Skip to content

chore(ci): Remove trivy - Manifests#3424

Merged
google-oss-prow[bot] merged 2 commits into
kubeflow:masterfrom
sameerdattav:remove-trivy
Mar 27, 2026
Merged

chore(ci): Remove trivy - Manifests#3424
google-oss-prow[bot] merged 2 commits into
kubeflow:masterfrom
sameerdattav:remove-trivy

Conversation

@sameerdattav

Copy link
Copy Markdown
Contributor

Removing trivy action - as instructed by @andreyvelich following kubeflow/katib#2644

Signed-off-by: Surya Sameer Datta Vaddadi <f20220373@goa.bits-pilani.ac.in>
Copilot AI review requested due to automatic review settings March 25, 2026 21:22
@github-actions

Copy link
Copy Markdown

Welcome to the Kubeflow Manifests Repository

Thanks for opening your first PR. Your contribution means a lot to the Kubeflow community.

Before making more PRs:
Please ensure your PR follows our Contributing Guide.
Please also be aware that many components are synchronizes from upstream via the scripts in /scripts.
So in some cases you have to fix the problem in the upstream repositories first, but you can use a PR against kubeflow/manifests to test the platform integration.

Community Resources:

Thanks again for helping to improve Kubeflow.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

This PR removes the GitHub Actions workflow that performed image extraction and Trivy-based vulnerability scanning for the kubeflow/manifests repository, aligning with the referenced instruction to drop this action.

Changes:

  • Deleted .github/workflows/trivy.yaml, removing the CI job that installed kustomize/trivy/python and ran tests/trivy_scan.py.
  • Eliminated artifact upload of trivy_scanned_results from CI.

@juliusvonkohout

Copy link
Copy Markdown
Member

Hello, this action is self-written. Why do you want to remove it ? Is the binary affected ?

@juliusvonkohout

Copy link
Copy Markdown
Member

/hold

@andreyvelich

Copy link
Copy Markdown
Member

Hello, this action is self-written. Why do you want to remove it ? Is the binary affected ?

@juliusvonkohout Please check the Slack security thread.

Comment thread .github/workflows/trivy.yaml
Signed-off-by: Surya Sameer Datta Vaddadi <f20220373@goa.bits-pilani.ac.in>
@google-oss-prow google-oss-prow Bot added size/S and removed size/M labels Mar 26, 2026
@juliusvonkohout

Copy link
Copy Markdown
Member

/lgtm
/approve

@juliusvonkohout

Copy link
Copy Markdown
Member

/unhold

@juliusvonkohout

juliusvonkohout commented Mar 27, 2026

Copy link
Copy Markdown
Member

/hold
Again. With 0.69.3 considered safe and immutable releases

@juliusvonkohout

Copy link
Copy Markdown
Member

Ok but as discussed with the cncf supply chain guy
/lgtm
/approve
/unhold

@google-oss-prow

Copy link
Copy Markdown

[APPROVALNOTIFIER] This PR is APPROVED

This pull-request has been approved by: juliusvonkohout

The full list of commands accepted by this bot can be found here.

The pull request process is described here

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@google-oss-prow google-oss-prow Bot merged commit 46f3142 into kubeflow:master Mar 27, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

4 participants