Skip to content

ci: route trivy findings to jira - #12

Draft
alexpriv8 wants to merge 1 commit into
masterfrom
trivy-jira-routing
Draft

alexpriv8 wants to merge 1 commit into
masterfrom
trivy-jira-routing

Conversation

@alexpriv8

Copy link
Copy Markdown
Contributor

Description of change

Align the repository Trivy scanner configuration with the public shared action and enable the maintained license scanner settings.

Validation

  • Staged-file pre-commit checks passed.
  • No internal Jira references are included.

Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com>
Copilot AI lite review requested due to automatic review settings September 25, 2026 22:32
@deepsource-io

deepsource-io Bot commented Sep 25, 2026

Copy link
Copy Markdown

DeepSource Code Review

We reviewed changes in db4763d...553befd on this pull request. Below is the summary for the review, and you can see the individual issues we found as inline review comments.

See full review on DeepSource ↗

PR Report Card

Overall Grade   Security  

Reliability  

Complexity  

Hygiene  

Code Review Summary

Analyzer Status Updated (UTC) Details
Go Sep 25, 2026 10:33p.m. Review ↗

Important

AI Review is run only on demand for your team. We're only showing results of static analysis review right now. To trigger AI Review, comment @deepsourcebot review on this thread.

Copilot AI left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Restore vulnerability coverage and scope license scanning appropriately.

Get a fresh assessment by requesting another Copilot review.

Review effort: Lite
Findings: 2 Medium severity

Open (2)
What changed in this PR

Updates Trivy configuration to route findings toward Jira by enabling license scanning and disabling vulnerability scanning.

Changes:

  • Disables the vuln scanner.
  • Enables license scanning settings.
File Summary
.trivy.yaml Adjusts Trivy scanners; moderate issues remain regarding lost vulnerability coverage and license scanning affecting local pre-commit runs.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

Comment thread .trivy.yaml
offline: true
scanners:
- vuln
# - vuln # keep disabled so not checked on PRs but explicitly via scheduled .github/workflows/pre-commit-cache.yaml
Comment thread .trivy.yaml
# - vuln # keep disabled so not checked on PRs but explicitly via scheduled .github/workflows/pre-commit-cache.yaml
- secret
- misconfig
- license # while enabled but run via the separate 'trivy-license' action
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants