Skip to content

Add lhotari/sandboxed-trivy-action v1.0.2 to approved actions#711

Open
lhotari wants to merge 1 commit intoapache:mainfrom
lhotari:lh-sandboxed-trivy-action-v1.0.2
Open

Add lhotari/sandboxed-trivy-action v1.0.2 to approved actions#711
lhotari wants to merge 1 commit intoapache:mainfrom
lhotari:lh-sandboxed-trivy-action-v1.0.2

Conversation

@lhotari
Copy link
Copy Markdown
Member

@lhotari lhotari commented Apr 14, 2026

Summary

Adds lhotari/sandboxed-trivy-action hash for v1.0.2.
Action name with hash: lhotari/sandboxed-trivy-action@f01374b6cc3bf7264ab238293e94f6db7ada6dd0

v1.0.2 contains a change by @rmoff to add Trivy scanning to Apache Iceberg's Kafka Connect CI.

@lhotari
Copy link
Copy Markdown
Member Author

lhotari commented Apr 14, 2026

I just noticed that there's a separate process for handling updates by Dependabot. Is this PR required?

@raboof
Copy link
Copy Markdown
Member

raboof commented Apr 14, 2026

I just noticed that there's a separate process for handling updates by Dependabot. Is this PR required?

Indeed it shouldn't be needed and Dependabot should crate it. We currently still have a cooldown configured but intend (#683) to remove that.

lhotari/sandboxed-trivy-action:
555963036b2012b44c1071508a236e569db28ebb:
tag: v1.0.1
f01374b6cc3bf7264ab238293e94f6db7ada6dd0:
Copy link
Copy Markdown
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

you're welcome to close and wait for dependabot or leave this PR open. If you want to leave it open: the idea is to add an expiry date to the 1.0.1 version now - 6 months from now or so.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants