Skip to content

Commit d117ea5

Browse files
authored
Pin trivy-action to SHA instead of mutable @master (#689)
2 parents f92a07a + 752f836 commit d117ea5

2 files changed

Lines changed: 4 additions & 4 deletions

File tree

.github/workflows/build-reusable.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -100,7 +100,7 @@ jobs:
100100
MATTERMOST_USERNAME: ${{ github.triggering_actor }}
101101

102102
- name: Run Trivy vulnerability scanner sarif
103-
uses: aquasecurity/trivy-action@master
103+
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1
104104
with:
105105
image-ref: ${{ fromJSON(steps.meta.outputs.json).tags[0] }}
106106
scan-type: image
@@ -117,7 +117,7 @@ jobs:
117117
sarif_file: "trivy-results.sarif"
118118

119119
- name: Run Trivy SBOM
120-
uses: aquasecurity/trivy-action@master
120+
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1
121121
with:
122122
image-ref: ${{ fromJSON(steps.meta.outputs.json).tags[0] }}
123123
scan-type: image
@@ -130,7 +130,7 @@ jobs:
130130
TRIVY_PASSWORD: ${{ secrets.GITHUB_TOKEN }}
131131

132132
- name: Run Trivy license scanner
133-
uses: aquasecurity/trivy-action@master
133+
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1
134134
with:
135135
image-ref: ${{ fromJSON(steps.meta.outputs.json).tags[0] }}
136136
scan-type: image

.github/workflows/ci.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -70,7 +70,7 @@ jobs:
7070
run: poetry run liccheck -s pyproject.toml
7171

7272
- name: Run Trivy vulnerability scanner
73-
uses: aquasecurity/trivy-action@master
73+
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1
7474
with:
7575
trivy-config: trivy.yaml
7676
scan-type: fs

0 commit comments

Comments
 (0)