Skip to content

ci: delete .github/workflows/trivy.yaml#1983

Open
mathetake wants to merge 1 commit intomainfrom
mathetake-patch-1
Open

ci: delete .github/workflows/trivy.yaml#1983
mathetake wants to merge 1 commit intomainfrom
mathetake-patch-1

Conversation

@mathetake
Copy link
Member

Description

I believe we are not affected but it's too dangerous to rely on it anymroe aquasecurity/trivy#10425

Signed-off-by: Takeshi Yoneda <t.y.mathetake@gmail.com>
@mathetake mathetake requested a review from a team as a code owner March 24, 2026 00:50
@dosubot dosubot bot added the size:M This PR changes 30-99 lines, ignoring generated files. label Mar 24, 2026
@codecov-commenter
Copy link

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 84.33%. Comparing base (98200a4) to head (a588fe4).

Additional details and impacted files
@@           Coverage Diff           @@
##             main    #1983   +/-   ##
=======================================
  Coverage   84.33%   84.33%           
=======================================
  Files         130      130           
  Lines       17987    17987           
=======================================
  Hits        15170    15170           
  Misses       1873     1873           
  Partials      944      944           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@mathetake mathetake enabled auto-merge (squash) March 24, 2026 01:59
@mathetake
Copy link
Member Author

/retest

@johnugeorge
Copy link
Contributor

@mathetake Do we have any credentials/ev that need to be rotated? I see that we are using a pinned trivy image. Is it better to take actions from our side(if any) than to remove it ? What do you think?

@mathetake
Copy link
Member Author

Do we have any credentials/ev that need to be rotated

Yes

@mathetake
Copy link
Member Author

And no I have no alternative and I don't have a confidence that the pinned action is safe either at this point

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

size:M This PR changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants