Skip to content

Commit 415ca60

Browse files
committed
Pin Trivy to safe version
1 parent d812524 commit 415ca60

1 file changed

Lines changed: 4 additions & 4 deletions

File tree

.github/workflows/vulnerabilities.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -16,15 +16,15 @@ on:
1616
jobs:
1717

1818
vulnerabilities:
19-
runs-on: ubuntu-22.04
19+
runs-on: ubuntu-24.04
2020
defaults:
2121
run:
2222
working-directory: .
2323
steps:
2424
- name: Checkout pygeoapi
2525
uses: actions/checkout@master
2626
- name: Scan vulnerabilities with trivy
27-
uses: aquasecurity/trivy-action@master
27+
uses: aquasecurity/trivy-action@v0.35.0
2828
with:
2929
scan-type: fs
3030
exit-code: 1
@@ -36,7 +36,7 @@ jobs:
3636
run: |
3737
docker buildx build -t ${{ github.repository }}:${{ github.sha }} --platform linux/amd64 --no-cache -f Dockerfile .
3838
- name: Scan locally built Docker image for vulnerabilities with trivy
39-
uses: aquasecurity/trivy-action@master
39+
uses: aquasecurity/trivy-action@v0.35.0
4040
env:
4141
TRIVY_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-db:2
4242
TRIVY_JAVA_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-java-db:1
@@ -46,4 +46,4 @@ jobs:
4646
ignore-unfixed: true
4747
severity: CRITICAL,HIGH
4848
vuln-type: os,library
49-
image-ref: '${{ github.repository }}:${{ github.sha }}'
49+
image-ref: '${{ github.repository }}:${{ github.sha }}'

0 commit comments

Comments
 (0)