fix(security): Remove Hard Fail from Trivy #5394
Merged
+0
−4
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Description
[Provide a brief description of the changes in this PR]
In my retry PR I added an
--exit-code 1
which is doing the correct thing of hard failing the check if there are High and Critical Vulnerabilities found in our code.In order to unblock the queue and get things built and uploaded, going to remove this flag for now and add it back in when we are able to properly address this and dedicate time to fixing each CVE that is identified.
This is a combination of either adding to our trivy ignore file or properly addressing each CVE which is a non-trivial amount of work.
How Has This Been Tested?
[Describe the tests you ran to verify your changes]
Backporting (check the box to trigger backport action)
Note: You have to check that the action passes, otherwise resolve the conflicts manually and tag the patches.