fix(ci): unblock integrations GHCR + lockfile builds - #312
Conversation
|
You have reached your Codex usage limits for code reviews. You can see your limits in the Codex usage dashboard. |
|
Caution Review failedThe pull request is closed. WalkthroughAdds CVE ignore lists for Trivy scanning, updates the GHCR integration GitHub Actions workflow to support Trivy ignore files and OIDC-based Cosign verification, updates build matrix entries, and modifies Dockerfiles to copy dependency lockfiles. Changes
Estimated code review effort🎯 3 (Moderate) | ⏱️ ~20–25 minutes
Possibly related PRs
Poem
✨ Finishing touches🧪 Generate unit tests (beta)
📜 Recent review detailsConfiguration used: CodeRabbit UI Review profile: CHILL Plan: Pro 📒 Files selected for processing (5)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
fix(ci): unblock integrations GHCR + lockfile builds
Fixes the integrations GHCR pipeline so it runs to completion and builds consistently.
cosign verifyidentity/issuer flags (cosign 2.x requires identity in keyless mode).pmoves/docker-compose.ymland adds Trivy ignore hooks for known upstream-only findings.requirements.lockso-r requirements.lockresolves during image builds.Notes
Summary by CodeRabbit
✏️ Tip: You can customize this high-level summary in your review settings.