Pipeline updates: PR workflow#83
Open
kevinfiol wants to merge 7 commits into
Open
Conversation
kevinfiol
marked this pull request as ready for review
July 23, 2026 19:48
🔒 Security Scan Results
|
| Severity | Total |
|---|---|
| 🟠 High | 9 |
| 🟡 Medium | 1 |
📦 did-lambda
| Severity | Count |
|---|---|
| 🟠 High | 9 |
| 🟡 Medium | 1 |
View detailed results: Security tab
Last updated: 2026-07-23 20:10:55 UTC
Collaborator
Author
RE: Scan results. This is expected since our security scan workflow is based on Refiners, which does NOT ignore CVEs that don't yet have a fix. CDCgov/dibbs-ecr-refiner#1459 In our case, the vulnerabilities lie with the |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Related Issue
#80
Changes Proposed
pr-security-scan.ymlfor PRsmainAdditional Information
Testing
See a run against this branch here: https://github.com/CDCgov/dibbs-ecr-diff/actions/runs/30038936177
You can test locally with
act:act workflow_dispatch -W ./.github/workflows/pipeline.yml # or individually act workflow_dispatch -W ./.github/workflows/typecheck.yml -j ty act workflow_dispatch -W ./.github/workflows/lint.yml -j ruff act workflow_dispatch -W ./.github/workflows/build.yml -j lambda-buildNote: concurrency in
pipeline.ymlis currently not supported byact: https://nektosact.com/not_supported.html?highlight=concurrency#plannedChecklist for Primary Reviewer