Skip to content

[fix][ci] Disable trivy-action#25373

Merged
lhotari merged 2 commits intoapache:masterfrom
lhotari:lh-disable-trivy
Mar 20, 2026
Merged

[fix][ci] Disable trivy-action#25373
lhotari merged 2 commits intoapache:masterfrom
lhotari:lh-disable-trivy

Conversation

@lhotari
Copy link
Copy Markdown
Member

@lhotari lhotari commented Mar 20, 2026

Motivation

The aquasecurity/trivy-action repository was compromised in a supply chain attack where an attacker force-pushed malicious payloads to 75 out of 76 version tags. Version v0.35.0 is the first safe release after the incident.

References:

Modifications

Documentation

  • doc-not-needed

@lhotari lhotari requested a review from merlimat March 20, 2026 16:46
@lhotari lhotari changed the title [fix][ci] Comment out trivy-action until it has been approved by ASF [fix][ci] Disable trivy-action until it has been approved by ASF Mar 20, 2026
@github-actions github-actions Bot added the doc-not-needed Your PR changes do not impact docs label Mar 20, 2026
@lhotari lhotari changed the title [fix][ci] Disable trivy-action until it has been approved by ASF [fix][ci] Disable trivy-action Mar 20, 2026
@lhotari
Copy link
Copy Markdown
Member Author

lhotari commented Mar 20, 2026

/pulsarbot rerun-failure-checks

@lhotari
Copy link
Copy Markdown
Member Author

lhotari commented Mar 20, 2026

I created apache/infrastructure-actions#546 to allow aquasecurity/trivy-action@57a97c7 since we'd like to use it later.

@codecov-commenter
Copy link
Copy Markdown

codecov-commenter commented Mar 20, 2026

Codecov Report

✅ All modified and coverable lines are covered by tests.
✅ Project coverage is 72.71%. Comparing base (a3ae705) to head (add4aee).
⚠️ Report is 16 commits behind head on master.

Additional details and impacted files

Impacted file tree graph

@@             Coverage Diff              @@
##             master   #25373      +/-   ##
============================================
+ Coverage     72.52%   72.71%   +0.19%     
+ Complexity    34275    33863     -412     
============================================
  Files          1927     1954      +27     
  Lines        154339   154792     +453     
  Branches      17683    17731      +48     
============================================
+ Hits         111935   112563     +628     
+ Misses        33389    33196     -193     
- Partials       9015     9033      +18     
Flag Coverage Δ
inttests 25.86% <ø> (-0.18%) ⬇️
systests 22.45% <ø> (?)
unittests 73.70% <ø> (-0.05%) ⬇️

Flags with carried forward coverage won't be shown. Click here to find out more.
see 173 files with indirect coverage changes

🚀 New features to boost your workflow:
  • ❄️ Test Analytics: Detect flaky tests, report on failures, and find test suite problems.
  • 📦 JS Bundle Analysis: Save yourself from yourself by tracking and limiting bundle sizes in JS merges.

@lhotari lhotari merged commit 6e577f0 into apache:master Mar 20, 2026
106 of 109 checks passed
@lhotari lhotari added this to the 4.2.0 milestone Mar 24, 2026
sandeep-ctds pushed a commit to datastax/pulsar that referenced this pull request Apr 1, 2026
sandeep-ctds pushed a commit to datastax/pulsar that referenced this pull request Apr 1, 2026
lhotari added a commit that referenced this pull request Apr 15, 2026
lhotari added a commit that referenced this pull request Apr 15, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants