Skip to content

Commit e46ffd7

Browse files
Priyankasaggu11929k8s-infra-cherrypick-robot
authored andcommitted
security: Update trivy-action to v0.35.0
Updates aquasecurity/trivy-action from mutable references to SHA-pinned version to address security vulnerabilities. - Updates to v0.35.0 (57a97c7e) - Pins to specific SHA for immutability - Addresses issue: aquasecurity/trivy#10425 Signed-off-by: Priyanka Saggu <priyankasaggu11929@gmail.com>
1 parent 7e6ab30 commit e46ffd7

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

.github/workflows/trivy.yaml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -27,7 +27,7 @@ jobs:
2727
make container
2828
2929
- name: Run Trivy vulnerability scanner
30-
uses: aquasecurity/trivy-action@master
30+
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0.35.0
3131
env:
3232
TRIVY_DB_REPOSITORY: "public.ecr.aws/aquasecurity/trivy-db:2"
3333
with:

0 commit comments

Comments
 (0)