Skip to content

chore: bump gorag dependency from v1.6.1 to v1.6.2 #18

chore: bump gorag dependency from v1.6.1 to v1.6.2

chore: bump gorag dependency from v1.6.1 to v1.6.2 #18

Triggered via push June 12, 2026 05:05
Status Success
Total duration 2m 8s
Artifacts 1

security.yml

on: push
Matrix: CodeQL Analysis
Dependency Review
0s
Dependency Review
Go Vulnerability Check
59s
Go Vulnerability Check
Security Summary
4s
Security Summary
Fit to window
Zoom out
Zoom in

Annotations

20 errors and 3 warnings
Go Vulnerability Check: internal/setup/component/memoryconfig/memoryconfig.go#L14
github.com/DotNetAge/gorag@v1.6.2: replacement directory ../gorag does not exist
Go Vulnerability Check: pkg/memory/memory.go#L20
github.com/DotNetAge/gorag@v1.6.2: replacement directory ../gorag does not exist
Go Vulnerability Check: pkg/memory/memory.go#L19
github.com/DotNetAge/gorag@v1.6.2: replacement directory ../gorag does not exist
Go Vulnerability Check: pkg/memory/memory.go#L18
github.com/DotNetAge/gorag@v1.6.2: replacement directory ../gorag does not exist
Go Vulnerability Check: pkg/memory/memory.go#L17
github.com/DotNetAge/gorag@v1.6.2: replacement directory ../gorag does not exist
Go Vulnerability Check: pkg/memory/memory.go#L16
github.com/DotNetAge/gorag@v1.6.2: replacement directory ../gorag does not exist
Go Vulnerability Check: pkg/memory/memory.go#L15
github.com/DotNetAge/gorag@v1.6.2: replacement directory ../gorag does not exist
Go Vulnerability Check: pkg/memory/memory.go#L14
github.com/DotNetAge/gorag@v1.6.2: replacement directory ../gorag does not exist
Go Vulnerability Check: pkg/memory/memory.go#L12
github.com/DotNetAge/gorag@v1.6.2: replacement directory ../gorag does not exist
Go Vulnerability Check: internal/core/app.go#L14
github.com/DotNetAge/gorag@v1.6.2: replacement directory ../gorag does not exist
CodeQL Analysis (go)
could not import strings (no metadata for strings)
CodeQL Analysis (go)
could not import path/filepath (no metadata for path/filepath)
CodeQL Analysis (go)
could not import os (no metadata for os)
CodeQL Analysis (go)
could not import io (no metadata for io)
CodeQL Analysis (go)
could not import fmt (no metadata for fmt)
CodeQL Analysis (go)
could not import context (no metadata for context)
CodeQL Analysis (go)
github.com/DotNetAge/gorag@v0.0.0-00010101000000-000000000000: replacement directory ../gorag does not exist
CodeQL Analysis (go)
github.com/DotNetAge/gorag@v0.0.0-00010101000000-000000000000: replacement directory ../gorag does not exist
CodeQL Analysis (go)
github.com/DotNetAge/gorag@v0.0.0-00010101000000-000000000000: replacement directory ../gorag does not exist
CodeQL Analysis (go)
github.com/DotNetAge/gorag@v0.0.0-00010101000000-000000000000: replacement directory ../gorag does not exist
Go Vulnerability Check
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4, actions/upload-artifact@v4. Actions will be forced to run with Node.js 24 by default starting June 16th, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
CodeQL Analysis (go)
Node.js 20 actions are deprecated. The following actions are running on Node.js 20 and may not work as expected: actions/checkout@v4. Actions will be forced to run with Node.js 24 by default starting June 16th, 2026. Node.js 20 will be removed from the runner on September 16th, 2026. Please check if updated versions of these actions are available that support Node.js 24. To opt into Node.js 24 now, set the FORCE_JAVASCRIPT_ACTIONS_TO_NODE24=true environment variable on the runner or in your workflow file. Once Node.js 24 becomes the default, you can temporarily opt out by setting ACTIONS_ALLOW_USE_UNSECURE_NODE_VERSION=true. For more information see: https://github.blog/changelog/2025-09-19-deprecation-of-node-20-on-github-actions-runners/
CodeQL Analysis (go)
Expected `which go` to return /home/runner/work/_temp/codeql-action-go-tracing/bin/go, but got /opt/hostedtoolcache/go/1.26.4/x64/bin/go: please ensure that the correct version of Go is installed before the `codeql-action/init` Action is used.

Artifacts

Produced during runtime
Name Size Digest
govulncheck-report Expired
160 Bytes
sha256:13d5f327518669ee277a8de99489657fe8fc355963920b4d3ad7fee46538b83a