Skip to content

chore: add build, verify, secret-scan, dependency-review, typos, and Trivy image scan jobs#2302

Open
kristina-solovyova wants to merge 1 commit into02-15-chore_add_linters_configurationfrom
03-02-chore_add_build_verify_secret-scan_dependency-review_typos_and_trivy_image_scan_jobs
Open

chore: add build, verify, secret-scan, dependency-review, typos, and Trivy image scan jobs#2302
kristina-solovyova wants to merge 1 commit into02-15-chore_add_linters_configurationfrom
03-02-chore_add_build_verify_secret-scan_dependency-review_typos_and_trivy_image_scan_jobs

Conversation

@kristina-solovyova
Copy link
Collaborator

No description provided.

@github-actions
Copy link

github-actions bot commented Mar 2, 2026

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/aquasecurity/trivy-action 0.34.1 🟢 6.3
Details
CheckScoreReason
Maintained🟢 79 commit(s) and 0 issue activity found in the last 90 days -- score normalized to 7
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Packaging⚠️ -1packaging workflow not detected
Code-Review🟢 9Found 21/22 approved changesets -- score normalized to 9
Binary-Artifacts🟢 10no binaries found in the repo
Token-Permissions🟢 7detected GitHub workflow tokens with excessive permissions
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy⚠️ 0security policy file not detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • .github/workflows/package.yaml

Copy link
Collaborator Author

kristina-solovyova commented Mar 2, 2026

Warning

This pull request is not mergeable via GitHub because a downstack PR is open. Once all requirements are satisfied, merge this PR as a stack on Graphite.
Learn more


How to use the Graphite Merge Queue

Add the label main-merge-queue to this PR to add it to the merge queue.

You must have a Graphite account in order to use the merge queue. Sign up using this link.

An organization admin has required the Graphite Merge Queue in this repository.

Please do not merge from GitHub as this will restart CI on PRs being processed by the merge queue.

This stack of pull requests is managed by Graphite. Learn more about stacking.

@kristina-solovyova kristina-solovyova force-pushed the 03-02-chore_add_build_verify_secret-scan_dependency-review_typos_and_trivy_image_scan_jobs branch 2 times, most recently from 27ed8a2 to fab46bd Compare March 2, 2026 15:42
@kristina-solovyova kristina-solovyova force-pushed the 03-02-chore_add_build_verify_secret-scan_dependency-review_typos_and_trivy_image_scan_jobs branch from fab46bd to 5e7cd77 Compare March 2, 2026 17:16
@kristina-solovyova kristina-solovyova mentioned this pull request Mar 3, 2026
@kristina-solovyova kristina-solovyova marked this pull request as ready for review March 5, 2026 08:50
@kristina-solovyova kristina-solovyova requested a review from a team as a code owner March 5, 2026 08:50
@graphite-app graphite-app bot requested review from assafgi and tigrawap March 5, 2026 08:50
@graphite-app
Copy link

graphite-app bot commented Mar 5, 2026

Graphite Automations

"Add anton/matt/sergey/kristina as reviwers on operator PRs" took an action on this PR • (03/05/26)

2 reviewers were added to this PR based on Anton Bykov's automation.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant