Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: remove docker image scanning #515

Merged
merged 1 commit into from
Oct 16, 2023

Conversation

shreemaan-abhishek
Copy link
Contributor

Following is the dependency graph for APISIX:

image

Most CVEs are from 3rd and 4th-level dependencies, which are difficult to upgrade/fix. Due to the existing CVEs the CI always fails and adding unfixable CVEs to an allowlist does not scale. Moreover, it is a problem in the long run for maintainers.

That's why I propose that we remove the docker image scanning workflow.

@monkeyDluffy6017 monkeyDluffy6017 merged commit bf08d86 into apache:master Oct 16, 2023
9 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants