Skip to content

Remove Trivy (compromised supply chain)#258

Merged
jdfalk merged 1 commit intomainfrom
remove-trivy
Mar 28, 2026
Merged

Remove Trivy (compromised supply chain)#258
jdfalk merged 1 commit intomainfrom
remove-trivy

Conversation

@jdfalk
Copy link
Copy Markdown
Owner

@jdfalk jdfalk commented Mar 27, 2026

Summary

Test plan

  • Verify workflows still run without Trivy jobs
  • Enable CodeQL default setup in repo settings

🤖 Generated with Claude Code

Trivy was compromised (see aquasecurity/trivy#10425). Removing all
Trivy configuration, workflow jobs/steps, scripts, and references.
CodeQL default setup should be used for code scanning instead.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
@github-actions github-actions bot added github-actions GitHub Actions related work type:documentation Improvements or additions to documentation module:config Configuration management tech:python Python programming language workflow:github-actions GitHub Actions workflows size/L labels Mar 27, 2026
@jdfalk jdfalk merged commit dffa8c7 into main Mar 28, 2026
31 of 41 checks passed
@jdfalk jdfalk deleted the remove-trivy branch March 28, 2026 00:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

github-actions GitHub Actions related work module:config Configuration management size/L tech:python Python programming language type:documentation Improvements or additions to documentation workflow:github-actions GitHub Actions workflows

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant