Repository navigation
Conversation
- Pin the patched Lambda runtime image - Update vulnerable example dependencies and Go setup - Keep deployment jobs on the default branch
- Keep omitted list inputs empty after the runtime upgrade
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Pin the patched upstream Lambda image by immutable digest and update vulnerable example Go dependencies. Align the example CI and README with Go 1.26, and restrict live deployments to master.
Related issues
N/A — repository-wide Trivy audit requested; no issue identifiers supplied.
AI authorship
entrypoint.sh,.github/workflows/ci.yml,Dockerfile,README.md,example/go.mod,example/go.sumChange classification
Core: action runtime changes affect consuming workflows; request two reviewers including the owner.
Plan reference
Restore the existing Trivy gate, preserve action inputs/entrypoint behavior, and verify before committing. Do not lower vulnerability severities or ignore CVEs.
Compatibility and scan-policy verification
Network-disabled amd64 debug parsing confirms empty layers/architectures become empty lists and six explicit list values remain intact. No AWS operations performed.
Verification
Checkout
fix/trivy-security-scanat2784329de6b7edce3d672d8248b3a17c3cd5b307and run fromlambda-action/. Prerequisites: Trivy 0.69.3 with the current vulnerability DB, Docker with linux/amd64 support, Go 1.26+, actionlint for modified workflows. Local commands were wrapped with rtk; Docker ran in Colima. No service credentials needed.trivy fs --scanners vuln,secret --severity CRITICAL,HIGH --exit-code 1 .git diff --check master...HEADdocker build --platform linux/amd64 -t lambda-action:trivy-fix .trivy image --scanners vuln --severity CRITICAL --exit-code 1 lambda-action:trivy-fixdocker run --rm --platform linux/amd64 --entrypoint /bin/drone-lambda lambda-action:trivy-fix --helpcd example && go test ./...actionlint .github/workflows/ci.ymlBehavioral scenario
Run the filesystem scan above; expect exit 0. Build and scan the image with the commands above; expect exit 0 and zero CRITICAL vulnerabilities. Run CLI help without credentials; expect usage output without contacting a service.
Execution status: Passed locally. GitHub PR checks will independently run after creation; no hosted result is claimed here. Live notification/deployment checks were not run because they affect external services.
Cleanup:
docker image rm lambda-action:trivy-fixremoves the test image.Security check
No credentials in the diff. Existing scan severities remain intact. No vulnerability exceptions added.
Risk and rollback
Upstream runtime/dependency upgrades may affect service integration; review compatibility before merging. Revert this commit to restore the previous image and configuration.
Reviewer guide
Review
.github/workflows/ci.yml,Dockerfile,README.md,example/go.mod,example/go.sum. Confirm the Trivy PR jobs finish successfully and review any remaining HIGH findings in uploaded SARIF. Service integration requires owner review in a disposable environment.Hosted verification
Trivy Security Scan passed at
2784329de6b7edce3d672d8248b3a17c3cd5b307: https://github.com/appleboy/lambda-action/actions/runs/37485829797