Skip to content

ci: drop trivy step#943

Merged
phisco merged 2 commits intomainfrom
copilot/drop-trivy-from-ci
Apr 15, 2026
Merged

ci: drop trivy step#943
phisco merged 2 commits intomainfrom
copilot/drop-trivy-from-ci

Conversation

Copy link
Copy Markdown
Contributor

Copilot AI commented Mar 23, 2026

The trivy-action has been compromised twice, most recently with credential exfiltration from CI runners (aquasecurity/trivy-action#541). Mirrors crossplane/crossplane#7237.

  • Remove the trivy-scan-fs job from .github/workflows/ci.yml
Original prompt

Open a pr similar to crossplane/crossplane#7237, dropping trivy from CI.


✨ Let Copilot coding agent set things up for you — coding agent works faster and does higher quality work when set up for your repo.

Copilot AI changed the title [WIP] Remove Trivy from CI configuration Drop trivy from CI Mar 23, 2026
Copilot AI requested a review from phisco March 23, 2026 07:34
@phisco phisco marked this pull request as ready for review March 23, 2026 07:43
@phisco phisco requested a review from a team as a code owner March 23, 2026 07:43
@phisco phisco requested a review from negz March 23, 2026 07:43
@phisco phisco changed the title Drop trivy from CI ci: drop trivy step Mar 23, 2026
@phisco phisco merged commit 3a5f761 into main Apr 15, 2026
9 checks passed
phisco added a commit to phisco/crossplane-runtime that referenced this pull request Apr 15, 2026
Backport of crossplane#943 to release-1.20.

The trivy-action has been compromised twice, most recently with
credential exfiltration from CI runners (see
aquasecurity/trivy-action#541). Remove the trivy-scan-fs job from CI,
mirroring the equivalent backport on crossplane/crossplane.

Signed-off-by: Philippe Scorsolini <5697904+phisco@users.noreply.github.com>
phisco added a commit to phisco/crossplane-runtime that referenced this pull request Apr 15, 2026
Backport of crossplane#943 to release-2.0.

The trivy-action has been compromised twice, most recently with
credential exfiltration from CI runners (see
aquasecurity/trivy-action#541). Remove the trivy-scan-fs job from CI,
mirroring the equivalent backport on crossplane/crossplane.

Signed-off-by: Philippe Scorsolini <5697904+phisco@users.noreply.github.com>
phisco added a commit to phisco/crossplane-runtime that referenced this pull request Apr 15, 2026
Backport of crossplane#943 to release-2.1.

The trivy-action has been compromised twice, most recently with
credential exfiltration from CI runners (see
aquasecurity/trivy-action#541). Remove the trivy-scan-fs job from CI,
mirroring the equivalent backport on crossplane/crossplane.

Signed-off-by: Philippe Scorsolini <5697904+phisco@users.noreply.github.com>
phisco added a commit to phisco/crossplane-runtime that referenced this pull request Apr 15, 2026
Backport of crossplane#943 to release-2.2.

The trivy-action has been compromised twice, most recently with
credential exfiltration from CI runners (see
aquasecurity/trivy-action#541). Remove the trivy-scan-fs job from CI,
mirroring the equivalent backport on crossplane/crossplane.

Signed-off-by: Philippe Scorsolini <5697904+phisco@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants