Skip to content

Commit c769fca

Browse files
author
Aisura
committed
ci: re-enable trivy vulnerability scanning with SHA-pinned action
1 parent ef000bf commit c769fca

1 file changed

Lines changed: 4 additions & 4 deletions

File tree

.github/workflows/ndc-python-lambda-connector.yaml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -102,7 +102,7 @@ jobs:
102102
tags: ${{ env.DOCKER_REGISTRY }}/${{ env.DOCKER_IMAGE_NAME }}:${{ github.sha }}
103103

104104
- name: Run Trivy vulnerability scanner (json output)
105-
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1
105+
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
106106
with:
107107
image-ref: ${{ env.DOCKER_REGISTRY }}/${{ env.DOCKER_IMAGE_NAME }}:${{ github.sha }}
108108
format: json
@@ -124,7 +124,7 @@ jobs:
124124
team=engine
125125
126126
- name: Fail build on High/Critical Vulnerabilities
127-
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1
127+
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
128128
with:
129129
skip-setup-trivy: true
130130
image-ref: ${{ env.DOCKER_REGISTRY }}/${{ env.DOCKER_IMAGE_NAME }}:${{ github.sha }}
@@ -177,7 +177,7 @@ jobs:
177177
echo "image_tag=$IMAGE_TAG" >> $GITHUB_OUTPUT
178178
179179
- name: Run Trivy vulnerability scanner (json output)
180-
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1
180+
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
181181
with:
182182
image-ref: ${{ steps.get-image-tag.outputs.image_tag }}
183183
format: json
@@ -199,7 +199,7 @@ jobs:
199199
team=engine
200200
201201
- name: Fail build on High/Critical Vulnerabilities
202-
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1
202+
uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0
203203
with:
204204
skip-setup-trivy: true
205205
image-ref: ${{ steps.get-image-tag.outputs.image_tag }}

0 commit comments

Comments
 (0)