Hi there! Two months ago we changed Pinot GitHub Actions to add a new action that uses trivy to analyze the Pinot docker image looking for vulnerabilities (
PR). This check is evaluated on all PRs, but it may have false positives in the sense that it may consider that a PR has vulnerabilities even when the included code doesn't have them. For example, let's say that a new vulnerability is discovered in one of our dependencies. Given that the job in master wasn't executed, trivy may consider that it is clean, but once a new PR is created, the pipeline is fired and the new vulnerability is detected.
When this job really matters is when the PR adds a new dependency or change the version used by some dependency. In that case, if the PR adds a known vulnerability, it will be detected. I know it is not ideal to have false positives in tests, but AFAIK there is no better way to detect this vulnerabilities. The other alternative is periodically check our docker images in master, but in my experience that is problematic. At the end of the day people just forget to check the reports and the vulnerability stays there until some user complains about that, which is very bad news.