Tags: opsta/.github
Tags
feat: review-gate reusable workflow (production, @v1) (#7) The portable domain-expert review-gate reusable, synced from the source of truth opsta-ai-pe review/ci/review-gate.reusable.yaml. Live-validated on a real PR (pulled the internal review-gate image, ran under DeepSeek, posted an advisory BLOCK). packages:read + guarded ghcr-login so private/internal images pull. Co-authored-by: Jirayut Nimsaeng <wingth@gmail.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
feat: review-gate reusable workflow (production, @v1) (#7) The portable domain-expert review-gate reusable, synced from the source of truth opsta-ai-pe review/ci/review-gate.reusable.yaml. Live-validated on a real PR (pulled the internal review-gate image, ran under DeepSeek, posted an advisory BLOCK). packages:read + guarded ghcr-login so private/internal images pull. Co-authored-by: Jirayut Nimsaeng <wingth@gmail.com> Co-authored-by: Claude Opus 4.8 <noreply@anthropic.com>
fix(security-trivy): auth image scans to self-hosted Zot + force remo… …te image source image-scan on a dockerless ARC runner failed: trivy image tried the docker daemon (no /var/run/docker.sock), and the authenticated Zot (htpasswd) broke trivy's anonymous remote fallback. Add TRIVY_USERNAME/PASSWORD from the inherited REGISTRY_* secrets (empty on AR → WI keychain) + --image-src remote so trivy pulls from the registry directly. Backward-compatible with AR/GKE. Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
PreviousNext