Skip to content

feat(autodiscovery): by default enable gha digest#8074

Merged
olblak merged 2 commits intoupdatecli:mainfrom
olblak:autodiscovery/gha/digest
Mar 24, 2026
Merged

feat(autodiscovery): by default enable gha digest#8074
olblak merged 2 commits intoupdatecli:mainfrom
olblak:autodiscovery/gha/digest

Conversation

@olblak
Copy link
Copy Markdown
Member

@olblak olblak commented Mar 24, 2026

In light of the recent Trivy breach, I am switching the autodiscovery plugin for GitHub action to retrieve digest by default.
While it wouldn't have protected against the attack, at least it would have mitigated it.

Test

To test this pull request, you can run the following commands:

cd <to_package_directory>
go test

Additional Information

Checklist

  • I have updated the documentation via pull request in website repository.

Tradeoff

Potential improvement

@olblak olblak added autodiscovery All things related to the autodiscovery feature github_actions Pull requests that update Github_actions code labels Mar 24, 2026
@loispostula
Copy link
Copy Markdown
Contributor

@olblak you'll probably need #8075

@olblak olblak added the enhancement New feature or request label Mar 24, 2026
@olblak olblak enabled auto-merge (squash) March 24, 2026 13:45
@olblak olblak merged commit e63bf71 into updatecli:main Mar 24, 2026
7 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

autodiscovery All things related to the autodiscovery feature enhancement New feature or request github_actions Pull requests that update Github_actions code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants