Skip to content

[DNM] test: exercise Trivy scanning against images-shared#722 - #137

Draft
bschwedler wants to merge 4 commits into
mainfrom
feat/trivy-security-scan
Draft

[DNM] test: exercise Trivy scanning against images-shared#722#137
bschwedler wants to merge 4 commits into
mainfrom
feat/trivy-security-scan

Conversation

@bschwedler

@bschwedler bschwedler commented Aug 10, 2026

Copy link
Copy Markdown
Contributor

Test-only. Points package-manager's three build workflows at images-shared's feat/trivy-security-scan so images-shared#722's Trivy scanning runs against real package-manager builds before it merges.

Nothing here is mergeable — PR scanning needs no caller-side change, since the Scan step is ungated in the shared reusable workflows. security-events: write grants were removed; they belong to the code-scanning upload in images-shared#734 and will land in a separate follow-up sequenced by images-shared#729.

@bschwedler
bschwedler force-pushed the feat/trivy-security-scan branch 2 times, most recently from 38acec7 to ceeab58 Compare August 10, 2026 16:53
Prepares this repo to receive SARIF uploads from bakery-build-native.yml
and bakery-build-pr.yml once images-shared#722/#729 land on main. The
reusable workflows now upload results automatically — gated on push for
native builds and unconditionally for PR builds — so no scan-image input
is needed here.

Part of the sequencing from images-shared#729: product repos grant the
permission before the reusable workflow declares it, to avoid breaking
callers still pinned to @main.
@bschwedler
bschwedler force-pushed the feat/trivy-security-scan branch from ceeab58 to d135fcf Compare August 10, 2026 19:50
These grants only exist to satisfy the SARIF code-scanning upload, which
has moved out of images-shared#722 into images-shared#734. #722 no longer
requests security-events on either reusable workflow, so nothing here
needs them yet.

The pr.yml pair would have stayed unused regardless: #734 wires the
upload into bakery-build-native.yml only, since fork PRs get a read-only
token and could not be granted the permission anyway.

Leaves this branch as pure test wiring for #722's scanning, which needs
no caller-side change -- the Scan step is ungated in the shared
workflows. The native grants return in the follow-up that images-shared#729
sequences ahead of #734.
@bschwedler bschwedler changed the title feat: enable Trivy image scanning [DNM] test: exercise Trivy scanning against images-shared#722 Aug 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant