Skip to content

Conversation

@cbandy
Copy link
Member

@cbandy cbandy commented May 14, 2025

I looked to see if we should return to the upstream Trivy action. The Trivy binary is better about fetching its database, but the action still caches poorly. I opted to update the binary for now.

This also configures Dependabot to update our local actions. Dependabot PRs for actions look like this: cbandy#15

Checklist:

  • Have you added an explanation of what your changes do and why you'd like them to be included?
  • Have you updated or added documentation for the change, as applicable?
  • Have you tested your changes on all related environments with successful results, as applicable?
    • Have you added automated tests?

Type of Changes:

  • Testing enhancement

cbandy added 2 commits May 14, 2025 11:11
The 'directory: /' configuration only looks at workflows.
Document why the local action is still necessary. We have to update it
ourselves periodically.

See: https://github.com/aquasecurity/trivy/releases/tag/v0.62.1
@cbandy cbandy merged commit ffdf703 into CrunchyData:main May 14, 2025
14 of 19 checks passed
@cbandy cbandy deleted the trivy-action branch May 14, 2025 19:51
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants