Skip to main content
Status: Active Governance Document | DSOM Security Standard | 2026-07-27

Summary

The Red Hat CodeReady Dependency Analytics (CRDA) action (redhat-actions/crda@v1) is permanently defunct. Its backend API (gw.api.openshift.io) was decommissioned by Red Hat with no announced replacement or migration path. Any DSOM repository using the GitHub-generated CRDA starter workflow will fail immediately with a DNS resolution error. The DSOM-standard replacement is the native Snyk GitHub Action (snyk/actions/python@master), which integrates directly with Snykโ€™s cloud backend and produces SARIF output compatible with GitHub Code Scanning.

The Failure Signature

When CRDA fails, the GitHub Actions log shows:
This is a permanent infrastructure failure, not a configuration error. No amount of reconfiguration will resolve it.

Snyk Concepts, Key Distinctions

AI agents and human operators must distinguish between three Snyk identifiers:

Action Version Matrix (Validated 2026-07-27)


Proven Workflow Template

The following template was validated in production on 2026-07-27 (commit 841c612). All steps passed with zero errors.

Setup Checklist

  • SNYK_TOKEN added to GitHub โ†’ Settings โ†’ Secrets โ†’ Actions.
  • requirements.txt present at repository root with all external Python dependencies.
  • github/codeql-action/upload-sarif@v4 (not @v3).
  • continue-on-error: true on Snyk step, ensures SARIF uploads even when vulnerabilities are found.
  • Results visible at: GitHub โ†’ Security โ†’ Code scanning.

SOURCES


Deep State of Mind (DSOM) For My AI Protocol | Harisfazillah Jamel (LinuxMalaysia) | 2026-07-27 Standard: UK English | DBP-standard Bahasa Melayu Malaysia (Piawai) | GNU General Public License v3.0