Skip to content

Conversation

@SgtCoDFish
Copy link
Member

@SgtCoDFish SgtCoDFish commented Dec 18, 2025

Summary

Improves Trivy security scanning frequency and TestGrid reporting for cert-manager container images.

  • Increases scan frequency: Trivy tests now run every 12 hours (previously 24 hours) for faster vulnerability detection
  • Improves alerting: Reduces stale results threshold from 36 to 18 hours to match the new scan frequency (and makes this more linked to the actual periodicity of the job)
  • Better test status reporting: Configures TestGrid to show binary pass/fail status instead of "flaky" for Trivy scans

Motivation

Security vulnerability scans should run frequently to detect issues quickly. By doubling the scan frequency and adjusting TestGrid settings appropriately, this ensures the team is notified sooner when vulnerabilities are discovered in cert-manager container images.

Also, the "FLAKY" status wasn't helpful for these tests - we really only care about the latest scan and whether it passed or failed.

See https://github.com/kubernetes/test-infra/blob/737791c6e2ee79bdc8efce2195eb6d20ebb6eb04/testgrid/config.md#prow-job-configuration for details on the testgrid annotations.

Testing

I haven't tested that these testgrid annotations from the linked doc actually work - I think it's easier to merge the PR and check if it did what we expect. I'm confident that this change won't be negative, at least!

Signed-off-by: Ashley Davis <ashley.davis@cyberark.com>
@cert-manager-prow cert-manager-prow bot added the dco-signoff: yes Indicates that all commits in the pull request have the valid DCO sign-off message. label Dec 18, 2025
@cert-manager-prow
Copy link
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign maelvls for approval. For more information see the Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@cert-manager-prow cert-manager-prow bot added the size/M Denotes a PR that changes 30-99 lines, ignoring generated files. label Dec 18, 2025
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dco-signoff: yes Indicates that all commits in the pull request have the valid DCO sign-off message. size/M Denotes a PR that changes 30-99 lines, ignoring generated files.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant