Skip to content

fix(docs): update SECURITY.md dependency scanning to OSV-Scanner - #147

Open
Kartikeya-trivedi wants to merge 1 commit into
kubeflow:mainfrom
Kartikeya-trivedi:fix/security-md-osv-scanner
Open

fix(docs): update SECURITY.md dependency scanning to OSV-Scanner#147
Kartikeya-trivedi wants to merge 1 commit into
kubeflow:mainfrom
Kartikeya-trivedi:fix/security-md-osv-scanner

Conversation

@Kartikeya-trivedi

Copy link
Copy Markdown
Contributor

Description

One-line docs fix: SECURITY.md (merged via #14) still says pip-audit runs in CI, but pip-audit was replaced by the nightly OSV-Scanner workflow in #30. This updates the Prevention Mechanisms line to describe the current setup — nightly scan of uv.lock, findings in the Security tab, automated fix PRs (e.g. #137).

Follow-up promised on the #30 review thread.

Type of Change

  • feat: New feature
  • fix: Bug fix
  • revert: Revert a change
  • chore: Maintenance / tooling

Checklist

  • Linting passes (make verify)
  • Documentation updated (if applicable)
  • Commit messages follow conventional format

Related Issues

Follow-up to #30 / #14

pip-audit was replaced by the nightly OSV-Scanner workflow in kubeflow#30; SECURITY.md merged via kubeflow#14 still described the old setup. Follow-up promised on the kubeflow#30 review thread.

Signed-off-by: Kartikeya Trivedi <kartikeyatrivedi4oct2004@gmail.com>
@google-oss-prow

Copy link
Copy Markdown
Contributor

[APPROVALNOTIFIER] This PR is NOT APPROVED

This pull-request has been approved by:
Once this PR has been reviewed and has the lgtm label, please assign kramaranya for approval. For more information see the Kubernetes Code Review Process.

The full list of commands accepted by this bot can be found here.

Details Needs approval from an approver in each of these files:

Approvers can indicate their approval by writing /approve in a comment
Approvers can cancel approval by writing /approve cancel in a comment

@github-actions

github-actions Bot commented Aug 5, 2026

Copy link
Copy Markdown
Contributor

🎉 Welcome to the Kubeflow MCP Server! 🎉

Thanks for opening your first PR! We're happy to have you as part of our community 🚀

Here's what happens next:

  • If you haven't already, please check out our Contributing Guide for repo-specific guidelines and the Kubeflow Contributor Guide for general community standards
  • Our team will review your PR soon! cc @kubeflow/kubeflow-sdk-team

Join the community:

Feel free to ask questions in the comments if you need any help or clarification!
Thanks again for contributing to Kubeflow! 🙏

@Krishna-kg732

Copy link
Copy Markdown
Member

/ok-to-test

@google-oss-prow google-oss-prow Bot added the ok-to-test Approve CI for external contributors label Aug 5, 2026
@Krishna-kg732

Copy link
Copy Markdown
Member

/lgtm
Thanks for working on this 🫡

@google-oss-prow google-oss-prow Bot added the lgtm Looks good to me — approved by a reviewer label Aug 6, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

lgtm Looks good to me — approved by a reviewer ok-to-test Approve CI for external contributors size/XS

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants