Skip to content

Commit c6d5da1

Browse files
authored
Merge pull request #3461 from cdr/jsjoeio/fix-3459
fix(ci): disable trivy-scan-image
2 parents 99542e6 + 35f57e5 commit c6d5da1

File tree

3 files changed

+9
-19
lines changed

3 files changed

+9
-19
lines changed

.github/workflows/ci.yaml

+6-1
Original file line numberDiff line numberDiff line change
@@ -434,7 +434,9 @@ jobs:
434434
trivy-scan-image:
435435
runs-on: ubuntu-20.04
436436
needs: docker-amd64
437-
437+
# NOTE@jsjoeio: disabling due to a memory issue upstream
438+
# See: https://github.com/github/codeql-action/issues/528
439+
if: 1 == 2
438440
steps:
439441
- name: Checkout code
440442
uses: actions/checkout@v2
@@ -457,6 +459,9 @@ jobs:
457459
output: "trivy-image-results.sarif"
458460
severity: "HIGH,CRITICAL"
459461

462+
- name: Debug Trivy SARIF file
463+
run: cat trivy-image-results.sarif && ls -l trivy-image-results.sarif
464+
460465
- name: Upload Trivy scan results to GitHub Security tab
461466
uses: github/codeql-action/upload-sarif@v1
462467
with:

package.json

+1
Original file line numberDiff line numberDiff line change
@@ -80,6 +80,7 @@
8080
"doctoc/**/trim": "^1.0.0",
8181
"postcss": "^8.2.1",
8282
"parcel-bundler/cssnano": "^5.0.2",
83+
"browserslist": "^4.16.5",
8384
"safe-buffer": "^5.1.1",
8485
"vfile-message": "^2.0.2"
8586
},

yarn.lock

+2-18
Original file line numberDiff line numberDiff line change
@@ -1867,18 +1867,7 @@ browserify-zlib@^0.2.0:
18671867
dependencies:
18681868
pako "~1.0.5"
18691869

1870-
browserslist@^4.0.0, browserslist@^4.1.0, browserslist@^4.12.0, browserslist@^4.14.5, browserslist@^4.16.3:
1871-
version "4.16.4"
1872-
resolved "https://registry.yarnpkg.com/browserslist/-/browserslist-4.16.4.tgz#7ebf913487f40caf4637b892b268069951c35d58"
1873-
integrity sha512-d7rCxYV8I9kj41RH8UKYnvDYCRENUlHRgyXy/Rhr/1BaeLGfiCptEdFE8MIrvGfWbBFNjVYx76SQWvNX1j+/cQ==
1874-
dependencies:
1875-
caniuse-lite "^1.0.30001208"
1876-
colorette "^1.2.2"
1877-
electron-to-chromium "^1.3.712"
1878-
escalade "^3.1.1"
1879-
node-releases "^1.1.71"
1880-
1881-
browserslist@^4.16.0:
1870+
browserslist@^4.0.0, browserslist@^4.1.0, browserslist@^4.12.0, browserslist@^4.14.5, browserslist@^4.16.0, browserslist@^4.16.3, browserslist@^4.16.5:
18821871
version "4.16.6"
18831872
resolved "https://registry.yarnpkg.com/browserslist/-/browserslist-4.16.6.tgz#d7901277a5a88e554ed305b183ec9b0c08f66fa2"
18841873
integrity sha512-Wspk/PqO+4W9qp5iUTJsa1B/QrYn1keNCcEP5OvP7WBwT4KaDly0uONYmC6Xa3Z5IqnUgS0KcgLYu1l74x0ZXQ==
@@ -2030,7 +2019,7 @@ caniuse-api@^3.0.0:
20302019
lodash.memoize "^4.1.2"
20312020
lodash.uniq "^4.5.0"
20322021

2033-
caniuse-lite@^1.0.0, caniuse-lite@^1.0.30001109, caniuse-lite@^1.0.30001208:
2022+
caniuse-lite@^1.0.0, caniuse-lite@^1.0.30001109:
20342023
version "1.0.30001209"
20352024
resolved "https://registry.yarnpkg.com/caniuse-lite/-/caniuse-lite-1.0.30001209.tgz#1bb4be0bd118e98e21cfb7ef617b1ef2164622f4"
20362025
integrity sha512-2Ktt4OeRM7EM/JaOZjuLzPYAIqmbwQMNnYbgooT+icoRGrKOyAxA1xhlnotBD1KArRSPsuJp3TdYcZYrL7qNxA==
@@ -3028,11 +3017,6 @@ [email protected]:
30283017
resolved "https://registry.yarnpkg.com/ee-first/-/ee-first-1.1.1.tgz#590c61156b0ae2f4f0255732a158b266bc56b21d"
30293018
integrity sha1-WQxhFWsK4vTwJVcyoViyZrxWsh0=
30303019

3031-
electron-to-chromium@^1.3.712:
3032-
version "1.3.717"
3033-
resolved "https://registry.yarnpkg.com/electron-to-chromium/-/electron-to-chromium-1.3.717.tgz#78d4c857070755fb58ab64bcc173db1d51cbc25f"
3034-
integrity sha512-OfzVPIqD1MkJ7fX+yTl2nKyOE4FReeVfMCzzxQS+Kp43hZYwHwThlGP+EGIZRXJsxCM7dqo8Y65NOX/HP12iXQ==
3035-
30363020
electron-to-chromium@^1.3.723:
30373021
version "1.3.727"
30383022
resolved "https://registry.yarnpkg.com/electron-to-chromium/-/electron-to-chromium-1.3.727.tgz#857e310ca00f0b75da4e1db6ff0e073cc4a91ddf"

0 commit comments

Comments
 (0)