adhit-r / adhit-r/niyama-policy-as-code

CI: Trivy job failing (fix vulnerabilities or configuration)

未關閉
#19 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
主要語言
HTML
星號
0
分支
0
PR 合併指標
30 天內沒有已合併 PR

描述

Observed failing check: Trivy on PR #16. Link: https://github.com/adhit-r/niyama-policy-as-code/actions/runs/19094017272 (job: Trivy).

Acceptance Criteria:
- Inspect Trivy results for image/dependency vulns
- Patch or upgrade vulnerable components, or ignore with justification
- Ensure Trivy passes for backend/frontend images

Deliverables:
- PR(s) with version bumps or config fixes
- Documented ignores with time-bounded follow-ups

Assignees: @adhit-r
Labels: ci, security, dependencies, bug

貢獻指南

這個儲存庫沒有索引到貢獻指南

研究方向

Start with the linked Trivy job in the Actions run for PR #16 and inspect its findings for the backend and frontend images and dependencies. Done means vulnerable components are patched or upgraded, justified ignores have time-bounded follow-ups, and Trivy passes for both images.

由索引模型根據 Issue 內容生成。

評估

領域
ci-cd, security
Issue 類型
缺陷
難度
4/5
預估耗時
3-5 天
活躍度
停滯
描述清晰度
基本清楚
新手友好度
38/100

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。