Retire Prowler image + IaC scans (keep K8s CIS only) #372
Loading…
Add table
Add a link
Reference in a new issue
No description provided.
Delete branch "retire-prowler-image-iac-scans"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
Why
Weekly compliance review (2026-06-07) surfaced the toil problem head-on:
The image and IaC scans generate tens of thousands of un-actioned, un-muted findings every week:
The K8s CIS scan is the only one with realized value (fully mutelisted, 0 unmuted WoW) and is retained. Matches the broader scaling-back of the reporting system as minikube heads toward retirement.
Changes
cronjob-image-scan.yamlandcronjob-iac-scan.yaml+ remove from kustomizationmutelist/trivyignore.yaml(only the IaC scan consumed it)review-compliance-reports: drop the two retired scans (and the grouped-findings rendering that existed solely for them)Deploy (after review)
🤖 Generated with Claude Code