feat(deps): bump actions/checkout from 7.0.0 to 7.0.1#468
feat(deps): bump actions/checkout from 7.0.0 to 7.0.1#468dependabot[bot] wants to merge 1 commit into
Quality Gate failed
Failed conditions
C Security Rating on New Code (required ≥ A)
See analysis details on SonarQube Cloud
Catch issues before they fail your Quality Gate with our IDE extension
SonarQube for IDE
Annotations
Check warning on line 32 in .github/workflows/deploy.yml
sonarqubecloud / SonarCloud Code Analysis
Omitting "--ignore-scripts" allows lifecycle scripts to run during package installation.
See more on https://sonarcloud.io/project/issues?id=sws2apps_github-gcloud-cli&issues=AZ-EDuGabMKH3YxkpFZs&open=AZ-EDuGabMKH3YxkpFZs&pullRequest=468
Check warning on line 35 in .github/workflows/deploy.yml
sonarqubecloud / SonarCloud Code Analysis
"npx" can install packages on-demand and run their lifecycle scripts.
See more on https://sonarcloud.io/project/issues?id=sws2apps_github-gcloud-cli&issues=AZ-EDuGabMKH3YxkpFZt&open=AZ-EDuGabMKH3YxkpFZt&pullRequest=468
Check warning on line 35 in .github/workflows/deploy.yml
sonarqubecloud / SonarCloud Code Analysis
Define exact package version to avoid installing unverified releases.
See more on https://sonarcloud.io/project/issues?id=sws2apps_github-gcloud-cli&issues=AZ-EDuGabMKH3YxkpFZu&open=AZ-EDuGabMKH3YxkpFZu&pullRequest=468