chore: remove trivy action#123
Conversation
Signed-off-by: Rob Bell <robell@redhat.com>
|
No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configurationConfiguration used: Central YAML (base), Organization UI (inherited) Review profile: CHILL Plan: Pro Run ID: 📒 Files selected for processing (1)
💤 Files with no reviewable changes (1)
📝 WalkthroughWalkthroughThis pull request removes Estimated code review effort🎯 1 (Trivial) | ⏱️ ~3 minutes Security FindingsRemoval of vulnerability scanning infrastructure — This deletion eliminates automated detection of filesystem-level vulnerabilities (CWE-693: Protection Mechanism Failure). There is no evidence in this diff that:
Actionable issue: Confirm whether vulnerability scanning continues via an alternative mechanism. If not, this represents a gap in security controls that should be explicitly documented and approved. 🚥 Pre-merge checks | ✅ 2✅ Passed checks (2 passed)
✏️ Tip: You can configure your own custom pre-merge checks in the settings. Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
What this PR does / why we need it:
Removing trivy as per upstream kubeflow#3389.
The action was already disabled and not running.
Which issue(s) this PR fixes (optional, in
Fixes #<issue number>, #<issue number>, ...format, will close the issue(s) when PR gets merged):Fixes #
Checklist:
Summary by CodeRabbit