ci: add blocking Trivy scans for runtime images

Closes #757 (closed)

Uses the shared digest-pinned Trivy template from infra!60.

Adds blocking fixable HIGH/CRITICAL scans for DBLab Server, CI Checker, RDS Refresh, CLI, and CE UI images built in MR and default-branch pipelines. Every scan targets the image tag emitted by its own pipeline and retains JSON evidence for 90 days.

The existing weekly advisory scan remains for broad recurring visibility.

Edited by Maya P

Merge request reports

Loading
Loading