Skip to content

Fix: [AEA-0000] - Always run valid trivy scans even if a previous scan failed, so that all vulnerabilities are identified at once. Shorten feedback cycle for vulnerabilities across multiple scans.#78

Merged
connoravo-nhs merged 3 commits intomainfrom
always-run-valid-trivy-scans
Mar 5, 2026
Merged

Conversation

@connoravo-nhs
Copy link
Contributor

Summary

  • Routine Change

Details

Always run required trivy vulnerability scans for all that apply, even if the previous scan has identified vulnerabilities and has failed. This shortens the feedback cycle for vulnerabilities across multiple scan types.

…all vulnerabilities are identified at once. Shorten feedback cycle for vulnerabilities across multiple scans.
@github-actions
Copy link
Contributor

github-actions bot commented Mar 5, 2026

This PR is linked to a ticket in an NHS Digital JIRA Project. Here's a handy link to the ticket:

AEA-0000

@connoravo-nhs connoravo-nhs enabled auto-merge (squash) March 5, 2026 15:03
connoravo-nhs and others added 2 commits March 5, 2026 15:54
Co-authored-by: tstephen-nhs <231503406+tstephen-nhs@users.noreply.github.com>
Signed-off-by: Connor Avery <214469360+connoravo-nhs@users.noreply.github.com>
@sonarqubecloud
Copy link

sonarqubecloud bot commented Mar 5, 2026

@connoravo-nhs connoravo-nhs merged commit d116ba9 into main Mar 5, 2026
11 checks passed
@connoravo-nhs connoravo-nhs deleted the always-run-valid-trivy-scans branch March 5, 2026 16:33
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants