🌱 Bump aquasecurity/trivy-action to v0.35.0#2433
Conversation
Signed-off-by: Mike Spreitzer <mspreitz@us.ibm.com>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
|
👋 Welcome to the KubeStellar community! 💖 Thanks and congrats 🎉 for opening your first PR here! We're excited to have you contributing. Before merge, please ensure:
📬 If you're using KubeStellar in your organization, please add your name to our Adopters list. 🙏 It really helps the project gain momentum and credibility — a small contribution back with a big impact. Resources:
A maintainer will review your PR soon. Hope you have a great time here! 🌟 ~~~~~~~~~~ 🌟 📬 If you like KubeStellar, please ⭐ star ⭐ our repo to support it! 🙏 It really helps the project gain momentum and credibility — a small contribution back with a big impact. |
There was a problem hiding this comment.
Pull request overview
Updates the container image vulnerability scanning workflow to use a newer, commit-pinned version of the Trivy GitHub Action for frontend/backend image scans.
Changes:
- Bump
aquasecurity/trivy-actionfrom0.28.0to the commit SHA forv0.35.0(pinned by hash). - Apply the same action version update to both frontend and backend scan steps.
💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
|
For this one we are breaking the rule of waiting at least a week for vulnerabilities to be discovered, because this is a fix for a supply chain attack and no older version is operable now. |
|
/assign @KPRoche |
463194e to
2a8fc55
Compare
2a8fc55 to
854820c
Compare
Signed-off-by: Mike Spreitzer <mspreitz@us.ibm.com>
854820c to
cd35ace
Compare
Summary
aquasecurity/trivy-actionto v0.35.057a97c7e7821a5776cebc9bb87c984fa69cba8f1Related issue(s)
Related: kubestellar/infra#129
Test plan
Generated with Claude Code