Skip to content

Commit f2d28e0

Browse files
committed
ci(security): pin trivy-action to v-prefixed tag
- Update aquasecurity/trivy-action from 0.35.0 to v0.35.0 to match the action's post-supply-chain-attack tag scheme
1 parent ccc738a commit f2d28e0

1 file changed

Lines changed: 2 additions & 2 deletions

File tree

.github/workflows/security.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -23,7 +23,7 @@ jobs:
2323
uses: actions/checkout@v6
2424

2525
- name: Run Trivy vulnerability scanner in repo mode
26-
uses: aquasecurity/trivy-action@0.35.0
26+
uses: aquasecurity/trivy-action@v0.35.0
2727
with:
2828
scan-type: "fs"
2929
scan-ref: "."
@@ -39,7 +39,7 @@ jobs:
3939
sarif_file: "trivy-results.sarif"
4040

4141
- name: Run Trivy vulnerability scanner (table output)
42-
uses: aquasecurity/trivy-action@0.35.0
42+
uses: aquasecurity/trivy-action@v0.35.0
4343
if: always()
4444
with:
4545
scan-type: "fs"

0 commit comments

Comments
 (0)