Skip to content

deps(actions): bump aquasecurity/trivy-action from e368e328979b113139d6f9068e03accaed98a518 to 1994662b5555670344cd84d29ed3cad4bd26f31c#425

Closed
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/github_actions/aquasecurity/trivy-action-1994662b5555670344cd84d29ed3cad4bd26f31c
Closed

deps(actions): bump aquasecurity/trivy-action from e368e328979b113139d6f9068e03accaed98a518 to 1994662b5555670344cd84d29ed3cad4bd26f31c#425
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/github_actions/aquasecurity/trivy-action-1994662b5555670344cd84d29ed3cad4bd26f31c

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 15, 2026

Bumps aquasecurity/trivy-action from e368e328979b113139d6f9068e03accaed98a518 to 1994662b5555670344cd84d29ed3cad4bd26f31c.

Commits
  • 1994662 chore(deps): bump the actions group with 5 updates (#558)
  • 6b36659 chore: add zizmor config (#557)
  • 316aa5a ci: add dependabot config (#556)
  • 264c9c5 test: use pinned digests for trivy-db, trivy-java-db and trivy-checks (#555)
  • aeb1396 ci: replace peter-evans/create-pull-request with gh CLI (#550)
  • f685ba7 ci: use action.yaml as single source of truth for Trivy version (#552)
  • 34f2b23 chore(ci): update bump-trivy workflow (#546)
  • 57a97c7 chore(deps): Update trivy to v0.69.3 (#519)
  • 97e0b38 chore: bump Trivy version to v0.69.2 in test workflow and README (#515)
  • 4c61e63 chore: bump default Trivy version to v0.69.2 (#513)
  • Additional commits viewable in compare view

@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 15, 2026

Labels

The following labels could not be found: dependencies, github-actions, security. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Apr 15, 2026

Dependency Review

✅ No vulnerabilities or license issues or OpenSSF Scorecard issues found.

OpenSSF Scorecard

PackageVersionScoreDetails
actions/aquasecurity/trivy-action 1994662b5555670344cd84d29ed3cad4bd26f31c 🟢 6.7
Details
CheckScoreReason
Code-Review🟢 9Found 15/16 approved changesets -- score normalized to 9
Maintained🟢 1014 commit(s) and 2 issue activity found in the last 90 days -- score normalized to 10
Binary-Artifacts🟢 10no binaries found in the repo
Packaging⚠️ -1packaging workflow not detected
Dangerous-Workflow🟢 10no dangerous workflow patterns detected
Token-Permissions🟢 7detected GitHub workflow tokens with excessive permissions
Pinned-Dependencies🟢 8dependency not pinned by hash detected -- score normalized to 8
CII-Best-Practices⚠️ 0no effort to earn an OpenSSF best practices badge detected
Fuzzing⚠️ 0project is not fuzzed
License🟢 10license file detected
Signed-Releases⚠️ -1no releases found
Branch-Protection⚠️ -1internal error: error during branchesHandler.setup: internal error: some github tokens can't read classic branch protection rules: https://github.com/ossf/scorecard-action/blob/main/docs/authentication/fine-grained-auth-token.md
Security-Policy⚠️ 0security policy file not detected
SAST⚠️ 0SAST tool is not run on all commits -- score normalized to 0

Scanned Files

  • .github/workflows/secure-go.yml

Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) from e368e328979b113139d6f9068e03accaed98a518 to 1994662b5555670344cd84d29ed3cad4bd26f31c.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](aquasecurity/trivy-action@e368e32...1994662)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-version: 1994662b5555670344cd84d29ed3cad4bd26f31c
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/github_actions/aquasecurity/trivy-action-1994662b5555670344cd84d29ed3cad4bd26f31c branch from 4daac07 to b76b600 Compare April 16, 2026 17:07
@itcmsgr
Copy link
Copy Markdown
Owner

itcmsgr commented Apr 16, 2026

Closing — will re-evaluate dependencies in v1.92

@itcmsgr itcmsgr closed this Apr 16, 2026
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github Apr 16, 2026

OK, I won't notify you again about this release, but will get in touch when a new version is available. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot Bot deleted the dependabot/github_actions/aquasecurity/trivy-action-1994662b5555670344cd84d29ed3cad4bd26f31c branch April 16, 2026 18:56
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant