Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add trivy scan workflow #186

Merged

Conversation

sunjayBhatia
Copy link
Contributor

What this PR does / why we need it:

Add trivy scan workflow to scan repo for vulnerabilities in dependencies and checked in secrets

Runs on main and release-1.10.0 branches

Which issue(s) this PR fixes:

N/A

Describe testing done for PR:

N/A

Special notes for your reviewer:

Release note:

NONE

New PR Checklist

  • Ensure PR contains only public links or terms
  • Use good commit messages
  • Squash the commits in this branch before merge to preserve our git history
  • If this PR is just an idea or POC, use a Draft PR instead of a full PR
  • Add appropriate labels according to what type of issue is being addressed.

Runs on main and release-1.10.0 branches

Will scan for vulnerabilities and checked in secrets

Signed-off-by: Sunjay Bhatia <[email protected]>
Copy link
Contributor

@flawedmatrix flawedmatrix left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM!

@sunjayBhatia sunjayBhatia merged commit 8bd6683 into vmware-tanzu:main Mar 25, 2024
5 checks passed
@sunjayBhatia sunjayBhatia deleted the add-trivy-scan-workflow branch March 25, 2024 19:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants