Skip to content

Conversation

@ezhang6811
Copy link

Issue #, if available:

Description of changes:
Add daily-scan.yml to detect security vulnerabilities in current source code.

Note that the Java SDK artifacts do not contain pom.properties or MANIFEST.MF metadata that Trivy can meaningfully scan, so we only run a dependency scan.

Example run: https://github.com/aws/aws-xray-sdk-java/actions/runs/20930932251/job/60141350349

By submitting this pull request, I confirm that my contribution is made under the terms of the Apache 2.0 license.

@ezhang6811 ezhang6811 requested a review from a team as a code owner January 12, 2026 18:47
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant