From 11cbf05ed7fb40de9647be1927e8745b62b81b6b Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 24 Mar 2026 17:58:28 +0000 Subject: [PATCH] Bump aquasecurity/trivy-action Bumps the github_actions group with 1 update in the /.github/workflows directory: [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action). Updates `aquasecurity/trivy-action` from 0.28.0 to 0.35.0 - [Release notes](https://github.com/aquasecurity/trivy-action/releases) - [Commits](https://github.com/aquasecurity/trivy-action/compare/0.28.0...0.35.0) --- updated-dependencies: - dependency-name: aquasecurity/trivy-action dependency-version: 0.35.0 dependency-type: direct:production dependency-group: github_actions ... Signed-off-by: dependabot[bot] --- .github/workflows/code-review.yml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/code-review.yml b/.github/workflows/code-review.yml index 1264fe68..b4aa46f7 100644 --- a/.github/workflows/code-review.yml +++ b/.github/workflows/code-review.yml @@ -228,7 +228,7 @@ jobs: docker build -t goodone-app:${{ github.sha }} -f deploy/dev/Dockerfile . - name: Run Trivy vulnerability scanner (Image) - uses: aquasecurity/trivy-action@0.28.0 + uses: aquasecurity/trivy-action@0.35.0 with: image-ref: 'goodone-app:${{ github.sha }}' format: 'table' @@ -239,7 +239,7 @@ jobs: version: 'latest' - name: Generate Trivy SARIF (Image) - uses: aquasecurity/trivy-action@0.28.0 + uses: aquasecurity/trivy-action@0.35.0 with: image-ref: 'goodone-app:${{ github.sha }}' format: 'sarif' @@ -258,7 +258,7 @@ jobs: continue-on-error: true - name: Run Trivy misconfiguration scanner (Dockerfile) - uses: aquasecurity/trivy-action@0.28.0 + uses: aquasecurity/trivy-action@0.35.0 with: scan-type: 'config' scan-ref: 'deploy/dev/Dockerfile' @@ -270,7 +270,7 @@ jobs: version: 'latest' - name: Generate Trivy SARIF (Config) - uses: aquasecurity/trivy-action@0.28.0 + uses: aquasecurity/trivy-action@0.35.0 with: scan-type: 'config' scan-ref: 'deploy/dev/Dockerfile'