Skip to content

GitHub: Switch to pinned aquasecurity/trivy-action#1327

Closed
roosterfish wants to merge 1 commit intocanonical:mainfrom
roosterfish:trivy_action
Closed

GitHub: Switch to pinned aquasecurity/trivy-action#1327
roosterfish wants to merge 1 commit intocanonical:mainfrom
roosterfish:trivy_action

Conversation

@roosterfish
Copy link
Copy Markdown
Contributor

After canonical/lxd#18099 removed the trivy action from LXD repo, use the upstream one.

Signed-off-by: Julian Pelizäus <julian.pelizaeus@canonical.com>
Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates the repository’s scheduled/manual security scan workflow to use the upstream Trivy GitHub Action (pinned by commit SHA) now that the LXD-provided Trivy install action is no longer available.

Changes:

  • Replaces manual Trivy installation + DB download/cache steps with aquasecurity/trivy-action (pinned).
  • Runs filesystem (fs) scanning for the repo and root filesystem (rootfs) scanning for extracted snaps via the action’s inputs.
  • Keeps SARIF upload flow unchanged to surface results in the GitHub Security tab.

💡 Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.

Copy link
Copy Markdown
Member

@simondeziel simondeziel left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM but maybe you'd like to wait for canonical/lxd#18105 to land to have both in sync. Up to you.

@roosterfish
Copy link
Copy Markdown
Contributor Author

Can be closed in favor or #1333.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants