-
Notifications
You must be signed in to change notification settings - Fork 228
fix: resolve CI failures in scorecard and image-scanning workflows #2336
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Conversation
…plugin_details_id (#1811) * remove plugin api test * fix id error. rename old id to new installedid
* refactor: change the color of Please sign in notification * chore: remove redundant dependency
* Remove plugins folder * Improve deployer service * Format k8 service * Fix build failure * Fix formatting
* locale sync: fail & comment * locale: sync all locales with master * Revert "locale: sync all locales with master" This reverts commit 8d7505d. * fix: locale sync check script * fix: remove unused import * ci: add locale sync check step * ci: use GH_REPO_TOKEN for PR commenting * ci: add token debug check * feat: add GitHub issue creation for locale sync * fix: final locale sync improvements * test: trigger CI to verify GH_REPO_TOKEN * fix: remove invalid comment causing syntax error * test: trigger fresh CI run to verify token * fix: final cleanup - ready for maintainer token setup * fix: add GITHUB_TOKEN fallback for locale sync check * debug: add token detection logging to identify permission issue * debug: enhance token debugging to identify permission issue * test: trigger CI to verify GH_REPO_TOKEN works for PR commenting * fix: resolve linting errors in locale sync script * fix: finalize PR comment logic for locale sync check Signed-off-by: Rishi Jat <[email protected]> * fix: finalize PR comment logic for locale sync check Signed-off-by: Rishi Jat <[email protected]> --------- Signed-off-by: Rishi Jat <[email protected]>
…1756) Signed-off-by: Krrish Sehgal <[email protected]>
* Update All Signed-off-by: adity1raut <[email protected]> * Update package-lock.json --------- Signed-off-by: adity1raut <[email protected]>
… component (#1771) * Fix debug log indentation and update showLogs prop based on onboarding status in ImportClusters component Signed-off-by: alokdangre <[email protected]> * Fix indentation in debug log comment in ImportClusters component --------- Signed-off-by: alokdangre <[email protected]>
* fixes in filter * optimise-filter * added check for sync
…d components (#1548) * chore: update version references to 0.28.0 across backend and frontend components Signed-off-by: arpit529srivastava <[email protected]> * chore: update documentation links to point to the latest version across frontend components Signed-off-by: arpit529srivastava <[email protected]> * chore: downgrade default version to 0.27.2 in WDS context creation Signed-off-by: arpit529srivastava <[email protected]> * chore: update script command to use version 0.27.2 in InstallationPage Signed-off-by: arpit529srivastava <[email protected]> * fixed link Signed-off-by: arpit529srivastava <[email protected]> --------- Signed-off-by: arpit529srivastava <[email protected]>
* enable prometheus server and grafana dashboard * add grafana dashboard in ui * add grafana menu * fix format issue * fix format issue * add translations * fix format issue * fix linting
…on (#1732) * refactor(installer): improve prerequisite checks and version extraction - Introduce CheckCommand() to verify binaries exist before running - Separate args (for existence check) and versionArgs (for version extraction) - In checkPrerequisite(): • Use LookPath to distinguish “not installed” vs “installed but errored” • Always capture CombinedOutput (ignore exit code) so we can parse version even on runtime errors - Update extractors for Kubeflex and clusteradm: • Regex now matches core semver (x.y.z) and ignores suffixes (e.g. a2f9eab or -0-g…) - Normalize all extractor functions to strip leading “v” and trim whitespace - Alias amd64/x86_64 in checkArchitecture to avoid false incompatibility - Guard sysctl checks behind a simple “docker run busybox echo” test - Cosmetic: rename prereq struct fields (args vs versionArgs) for clarity Closes: n/a * fix(installer): update prerequisite check to mark command as installed if it exists * fix(installer): handle command failure in prerequisite check by returning unknown version Signed-off-by: Alok Dangre <[email protected]> * fixed error --------- Signed-off-by: Alok Dangre <[email protected]>
…1842) Bumps [helm.sh/helm/v3](https://github.com/helm/helm) from 3.18.4 to 3.18.5. - [Release notes](https://github.com/helm/helm/releases) - [Commits](helm/helm@v3.18.4...v3.18.5) --- updated-dependencies: - dependency-name: helm.sh/helm/v3 dependency-version: 3.18.5 dependency-type: direct:production ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
…1840) (#1845) Signed-off-by: Rishi Jat <[email protected]>
…#1854) * Add the documentation for installating the plugin from the local * Remove doc
* remove plugin api test * fix id error. rename old id to new installedid * fix: Install Now button is clickable * fix: prettier error
…nnecessary timeout (#1850) * refactor onboarding process: improve completion handling and remove unnecessary timeout * remove unnecessary debug log statement from onboarding process
* Update Signed-off-by: adity1raut <[email protected]> * Update Bug Signed-off-by: adity1raut <[email protected]> --------- Signed-off-by: adity1raut <[email protected]>
…rrors (#1866) Signed-off-by: alokdangre <[email protected]>
…identification of plugins) (#1867)
…#1873) * refactor: switching installed_plugin_id to plugin_details_id (global identification of plugins) * refactor: plugin feedback submission * chore: fixing the suggestions field * test: update test API only
* feat: add DB auto migration * chore: handle auto-migrating failing errors
* added Missing Translation * added Missing Translation for hindi * Lowercase the Grafana
* fix: marketplace upload error when same plugin is already installed * fix: add missing argument IsMarketPlacePlugin * fix wrong comment in latest up migration * add is_marketplace_plugin in json type for model
- Mount quay-auth secret for registry authentication - Configure buildah to use the auth credentials - Temporarily skip frontend build (blocked by Dockerfile issue #2329) The quay-auth secret has been created in the test-pods namespace on the Prow cluster. Signed-off-by: Andrew Anderson <[email protected]>
Make locale sync check informational instead of failing
ci: skip pr-verifier for dependabot PRs
ci: standardize workflow naming and add common workflows
Add OpenSSF Scorecard for security scoring and visibility. Results are published to GitHub Security tab. Co-authored-by: Claude Opus 4.5 <[email protected]>
* chore: add OpenSSF Scorecard workflow Add OpenSSF Scorecard for security scoring and visibility. Results are published to GitHub Security tab. Co-Authored-By: Claude Opus 4.5 <[email protected]> * chore: add Trivy container image scanning Add Trivy vulnerability scanning for container images. Scans for CRITICAL and HIGH CVEs, results published to GitHub Security tab. Co-Authored-By: Claude Opus 4.5 <[email protected]> --------- Co-authored-by: Claude Opus 4.5 <[email protected]>
- Fix scorecard.yml: use job-level permissions instead of workflow-level
to satisfy OSSF scorecard webapp restrictions
- Fix image-scanning.yml: update Dockerfile paths where needed
Signed-off-by: Andrew Anderson <[email protected]>
|
[APPROVALNOTIFIER] This PR is NOT APPROVED This pull-request has been approved by: The full list of commands accepted by this bot can be found here. DetailsNeeds approval from an approver in each of these files:Approvers can indicate their approval by writing |
Summary
Details
The OpenSSF Scorecard action rejects workflows with global write permissions. This PR moves the permissions to job-level.
For repos with multiple Dockerfiles (galaxy, ui), a matrix build strategy is used to scan all components.
Test plan
🤖 Generated with Claude Code