Repository navigation
Consolidate container image CVE tracking - #65661
Merged
Merged
Conversation
3 tasks
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot
AI
changed the title
[WIP] Consolidate container image scan CVE findings
Consolidate container image CVE tracking
Oct 4, 2026
Comment on lines
35
to
+38
| assign-to-user: | ||
| target: "52657" | ||
| target: "*" | ||
| allowed: [pelikhan] | ||
| max: 1 | ||
| max: 25 |
Contributor
There was a problem hiding this comment.
Copilot review overview
🟡 Changes recommended
The wildcard assignment output needs title and label gates to prevent assignments on unrelated issues.
Review effort: Balanced
Findings: 1
Open (1)
What changed in this PR
Updates container scanning to track CVEs through stable image-family burn-down issues while retaining #52657 as the summary index.
Changes:
- Adds family tracker creation, updates, reopening, assignment, and legacy issue retirement.
- Requires explicit CVE fixes or documented exceptions and adds corresponding evaluations.
- Regenerates workflow locks, including Codex shell-tool compatibility settings.
| File | Description |
|---|---|
.github/workflows/daily-squid-image-scan.md |
Defines family tracking and remediation policy. |
.github/workflows/daily-squid-image-scan.lock.yml |
Compiles the updated scan workflow. |
.github/workflows/windows.lock.yml |
Refreshes Codex configuration. |
.github/workflows/update-astro.lock.yml |
Refreshes Codex configuration. |
.github/workflows/smoke-otel-backends.lock.yml |
Refreshes Codex configuration. |
.github/workflows/smoke-github-codex.lock.yml |
Refreshes Codex configuration. |
.github/workflows/smoke-codex-auto.lock.yml |
Refreshes Codex configuration. |
.github/workflows/smoke-ci.lock.yml |
Refreshes Codex configuration. |
.github/workflows/sighthound-security-scan.lock.yml |
Refreshes Codex configuration. |
.github/workflows/schema-feature-coverage.lock.yml |
Refreshes Codex configuration. |
.github/workflows/repo-audit-analyzer.lock.yml |
Refreshes Codex configuration. |
.github/workflows/purelock.lock.yml |
Refreshes Codex configuration. |
.github/workflows/poem-bot.lock.yml |
Refreshes Codex configuration. |
.github/workflows/outcome-collector.lock.yml |
Refreshes Codex configuration. |
.github/workflows/metrics-collector.lock.yml |
Refreshes Codex configuration. |
.github/workflows/issue-triage-agent.lock.yml |
Refreshes Codex configuration. |
.github/workflows/grumpy-reviewer.lock.yml |
Refreshes Codex configuration. |
.github/workflows/github-remote-mcp-auth-test.lock.yml |
Refreshes Codex configuration. |
.github/workflows/front-page-copy-guard.lock.yml |
Refreshes Codex configuration. |
.github/workflows/example-permissions-warning.lock.yml |
Refreshes Codex configuration. |
.github/workflows/eslint-monster.lock.yml |
Refreshes Codex configuration. |
.github/workflows/dependabot-go-checker.lock.yml |
Refreshes Codex configuration. |
.github/workflows/daily-windows-defender-scan.lock.yml |
Refreshes Codex configuration. |
.github/workflows/daily-spending-forecast.lock.yml |
Refreshes Codex configuration. |
.github/workflows/daily-regulatory.lock.yml |
Refreshes Codex configuration. |
.github/workflows/daily-go-test-parallelizer.lock.yml |
Refreshes Codex configuration. |
.github/workflows/daily-evals-report.lock.yml |
Refreshes Codex configuration. |
.github/workflows/daily-doc-updater.lock.yml |
Refreshes Codex configuration. |
.github/workflows/daily-cli-performance.lock.yml |
Refreshes Codex configuration. |
.github/workflows/daily-awf-spec-compiler-surfacing.lock.yml |
Refreshes Codex configuration. |
.github/workflows/copilot-centralization-optimizer.lock.yml |
Refreshes Codex configuration. |
.github/workflows/commit-changes-analyzer.lock.yml |
Refreshes Codex configuration. |
.github/workflows/cloclo.lock.yml |
Refreshes Codex configuration. |
.github/workflows/changeset.lock.yml |
Refreshes Codex configuration. |
.github/workflows/avenger.lock.yml |
Refreshes Codex configuration. |
.github/workflows/audit-workflows.lock.yml |
Refreshes Codex configuration. |
.github/workflows/api-consumption-report.lock.yml |
Refreshes Codex configuration. |
.github/workflows/agentic-token-trend-audit.lock.yml |
Refreshes Codex configuration. |
.github/workflows/ace-editor.lock.yml |
Refreshes Codex configuration. |
Comment on lines
+36
to
+38
| target: "*" | ||
| allowed: [pelikhan] | ||
| max: 1 | ||
| max: 25 |
This was referenced Oct 5, 2026
Contributor
|
🎉 This pull request is included in a new release. Release: |
11 tasks
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.

Image-scan issues duplicate findings across versions, obscuring active remediation. The workflow now tracks findings by stable image family, retires superseded tag issues, and records a fix path or exception for each CVE.
[container-image-scan] <Family> CVE burn-downissue per scanned family; use issue [container-image-scan] Container CVE burn-down #52657 as a summary index.Example:
[container-image-scan] Firewall CVE burn-downgroups findings across firewall image components and tags.