Skip to content

Chore: [AEA-6424] - use new quality checks#735

Merged
anthony-nhs merged 1 commit intomainfrom
new_qc
Apr 13, 2026
Merged

Chore: [AEA-6424] - use new quality checks#735
anthony-nhs merged 1 commit intomainfrom
new_qc

Conversation

@anthony-nhs
Copy link
Copy Markdown
Contributor

Summary

  • Routine Change

Details

  • use latest quality checks

Copilot AI review requested due to automatic review settings April 13, 2026 16:32
@sonarqubecloud
Copy link
Copy Markdown

Copy link
Copy Markdown

Copilot AI left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Pull request overview

Updates repository quality/security tooling to align with the latest shared “quality checks” setup, tightening GitHub Actions token permissions and adjusting local developer checks accordingly.

Changes:

  • Removed legacy Trivy configuration/ignore files.
  • Updated GitHub Actions workflows to use newer pinned versions of shared EPS common workflows and added explicit permissions blocks.
  • Added a local pre-commit Grype scan hook, introduced CODEOWNERS coverage for workflow changes, and bumped the devcontainer image version.

Reviewed changes

Copilot reviewed 9 out of 10 changed files in this pull request and generated no comments.

Show a summary per file
File Description
trivy.yaml Removes Trivy configuration (no longer needed with updated quality checks).
.trivyignore.yaml Removes Trivy vulnerability ignore configuration.
.pre-commit-config.yaml Adds a local Grype scan hook via make grype-scan-local.
.github/workflows/sync_copilot.yml Adds explicit workflow-level permissions hardening.
.github/workflows/release.yml Updates shared workflow refs and scopes job permissions explicitly.
.github/workflows/pull_request.yml Updates shared workflow refs and scopes job permissions explicitly.
.github/workflows/ci.yml Updates shared workflow refs and scopes job permissions explicitly.
.github/CODEOWNERS Adds codeowner requirement for workflow changes.
.devcontainer/devcontainer.json Bumps devcontainer image version to v1.4.4.

@sonarqubecloud
Copy link
Copy Markdown

@anthony-nhs anthony-nhs merged commit b429fbf into main Apr 13, 2026
15 checks passed
@anthony-nhs anthony-nhs deleted the new_qc branch April 13, 2026 16:36
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants