Open tnozicka opened 1 year ago
We use Trivy as well as the one in Dockerhub. They are OK'ish.
The Scylla Operator project currently lacks enough contributors to adequately respond to all issues.
This bot triages un-triaged issues according to the following rules:
lifecycle/stale
is appliedlifecycle/stale
was applied, lifecycle/rotten
is appliedlifecycle/rotten
was applied, the issue is closedYou can:
/remove-lifecycle stale
/close
/lifecycle stale
The Scylla Operator project currently lacks enough contributors to adequately respond to all issues.
This bot triages un-triaged issues according to the following rules:
lifecycle/stale
is appliedlifecycle/stale
was applied, lifecycle/rotten
is appliedlifecycle/rotten
was applied, the issue is closedYou can:
/remove-lifecycle rotten
/close
/lifecycle rotten
/remove lifecycle-rotten /triage accepted /priority backlog
(btw. we also use clair through quay.io)
We should look into the vulnerability scanning and our options compared to just dependabot.
@mykaul sugested to have a look at https://github.com/aquasecurity/trivy for example