Repository navigation
Conversation
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Triage SummaryCategory: chore (security/license policy update) Updates Next: fast-track once CI passes — keeps the security/compliance scan green.
|
There was a problem hiding this comment.
Pull request overview
Updates Grant’s container-license policy for reviewed firewall image findings.
Changes:
- Expands allowed licenses and ignored packages.
- Adds policy regression tests.
- Adds a patch changeset.
Show a summary per file
| File | Description |
|---|---|
.grant.yaml |
Adds reviewed licenses and package exclusions. |
pkg/cli/grant_test.go |
Verifies required policy entries remain present. |
.changeset/patch-container-grant-policy.md |
Records the policy update. |
Review details
Tip
Add Copilot custom instructions for smarter, more guided reviews. Learn how to get started.
- Files reviewed: 3/3 changed files
- Comments generated: 1
- Review effort level: Balanced
| allow: | ||
| - MIT | ||
| - Apache-2.0 | ||
| - Artistic-2.0 |
The daily container image scan reported license policy violations for
gh-aw-firewall/cli-proxy:0.27.44, mostly from Alpine base-layer/runtime packages and known permissive licenses not yet represented in the Grant policy. No newergh-aw-firewallrelease is currently available to consume for the remaining upstream image CVEs.Grant policy
BlueOak-1.0.0,MPL-2.0,Zlib,curl,CC0-1.0, andCC-BY-3.0.Regression coverage