Skip to content

Consolidate container image CVE tracking - #65661

Merged
pelikhan merged 3 commits into
mainfrom
copilot/aw-top-10-consolidate-cve-findings
Oct 4, 2026
Merged

pelikhan merged 3 commits into
mainfrom
copilot/aw-top-10-consolidate-cve-findings

Conversation

Copilot AI commented Oct 4, 2026 •

Copy link
Copy Markdown
Contributor

Image-scan issues duplicate findings across versions, obscuring active remediation. The workflow now tracks findings by stable image family, retires superseded tag issues, and records a fix path or exception for each CVE.

  • Family trackers: Maintain one [container-image-scan] <Family> CVE burn-down issue per scanned family; use issue [container-image-scan] Container CVE burn-down #52657 as a summary index.
  • Superseded tags: Close legacy per-tag issues only when compiler output confirms the image reference is no longer in use; retain ambiguous references.
  • CVE disposition: Record a fixed package version and corresponding image bump, or an exception with its reason, owner, relevant advisory, and review date.

Example: [container-image-scan] Firewall CVE burn-down groups findings across firewall image components and tags.

Copilot AI and others added 2 commits October 4, 2026 21:05
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Co-authored-by: pelikhan <4175913+pelikhan@users.noreply.github.com>
Copilot AI changed the title [WIP] Consolidate container image scan CVE findings Consolidate container image CVE tracking Oct 4, 2026
Copilot AI requested a review from pelikhan October 4, 2026 21:10
Comment on lines 35 to +38
assign-to-user:
target: "52657"
target: "*"
allowed: [pelikhan]
max: 1
max: 25
@pelikhan
pelikhan marked this pull request as ready for review October 4, 2026 21:49
Copilot AI balanced review requested due to automatic review settings October 4, 2026 21:49
@pelikhan
pelikhan merged commit a5e1584 into main Oct 4, 2026
3 checks passed
@pelikhan
pelikhan deleted the copilot/aw-top-10-consolidate-cve-findings branch October 4, 2026 21:49

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

The wildcard assignment output needs title and label gates to prevent assignments on unrelated issues.

Review effort: Balanced
Findings: 1 Medium severity

Open (1)
What changed in this PR

Updates container scanning to track CVEs through stable image-family burn-down issues while retaining #52657 as the summary index.

Changes:

  • Adds family tracker creation, updates, reopening, assignment, and legacy issue retirement.
  • Requires explicit CVE fixes or documented exceptions and adds corresponding evaluations.
  • Regenerates workflow locks, including Codex shell-tool compatibility settings.
File Description
.github/​workflows/​daily-squid-image-scan.md Defines family tracking and remediation policy.
.github/​workflows/​daily-squid-image-scan.lock.yml Compiles the updated scan workflow.
.github/​workflows/​windows.lock.yml Refreshes Codex configuration.
.github/​workflows/​update-astro.lock.yml Refreshes Codex configuration.
.github/​workflows/​smoke-otel-backends.lock.yml Refreshes Codex configuration.
.github/​workflows/​smoke-github-codex.lock.yml Refreshes Codex configuration.
.github/​workflows/​smoke-codex-auto.lock.yml Refreshes Codex configuration.
.github/​workflows/​smoke-ci.lock.yml Refreshes Codex configuration.
.github/​workflows/​sighthound-security-scan.lock.yml Refreshes Codex configuration.
.github/​workflows/​schema-feature-coverage.lock.yml Refreshes Codex configuration.
.github/​workflows/​repo-audit-analyzer.lock.yml Refreshes Codex configuration.
.github/​workflows/​purelock.lock.yml Refreshes Codex configuration.
.github/​workflows/​poem-bot.lock.yml Refreshes Codex configuration.
.github/​workflows/​outcome-collector.lock.yml Refreshes Codex configuration.
.github/​workflows/​metrics-collector.lock.yml Refreshes Codex configuration.
.github/​workflows/​issue-triage-agent.lock.yml Refreshes Codex configuration.
.github/​workflows/​grumpy-reviewer.lock.yml Refreshes Codex configuration.
.github/​workflows/​github-remote-mcp-auth-test.lock.yml Refreshes Codex configuration.
.github/​workflows/​front-page-copy-guard.lock.yml Refreshes Codex configuration.
.github/​workflows/​example-permissions-warning.lock.yml Refreshes Codex configuration.
.github/​workflows/​eslint-monster.lock.yml Refreshes Codex configuration.
.github/​workflows/​dependabot-go-checker.lock.yml Refreshes Codex configuration.
.github/​workflows/​daily-windows-defender-scan.lock.yml Refreshes Codex configuration.
.github/​workflows/​daily-spending-forecast.lock.yml Refreshes Codex configuration.
.github/​workflows/​daily-regulatory.lock.yml Refreshes Codex configuration.
.github/​workflows/​daily-go-test-parallelizer.lock.yml Refreshes Codex configuration.
.github/​workflows/​daily-evals-report.lock.yml Refreshes Codex configuration.
.github/​workflows/​daily-doc-updater.lock.yml Refreshes Codex configuration.
.github/​workflows/​daily-cli-performance.lock.yml Refreshes Codex configuration.
.github/​workflows/​daily-awf-spec-compiler-surfacing.lock.yml Refreshes Codex configuration.
.github/​workflows/​copilot-centralization-optimizer.lock.yml Refreshes Codex configuration.
.github/​workflows/​commit-changes-analyzer.lock.yml Refreshes Codex configuration.
.github/​workflows/​cloclo.lock.yml Refreshes Codex configuration.
.github/​workflows/​changeset.lock.yml Refreshes Codex configuration.
.github/​workflows/​avenger.lock.yml Refreshes Codex configuration.
.github/​workflows/​audit-workflows.lock.yml Refreshes Codex configuration.
.github/​workflows/​api-consumption-report.lock.yml Refreshes Codex configuration.
.github/​workflows/​agentic-token-trend-audit.lock.yml Refreshes Codex configuration.
.github/​workflows/​ace-editor.lock.yml Refreshes Codex configuration.

Comment on lines +36 to +38
target: "*"
allowed: [pelikhan]
max: 1
max: 25
@github-actions

github-actions Bot commented Oct 5, 2026

Copy link
Copy Markdown
Contributor

🎉 This pull request is included in a new release.

Release: v0.91.0

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[AW Top 10] 05 Consolidate container image scan CVE findings

4 participants