Skip to content

Commit 6f74dc8

Browse files
authored
Merge pull request #1806 from NASA-AMMOS/patch/pin-trivy-action-version
Pin trivy-action to save 0.24.0 in response to security compromise
2 parents 7be7bf0 + 8448f0b commit 6f74dc8

1 file changed

Lines changed: 2 additions & 1 deletion

File tree

.github/workflows/publish.yml

Lines changed: 2 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -158,7 +158,8 @@ jobs:
158158
- uses: actions/checkout@v4
159159

160160
- name: Scan ${{ matrix.image }} for vulnerabilities
161-
uses: aquasecurity/trivy-action@0.24.0
161+
# pinned to commit for release https://github.com/aquasecurity/trivy-action/releases/tag/v0.24.0
162+
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8
162163
env:
163164
TRIVY_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-db
164165
TRIVY_JAVA_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-java-db

0 commit comments

Comments
 (0)