Skip to content

fix: remove trivy from Docker build while assessing compromise impact#56

Merged
dacoburn merged 2 commits intomainfrom
doug/remove-trivy
Mar 22, 2026
Merged

fix: remove trivy from Docker build while assessing compromise impact#56
dacoburn merged 2 commits intomainfrom
doug/remove-trivy

Conversation

@dacoburn
Copy link
Contributor

Summary

Changes

  • Removing Trivy from the image until we confirm the impact of their compromise

Testing


Release checklist (skip for non-release PRs)

  • socket_basics/version.py updated to new version
  • pyproject.toml version: field updated to match
  • action.yml image: ref updated to docker://ghcr.io/socketdev/socket-basics:<new-version> (auto-updated by publish-docker.yml after v2.0.0; manual update required only for the initial v2.0.0 release)
  • CHANGELOG.md [Unreleased] section reviewed (note: this content is replaced by auto-generated release notes when the tag fires — see docs/releasing.md)

⚠️ After merging: run publish-docker.yml via workflow_dispatch with the new version
before creating the git tag. The image must exist in GHCR before the tag is pushed.
See docs/releasing.md for the full process.

@dacoburn dacoburn requested a review from a team as a code owner March 22, 2026 23:03
@dacoburn dacoburn merged commit f3538b7 into main Mar 22, 2026
11 of 12 checks passed
@dacoburn dacoburn deleted the doug/remove-trivy branch March 22, 2026 23:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants