Skip to content

fix: impacted old trivy version#464

Merged
vMaroon merged 2 commits intollm-d:mainfrom
zdtsw:chore_cve
Mar 26, 2026
Merged

fix: impacted old trivy version#464
vMaroon merged 2 commits intollm-d:mainfrom
zdtsw:chore_cve

Conversation

@zdtsw
Copy link
Copy Markdown
Contributor

@zdtsw zdtsw commented Mar 26, 2026

Signed-off-by: Wen Zhou <wenzhou@redhat.com>
Copilot AI review requested due to automatic review settings March 26, 2026 07:22
Copy link
Copy Markdown
Contributor

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the repository’s composite Trivy scan action to avoid using a hard-pinned, outdated Trivy .deb install, aligning with the linked Trivy security advisory.

Changes:

  • Replaces manual Trivy installation via wget + dpkg with aquasecurity/trivy-action.
  • Runs image scanning through the maintained Trivy GitHub Action with configured severity filtering.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Comment thread .github/actions/trivy-scan/action.yml Outdated
Co-authored-by: Copilot <175728472+Copilot@users.noreply.github.com>
Signed-off-by: Wen Zhou <wenzhou@redhat.com>
@vMaroon
Copy link
Copy Markdown
Member

vMaroon commented Mar 26, 2026

/lgtm
/approve

@github-actions github-actions bot added the lgtm Looks good to me, indicates that a PR is ready to be merged. label Mar 26, 2026
@vMaroon vMaroon merged commit bcee6cf into llm-d:main Mar 26, 2026
10 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lgtm Looks good to me, indicates that a PR is ready to be merged.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants