Skip to content

chore(security): automated Trivy autofix PRs#132

Open
fyzanshaik-atlan wants to merge 4 commits intomainfrom
codex/security-autofix
Open

chore(security): automated Trivy autofix PRs#132
fyzanshaik-atlan wants to merge 4 commits intomainfrom
codex/security-autofix

Conversation

@fyzanshaik-atlan
Copy link
Copy Markdown
Collaborator

Adds repo-local Trivy scanning pinned to aquasecurity/trivy-action@0.33.1 (uv.lock support) and a weekly/manual security autofix workflow.

Autofix behavior:

  • Scan HIGH/CRITICAL vulnerabilities
  • Attempt deterministic uv remediation across all apps
  • Run unit tests where available
  • Open/update a single PR, or create an issue when findings are unfixable

Requires GitHub App secrets: SECURITY_AUTOFIX_APP_ID and SECURITY_AUTOFIX_APP_PRIVATE_KEY.

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Feb 3, 2026

📦 Trivy Vulnerability Scan Results

Schema Version Created At Artifact Type
2 2026-02-03T15:18:01.053466652Z . filesystem

Report Summary

Could not generate summary table (data length mismatch: 30 vs 27).

Scan Result Details

connectors/anaplan/uv.lock
connectors/mysql/uv.lock
quickstart/ai_giphy/uv.lock
quickstart/giphy/uv.lock
quickstart/hello_world/uv.lock
templates/generic/uv.lock
utilities/asset_descriptor_reminder/uv.lock
utilities/freshness_monitor/uv.lock
utilities/workflows_observability/uv.lock

@github-actions
Copy link
Copy Markdown

github-actions Bot commented Feb 3, 2026

📦 Trivy Secret Scan Results

Schema Version Created At Artifact Type
2 2026-02-03T15:18:13.879938886Z . filesystem

Report Summary

Target Type Secrets . filesystem ✅ None found

Scan Result Details

✅ No secrets found during the scan for ..

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant