openzipkin / brave

Java distributed tracing implementation compatible with Zipkin backend services.
Apache License 2.0
2.35k stars 714 forks source link

trivy: adds maven-invoker-plugin ignoring config #1420

Closed codefromthecrypt closed 4 months ago

codefromthecrypt commented 4 months ago

I've given up trying to convince trivy to consider maven-invoker-plugin a test vs a deployment. This adds a config and a helper script to run it ad-hoc.

codefromthecrypt commented 4 months ago

marking draft in case upstream accepts a plan forward which is to consider src/it deps "dev dependencies" which would have the same affect of not burdening folks with noise, unless they opt into it.

codefromthecrypt commented 4 months ago

https://github.com/aquasecurity/trivy/pull/6213 obviates this