Status: Active Governance Document | DSOM Security Standard | 2026-07-27
Summary
The Red Hat CodeReady Dependency Analytics (CRDA) action (redhat-actions/crda@v1) is permanently defunct. Its backend API (gw.api.openshift.io) was decommissioned by Red Hat with no announced replacement or migration path. Any DSOM repository using the GitHub-generated CRDA starter workflow will fail immediately with a DNS resolution error.
The DSOM-standard replacement is the native Snyk GitHub Action (snyk/actions/python@master), which integrates directly with Snykโs cloud backend and produces SARIF output compatible with GitHub Code Scanning.
The Failure Signature
When CRDA fails, the GitHub Actions log shows:Snyk Concepts, Key Distinctions
AI agents and human operators must distinguish between three Snyk identifiers:Action Version Matrix (Validated 2026-07-27)
Proven Workflow Template
The following template was validated in production on 2026-07-27 (commit841c612). All steps passed with zero errors.
Setup Checklist
-
SNYK_TOKENadded to GitHub โ Settings โ Secrets โ Actions. -
requirements.txtpresent at repository root with all external Python dependencies. -
github/codeql-action/upload-sarif@v4(not@v3). -
continue-on-error: trueon Snyk step, ensures SARIF uploads even when vulnerabilities are found. - Results visible at: GitHub โ Security โ Code scanning.
SOURCES
snyk/actions, Official Snyk GitHub Actions.github/codeql-actionchangelog, v3 deprecation notice.redhat-actions/crda, Archived; no longer maintained..agents/skills/github-actions-snyk-scanner/SKILL.md, Executable SOP for this workflow..github/workflows/crda.yml, Live workflow file in this repository.
Deep State of Mind (DSOM) For My AI Protocol | Harisfazillah Jamel (LinuxMalaysia) | 2026-07-27 Standard: UK English | DBP-standard Bahasa Melayu Malaysia (Piawai) | GNU General Public License v3.0