Files
alangou 3693b32841 ci(trivy): add artifact and PR configuration scans (#3185)
* ci(trivy): add artifact and PR configuration scans

Signed-off-by: Adrien Langou <alangou@nvidia.com>

* fix(ci): harden Trivy gate detection and finding diff

Signed-off-by: Adrien Langou <alangou@nvidia.com>

* feat(ci): scan released artifacts in release pipelines

Signed-off-by: Adrien Langou <alangou@nvidia.com>

* fix(ci): harden and simplify Trivy scans

Signed-off-by: Adrien Langou <alangou@nvidia.com>

* fix(ci): consolidate Trivy reports and prevent collisions

Signed-off-by: Adrien Langou <alangou@nvidia.com>

---------

Signed-off-by: Adrien Langou <alangou@nvidia.com>
2026-09-09 13:58:06 +00:00

242 lines
3.7 KiB
Plaintext

# =============================================================================
# Rust
# =============================================================================
# Build output
/target/
e2e/rust/target/
target/
debug/
release/
# Cargo lock for libraries (keep for binaries/workspace)
# Cargo.lock # We keep this since this is a binary/workspace project
# Generated code
*.rs.bk
# Profiling
*.profraw
*.profdata
# =============================================================================
# Python
# =============================================================================
# Byte-compiled / optimized / DLL files
__pycache__/
*.py[cod]
*$py.class
# C extensions
*.so
# Distribution / packaging
.Python
develop-eggs/
dist/
downloads/
eggs/
.eggs/
lib/
lib64/
parts/
sdist/
var/
wheels/
share/python-wheels/
*.egg-info/
.installed.cfg
*.egg
MANIFEST
python/*.data
# Virtual environments
.venv/
venv/
ENV/
env/
# .python-version is tracked — pins uv to match the sandbox base image Python
# Installer logs
pip-log.txt
pip-delete-this-directory.txt
# Unit test / coverage reports
coverage.out
coverage/
htmlcov/
# Trivy scan reports (tasks/scripts/trivy-scan-*.sh)
/reports/
.tox/
.nox/
.coverage
.coverage.*
.cache
nosetests.xml
coverage.xml
*.cover
*.py,cover
.hypothesis/
.pytest_cache/
pytestdebug.log
# Translations
*.mo
*.pot
# mypy
.mypy_cache/
.dmypy.json
dmypy.json
# Ruff
.ruff_cache/
# Type stubs
.pytype/
# Cython debug symbols
cython_debug/
# Generated Python protobuf stubs (keep package marker)
python/openshell/_proto/*
!python/openshell/_proto/__init__.py
# =============================================================================
# IDE / Editor
# =============================================================================
# VSCode
.vscode/
!.vscode/settings.json
!.vscode/tasks.json
!.vscode/launch.json
!.vscode/extensions.json
# JetBrains
.idea/
*.iml
*.ipr
*.iws
out/
# Vim
*.swp
*.swo
*~
# Emacs
*~
\#*\#
/.emacs.desktop
/.emacs.desktop.lock
*.elc
auto-save-list
tramp
.\#*
# =============================================================================
# Agent tooling
# =============================================================================
# Local agent state and configuration
.codex/
.pi/
.claude/settings.local.json
.claude/worktrees/
# =============================================================================
# OS
# =============================================================================
# macOS
.DS_Store
.AppleDouble
.LSOverride
._*
# Windows
Thumbs.db
ehthumbs.db
Desktop.ini
# Linux
*~
# =============================================================================
# Project-specific
# =============================================================================
# Local configuration
*.local
.env
.env.*
!.env.example
# Logs
*.log
logs/
# Temporary files
tmp/
temp/
*.tmp
e2e/gpu/images/.build/
# Secrets/credentials (should never be committed)
*.pem
*.key
*.crt
secrets/
credentials/
kubeconfig
# Documentation build output
_build/
# Gateway microVM rootfs build artifacts
rootfs/
# Docker build artifacts (image tarballs, packaged helm charts)
deploy/docker/.build/
# Helm subchart tarballs (regenerated by `helm dependency build`)
deploy/helm/openshell/charts/
# SBOM generated output (JSON, CSV) — release artifacts, not committed
deploy/sbom/output/
# Debian package build output (default OPENSHELL_OUTPUT_DIR for tasks/scripts/package-deb.sh)
artifacts/
# Local mise settings
mise.local.toml
# Ignore plans for now
architecture/plans
rfc.md
.worktrees
.z3-trace
# RPM build artifacts
*.src.rpm
*.tar.gz
*.tar.xz
*.tar.bz2
# Snap build artifacts
*.snap
*.comp
# Markdown/mermaid lint tooling deps
scripts/lint-mermaid/node_modules/
# Nix
/result
/result-*