Skip to content

Merge v4-beta to v4 (2026-04-01)#156

Merged
mike-ainsel merged 5 commits intov4from
merge-2026-04-01
Apr 1, 2026
Merged

Merge v4-beta to v4 (2026-04-01)#156
mike-ainsel merged 5 commits intov4from
merge-2026-04-01

Conversation

@mike-ainsel
Copy link
Copy Markdown
Member

Merge v4-beta into v4

Pin trivy install script to download v0.69.3 (latest safe release)
instead of unpinned latest. v0.69.4 was compromised and removed.

See: https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise
Replace hardcoded/commented PL_DOCKER_REGISTRY_PUSH_TO env var with
a workflow input that defaults to quay.io/milaboratories/pl-containers.

Users can override the registry without touching the workflow files.
Set to empty string to disable pushing.
…nput

Add pl-docker-registry-push-to workflow input
@mike-ainsel mike-ainsel merged commit f8acca8 into v4 Apr 1, 2026
PaulNewling pushed a commit that referenced this pull request Apr 2, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants