Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore(deps): update ecr-scan-results-buildkite-plugin to v1.4.0 [CSRE-3451] #29

Merged
merged 1 commit into from
Dec 5, 2023

Conversation

fleet-updates-culture-amp-sre[bot]
Copy link
Contributor

@fleet-updates-culture-amp-sre fleet-updates-culture-amp-sre bot commented Dec 4, 2023

Details

Important

This plugin runs as part of the build and works hard to avoid failing unless your thresholds are reached. It is a low risk update in that an issue with the update is unlikely to block builds from proceeding.

Merge when (a) the build succeeds, and (b) you can see vulnerability findings annotated.

If this update has already been applied by a subsequent PR, please just close this one.

This is an automated PR raised to update the ecr-scan-results-buildkite-plugin. It brings the capability to ignore findings both locally to the repository and centrally via build agent configuration. It is beneficial and safe to apply this update!

Key features of the newest version (more details on GitHub):

  • skips execution when the build has failed
  • allows for vulnerability findings to be ignored using repository
    local configuration
  • CVE lists are now sorted by severity and score, and
  • CVSS3 scores present in source feed are now displayed.

Full details in the release on GitHub.

Example output

image

See also

See https://github.com/cultureamp/ecr-scan-results-buildkite-plugin/releases

Key features of the newest version allows for vulnerability findings to be
ignored using repository local configuration, CVE lists are now sorted by
severity and score, and CVSS3 scores present in source feed are now displayed.

Full details in the release on GitHub.

See https://github.com/cultureamp/ecr-scan-results-buildkite-plugin/releases
@jamestelfer jamestelfer merged commit edbd93a into main Dec 5, 2023
7 checks passed
@jamestelfer jamestelfer deleted the sre/ecr-scan-plugin-update branch December 5, 2023 04:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
None yet
Development

Successfully merging this pull request may close these issues.

2 participants