Skip to content

Commit 6da9d16

Browse files
committed
use hashes for actions for trivvy workflow
Signed-off-by: Humair Khan <HumairAK@users.noreply.github.com>
1 parent d01d170 commit 6da9d16

File tree

1 file changed

+4
-4
lines changed

1 file changed

+4
-4
lines changed

.github/workflows/trivy.yml

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -18,12 +18,12 @@ jobs:
1818
runs-on: ubuntu-24.04
1919
steps:
2020
- name: Checkout code
21-
uses: actions/checkout@v4
21+
uses: actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
2222

2323
- name: Run Trivy vulnerability scanner in repo mode
2424
id: trivy-skip-db
2525
continue-on-error: true
26-
uses: aquasecurity/trivy-action@0.35.0
26+
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # 0.35.0
2727
with:
2828
scan-type: 'fs'
2929
ignore-unfixed: true
@@ -40,7 +40,7 @@ jobs:
4040

4141
- name: Run Trivy vulnerability scanner (with DB download)
4242
if: steps.trivy-skip-db.outcome == 'failure'
43-
uses: aquasecurity/trivy-action@0.35.0
43+
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # 0.35.0
4444
with:
4545
scan-type: 'fs'
4646
ignore-unfixed: true
@@ -53,6 +53,6 @@ jobs:
5353
TRIVY_JAVA_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-java-db:1
5454

5555
- name: Upload Trivy scan results to GitHub Security tab
56-
uses: github/codeql-action/upload-sarif@v4
56+
uses: github/codeql-action/upload-sarif@256d634097be96e792d6764f9edaefc4320557b1 # v4
5757
with:
5858
sarif_file: 'trivy-results.sarif'

0 commit comments

Comments
 (0)