Skip to content

fix(ci): pin trivy-action to existing v0.36.0 + non-blocking#5

Merged
Headgent merged 1 commit into
developfrom
fix/trivy-action-version
Jun 14, 2026
Merged

fix(ci): pin trivy-action to existing v0.36.0 + non-blocking#5
Headgent merged 1 commit into
developfrom
fix/trivy-action-version

Conversation

@Headgent

Copy link
Copy Markdown
Contributor

Fixt den roten main-Run von P2-phpcli: aquasecurity/trivy-action@0.28.0 existiert nicht → Action-Resolution scheiterte. Alle Images (inkl. Datums-Tags) waren korrekt publiziert; nur der trivy-Job war rot.

  • Pin auf v0.36.0 (via git refs verifiziert; non-v 0.36.0 existiert für diese Version nicht)
  • continue-on-error: true am Job → der informative CVE-Report kann einen Publish nie blockieren (PRD E6)

The previous pin @0.28.0 does not exist (action resolution failed), reddening
the otherwise-green main run although all images published correctly. Pin to
v0.36.0 (verified via git refs) and add continue-on-error so the informational
CVE report can never block a publish, per PRD E6 (Trivy non-blocking).
@Headgent Headgent merged commit 87f4664 into develop Jun 14, 2026
6 checks passed
@Headgent Headgent deleted the fix/trivy-action-version branch June 14, 2026 05:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant