Skip to content

[DNM] test: exercise Trivy scanning against images-shared#722 - #185

Draft
bschwedler wants to merge 1 commit into
mainfrom
feat/trivy-security-scan
Draft

[DNM] test: exercise Trivy scanning against images-shared#722#185
bschwedler wants to merge 1 commit into
mainfrom
feat/trivy-security-scan

Conversation

@bschwedler

Copy link
Copy Markdown
Contributor

Test-only. Points this repo's build workflows at images-shared's feat/trivy-security-scan so images-shared#722's Trivy scanning runs against real builds before it merges.

Nothing here is mergeable — PR scanning needs no caller-side change, since the Scan step is ungated in the shared reusable workflows. No security-events grants: those belong to the code-scanning upload in images-shared#734 and land in a separate follow-up sequenced by images-shared#729.

Both the reusable-workflow ref and the version input are repointed. version feeds setup-bakery, so changing only uses: would run the new workflow file against a released bakery that has no trivy command.

Test-only wiring so images-shared#722's Trivy scanning runs against real
workbench builds before it merges. Must be dropped before this branch
goes anywhere near main.

Repoints both the reusable-workflow ref and the version input. The latter
feeds setup-bakery, so changing only `uses:` would run the new workflow
file against a released bakery with no `trivy` command.

No security-events grants: PR scanning needs no caller-side change, since
the Scan step is ungated in the shared workflows.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant