and packaging#14600
HTRamsey wants to merge 1 commit into
mavlink:masterfrom
HTRamsey:chore/ci-packaging-refresh

chore: modernize CI and packaging

d20ae7f
Select commit
Loading
Failed to load commit list.
GitHub Advanced Security / CodeQL succeeded Jul 16, 2026 in 5s

39 new alerts including 39 medium severity security vulnerabilities

New alerts in code changed by this pull request

Security Alerts:

  • 39 medium

Alerts not introduced by this pull request might have been detected because the code changes were too large.

See annotations below for details.

View all branch alerts.

Annotations

Check warning on line 86 in .github/actions/build-prerequisites/action.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'action.yml' step
Uses Step
uses 'lukka/get-cmake' with ref 'v4.3.3', not a pinned commit hash

Check warning on line 53 in .github/actions/coverage/action.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'action.yml' step
Uses Step
uses 'codecov/codecov-action' with ref 'v7', not a pinned commit hash

Check warning on line 51 in .github/actions/docker/action.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'action.yml' step
Uses Step
uses 'docker/login-action' with ref 'v4', not a pinned commit hash

Check warning on line 21 in .github/actions/setup-python/action.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'action.yml' step
Uses Step
uses 'astral-sh/setup-uv' with ref 'v8.3.2', not a pinned commit hash

Check warning on line 53 in .github/actions/test-report/action.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium test

Unpinned 3rd party Action 'action.yml' step
Uses Step
uses 'codecov/codecov-action' with ref 'v7', not a pinned commit hash

Check warning on line 48 in .github/workflows/_cache-cleanup.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action '_cache-cleanup' step
Uses Step
uses 'step-security/harden-runner' with ref 'v2', not a pinned commit hash

Check warning on line 57 in .github/workflows/_detect-changes.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'Detect Changes' step
Uses Step
uses 'step-security/harden-runner' with ref 'v2', not a pinned commit hash

Check warning on line 49 in .github/workflows/analysis.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'Code Analysis' step
Uses Step
uses 'runs-on/action' with ref 'v2', not a pinned commit hash

Check warning on line 114 in .github/workflows/android.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'Android' step
Uses Step
uses 'step-security/harden-runner' with ref 'v2', not a pinned commit hash

Check warning on line 317 in .github/workflows/android.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'Android' step
Uses Step
uses 'step-security/harden-runner' with ref 'v2', not a pinned commit hash

Check warning on line 322 in .github/workflows/android.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'Android' step
Uses Step
uses 'gradle/actions/dependency-submission' with ref 'v6', not a pinned commit hash

Check warning on line 88 in .github/workflows/build-gstreamer.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'Build GStreamer' step
Uses Step
uses 'runs-on/action' with ref 'v2', not a pinned commit hash

Check warning on line 51 in .github/workflows/build-profile.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'Build Profile' step
Uses Step
uses 'runs-on/action' with ref 'v2', not a pinned commit hash

Check warning on line 38 in .github/workflows/clusterfuzzlite.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'ClusterFuzzLite' step
Uses Step
uses 'step-security/harden-runner' with ref 'v2', not a pinned commit hash

Check warning on line 43 in .github/workflows/clusterfuzzlite.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'ClusterFuzzLite' step
Uses Step
uses 'google/clusterfuzzlite/actions/build_fuzzers' with ref 'v1', not a pinned commit hash

Check warning on line 50 in .github/workflows/clusterfuzzlite.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'ClusterFuzzLite' step
Uses Step
uses 'google/clusterfuzzlite/actions/run_fuzzers' with ref 'v1', not a pinned commit hash

Check warning on line 66 in .github/workflows/clusterfuzzlite.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'ClusterFuzzLite' step
Uses Step
uses 'step-security/harden-runner' with ref 'v2', not a pinned commit hash

Check warning on line 71 in .github/workflows/clusterfuzzlite.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'ClusterFuzzLite' step
Uses Step
uses 'google/clusterfuzzlite/actions/build_fuzzers' with ref 'v1', not a pinned commit hash

Check warning on line 39 in .github/workflows/crowdin.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'Crowdin Translations' step
Uses Step
uses 'step-security/harden-runner' with ref 'v2', not a pinned commit hash

Check warning on line 45 in .github/workflows/custom-build.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'Custom Build' step
Uses Step
uses 'step-security/harden-runner' with ref 'v2', not a pinned commit hash

Check warning on line 49 in .github/workflows/dependency-review.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'Dependency Review' step
Uses Step
uses 'gradle/actions/wrapper-validation' with ref 'v4', not a pinned commit hash

Check warning on line 42 in .github/workflows/docker.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'Docker' step
Uses Step
uses 'step-security/harden-runner' with ref 'v2', not a pinned commit hash

Check warning on line 99 in .github/workflows/docker.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'Docker' step
Uses Step
uses 'step-security/harden-runner' with ref 'v2', not a pinned commit hash

Check warning on line 246 in .github/workflows/docker.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'Docker' step
Uses Step
uses 'anchore/sbom-action' with ref 'v0', not a pinned commit hash

Check warning on line 257 in .github/workflows/docker.yml

See this annotation in the file changed.

Code scanning / CodeQL

Unpinned tag for a non-immutable Action in workflow or composite action Medium

Unpinned 3rd party Action 'Docker' step
Uses Step: grype-image
uses 'anchore/scan-action' with ref 'v7', not a pinned commit hash