Skip to content

🌱 Bump aquasecurity/trivy-action to v0.35.0#2433

Open
MikeSpreitzer wants to merge 2 commits intodevfrom
bump-trivy-action-0.35.0
Open

🌱 Bump aquasecurity/trivy-action to v0.35.0#2433
MikeSpreitzer wants to merge 2 commits intodevfrom
bump-trivy-action-0.35.0

Conversation

@MikeSpreitzer
Copy link
Copy Markdown

Summary

  • Upgrades aquasecurity/trivy-action to v0.35.0
  • Pin by commit hash per repo GHA discipline: 57a97c7e7821a5776cebc9bb87c984fa69cba8f1

Related issue(s)

Related: kubestellar/infra#129

Test plan

  • CI passes on this PR

Generated with Claude Code

Signed-off-by: Mike Spreitzer <mspreitz@us.ibm.com>
Copilot AI review requested due to automatic review settings March 23, 2026 16:11
@kubestellar-prow kubestellar-prow bot added the dco-signoff: yes Indicates the PR's author has signed the DCO. label Mar 23, 2026
@kubestellar-prow
Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign antedotee for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@github-actions
Copy link
Copy Markdown
Contributor

👋 Welcome to the KubeStellar community! 💖

Thanks and congrats 🎉 for opening your first PR here! We're excited to have you contributing.

Before merge, please ensure:

  • DCO Sign-off — All commits signed with git commit -s (DCO)
  • PR Title — Starts with an emoji: ✨ feature | 🐛 bug fix | 📖 docs | 🌱 infra/tests | ⚠️ breaking

📬 If you're using KubeStellar in your organization, please add your name to our Adopters list. 🙏 It really helps the project gain momentum and credibility — a small contribution back with a big impact.

Resources:

A maintainer will review your PR soon. Hope you have a great time here!

🌟 ~~~~~~~~~~ 🌟

📬 If you like KubeStellar, please ⭐ star ⭐ our repo to support it!

🙏 It really helps the project gain momentum and credibility — a small contribution back with a big impact.

@kubestellar-prow kubestellar-prow bot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Mar 23, 2026
@github-actions github-actions bot added the ci label Mar 23, 2026
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the container image vulnerability scanning workflow to use a newer, commit-pinned version of the Trivy GitHub Action for frontend/backend image scans.

Changes:

  • Bump aquasecurity/trivy-action from 0.28.0 to the commit SHA for v0.35.0 (pinned by hash).
  • Apply the same action version update to both frontend and backend scan steps.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

@MikeSpreitzer
Copy link
Copy Markdown
Author

For this one we are breaking the rule of waiting at least a week for vulnerabilities to be discovered, because this is a fix for a supply chain attack and no older version is operable now.

@MikeSpreitzer
Copy link
Copy Markdown
Author

/assign @KPRoche

@kubestellar-prow kubestellar-prow bot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. dco-signoff: no Indicates the PR's author has not signed the DCO. and removed size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. dco-signoff: yes Indicates the PR's author has signed the DCO. size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Mar 24, 2026
@github-actions github-actions bot added size/S Denotes a PR that changes 10-29 lines, ignoring generated files. and removed frontend labels Mar 24, 2026
@kubestellar-prow kubestellar-prow bot added the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Mar 24, 2026
@MikeSpreitzer MikeSpreitzer force-pushed the bump-trivy-action-0.35.0 branch from 463194e to 2a8fc55 Compare March 24, 2026 07:52
@kubestellar-prow kubestellar-prow bot added dco-signoff: yes Indicates the PR's author has signed the DCO. and removed dco-signoff: no Indicates the PR's author has not signed the DCO. labels Mar 24, 2026
@kubestellar-prow kubestellar-prow bot removed the size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. label Mar 24, 2026
@MikeSpreitzer MikeSpreitzer force-pushed the bump-trivy-action-0.35.0 branch from 2a8fc55 to 854820c Compare March 24, 2026 08:01
@kubestellar-prow kubestellar-prow bot added size/XS Denotes a PR that changes 0-9 lines, ignoring generated files. and removed size/S Denotes a PR that changes 10-29 lines, ignoring generated files. labels Mar 24, 2026
Signed-off-by: Mike Spreitzer <mspreitz@us.ibm.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

ci dco-signoff: yes Indicates the PR's author has signed the DCO. frontend size/XS Denotes a PR that changes 0-9 lines, ignoring generated files.

Projects

Status: In Progress

Development

Successfully merging this pull request may close these issues.

3 participants