Skip to content

ci: route trivy findings to jira - #429

Draft
alexpriv8 wants to merge 1 commit into
masterfrom
trivy-jira-routing
Draft

alexpriv8 wants to merge 1 commit into
masterfrom
trivy-jira-routing

Conversation

@alexpriv8

Copy link
Copy Markdown
Contributor

Description of change

Align the repository Trivy scanner configuration with the public shared action and enable the maintained license scanner settings.

Validation

  • Staged-file pre-commit checks passed.
  • No internal Jira references are included.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings September 25, 2026 22:32
@deepsource-io

deepsource-io Bot commented Sep 25, 2026 •

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in 3abac28...8cccf48 on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Secrets Sep 25, 2026 10:33p.m. Review ↗
Python Sep 25, 2026 10:33p.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Removing vuln globally disables scheduled vulnerability scanning; configure the scheduled job to pass it explicitly.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 1 High severity

Open (1)
What changed in this PR

Updates Trivy configuration to align with the shared action and enable license scanning.

Changes:

  • Removes vuln from the scanner list.
  • Enables license scanning.
File Summary
.trivy.yaml Adjusts enabled Trivy scanners.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .trivy.yaml
offline: true
scanners:
- vuln
# - vuln # keep disabled so not checked on PRs but explicitly via scheduled .github/workflows/pre-commit-cache.yaml

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants