Skip to content

chore(ci): move the Trivy scan out of Validate, scope secrets - #8

Merged
JustMaris merged 1 commit into
mainfrom
claude/action-optimization-review-sdwegr
Sep 24, 2026
Merged

JustMaris merged 1 commit into
mainfrom
claude/action-optimization-review-sdwegr

Conversation

@JustMaris

@JustMaris JustMaris commented Sep 24, 2026 •

Copy link
Copy Markdown
Member

Summary

  • auto-merge and release-please: pass only DNB_ROBOT_CLIENT_ID and AUTOMATION_APP_PRIVATE_KEY instead of secrets: inherit, which handed the called workflow every repo and org secret.
  • Dependabot: 7-day cooldown on every ecosystem, so a hijacked or broken release is usually caught and pulled before it's offered here (same as reusable-actions).
  • Trivy image scan moved out of Validate into its own security.yml (PRs + weekly on main), so a CVE can't block every Dependabot merge; dropped the inputs that just restated the reusable workflow's defaults.
  • Commented why go-version stays explicit: go.mod's go 1.27.0 would pin exactly 1.27.0.

Test plan

  • actionlint passes on the changed workflows, and dependabot.yml parses
  • zizmor findings went down, with none added
  • CI passes on this PR

- auto-merge and release-please: pass only DNB_ROBOT_CLIENT_ID and AUTOMATION_APP_PRIVATE_KEY instead of `secrets: inherit`, which handed the called workflow every repo and org secret.

- Dependabot: 7-day cooldown on every ecosystem, so a hijacked or broken release is usually caught and pulled before it's offered here (same as reusable-actions).

- Trivy image scan moved out of Validate into its own `security.yml` (PRs + weekly on main), so a CVE can't block every Dependabot merge; dropped the inputs that just restated the reusable workflow's defaults.

- Commented why `go-version` stays explicit: `go.mod`'s `go 1.27.0` would pin exactly 1.27.0.
@JustMaris
JustMaris merged commit 3864264 into main Sep 24, 2026
6 checks passed
@JustMaris
JustMaris deleted the claude/action-optimization-review-sdwegr branch September 24, 2026 09:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant