Skip to content

fix: pin trivy docker/action refs to safe versions (CVE-2026-33634)#6

Merged
indradhanush merged 1 commit intomainfrom
fix/pin-trivy-cve-2026-33634
Apr 14, 2026
Merged

fix: pin trivy docker/action refs to safe versions (CVE-2026-33634)#6
indradhanush merged 1 commit intomainfrom
fix/pin-trivy-cve-2026-33634

Conversation

@indradhanush
Copy link
Copy Markdown

Summary

Pins unsafe trivy references to safe versions to address CVE-2026-33634.

Changes:

  • aquasec/trivy:<mutable-tag>aquasec/trivy:0.69.3
  • aquasecurity/trivy-action@<mutable-ref>trivy-action@v0.35.0
  • aquasecurity/setup-trivy@<mutable-ref>setup-trivy@v0.2.6

References

🤖 Generated with Claude Code

Unsafe trivy references fixed:
- aquasec/trivy:<mutable-tag> → aquasec/trivy:0.69.3
- aquasecurity/trivy-action@<mutable-ref> → trivy-action@v0.35.0
- aquasecurity/setup-trivy@<mutable-ref> → setup-trivy@v0.2.6

Mutable tags/refs allow supply chain attacks via CVE-2026-33634.
@indradhanush indradhanush merged commit 4fc7fe3 into main Apr 14, 2026
10 of 11 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants