Skip to content

ci: pin trivy-action, add gitleaks scanning#2

Open
fheikens wants to merge 1 commit intomainfrom
ci/release-protocol-gates
Open

ci: pin trivy-action, add gitleaks scanning#2
fheikens wants to merge 1 commit intomainfrom
ci/release-protocol-gates

Conversation

@fheikens
Copy link
Copy Markdown
Contributor

Summary

  • Pin trivy-action from @master to @0.31.0 (supply chain hygiene)
  • Add gitleaks secret detection step

Part of Elevarq-wide release protocol standardization. This repo already
had the most mature CI — these are incremental improvements.

Release gates now enforced in CI

  • Correctness: integration tests, resilience tests, startup failure tests
  • Lint: hadolint, ShellCheck, Helm lint
  • Security: Trivy (fs + image + config), gitleaks
  • Artifact: SBOM generation (TODO — add on release workflow)
  • Supply chain: cosign signing (TODO — add on release workflow)

🤖 Generated with Claude Code

- Pin trivy-action from @master to @0.31.0
- Add gitleaks secret detection step in security-scan job

Part of Elevarq release protocol standardization.

Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant