Skip to content

Conversation

@Mionsz
Copy link
Collaborator

@Mionsz Mionsz commented Mar 26, 2025

FIX: More dashboard and trivy relatred fixes.
Add: Missing pip version pinnings
Add: Missing hash version hooking in github actions.

@Mionsz Mionsz requested review from moleksy and soopel as code owners March 26, 2025 13:24
@Mionsz Mionsz force-pushed the private/mlinkiew/trivy-related-fixes branch from 2850ce4 to 415cc8a Compare March 26, 2025 13:33
@Mionsz Mionsz added bug fix Something isn't working help wanted Extra attention is needed maintainers review request Pull request is ready to be reviewed. RC-Blocker Prioritize this label as it is a release candidate and release blocker labels Mar 26, 2025
@Mionsz Mionsz force-pushed the private/mlinkiew/trivy-related-fixes branch 2 times, most recently from 32708c8 to 3fa797e Compare March 31, 2025 06:01
Copy link
Collaborator

@MateuszGrabuszynski MateuszGrabuszynski left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

It is a good practice to add those package versions to ensure stable execution conditions. However, we should keep in mind, they all shall be less than 1 year old, unless strictly necessary.

@Mionsz Mionsz force-pushed the private/mlinkiew/trivy-related-fixes branch from 3fa797e to 33bfa50 Compare April 15, 2025 09:32
@Mionsz Mionsz force-pushed the private/mlinkiew/trivy-related-fixes branch from fc7540f to a361105 Compare May 8, 2025 00:34
Copy link
Collaborator

@MateuszGrabuszynski MateuszGrabuszynski left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM

@Mionsz Mionsz force-pushed the private/mlinkiew/trivy-related-fixes branch from 225ae5d to b6d8469 Compare May 27, 2025 08:42
@Mionsz Mionsz force-pushed the private/mlinkiew/trivy-related-fixes branch from bdf388b to 7a20351 Compare June 17, 2025 10:57
Mionsz added 4 commits July 30, 2025 11:25
FIX: Trivy related update to `github_pages_update.yml`
Pinning the versions of action workflows

Signed-off-by: Miłosz Linkiewicz <[email protected]>
FIX: Security scans versioning in `validation-tests.yml`
Pinned down the version of pipenv being installed by `python3 -m pip`

Signed-off-by: Miłosz Linkiewicz <[email protected]>
FIX: Added version pinning in setup_build_env.sh. This addressed another issue found by trivy and security tools.

Signed-off-by: Miłosz Linkiewicz <[email protected]>
Signed-off-by: Miłosz Linkiewicz <[email protected]>
@Mionsz Mionsz force-pushed the private/mlinkiew/trivy-related-fixes branch from 7a20351 to 5004be6 Compare July 30, 2025 09:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bug fix Something isn't working help wanted Extra attention is needed maintainers review request Pull request is ready to be reviewed. RC-Blocker Prioritize this label as it is a release candidate and release blocker

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants