Skip to content

Commit 07b295d

Browse files
author
Aisura
committed
ci: re-enable trivy vulnerability scanning with SHA-pinned action
1 parent d5464e2 commit 07b295d

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

.github/workflows/ndc-nodejs-lambda-connector.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -129,7 +129,7 @@ jobs:
129129
tags: ${{ env.DOCKER_REGISTRY }}/${{ env.DOCKER_IMAGE_NAME }}:scan
130130

131131
- name: Run Trivy vulnerability scanner (json output)
132-
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1
132+
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
133133
with:
134134
image-ref: ${{ env.DOCKER_REGISTRY }}/${{ env.DOCKER_IMAGE_NAME }}:scan
135135
format: json
@@ -152,7 +152,7 @@ jobs:
152152
team=engine
153153
154154
- name: Fail build on High/Critical Vulnerabilities
155-
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1
155+
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
156156
with:
157157
skip-setup-trivy: true
158158
image-ref: ${{ env.DOCKER_REGISTRY }}/${{ env.DOCKER_IMAGE_NAME }}:scan

0 commit comments

Comments
 (0)