@@ -30,10 +30,10 @@ jobs:
3030 runs-on : ubuntu-22.04
3131 steps :
3232 - name : Checkout
33- uses : actions/checkout@v4
33+ uses : actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4
3434
3535 - name : Run Trivy in config mode for deployments
36- uses : aquasecurity/trivy-action@master
36+ uses : aquasecurity/trivy-action@b2933f565dbc598b29947660e66259e3c7bc8561 # 0.20.0
3737 with :
3838 scan-type : config
3939 scan-ref : deployments/
@@ -49,10 +49,10 @@ jobs:
4949 runs-on : ubuntu-22.04
5050 steps :
5151 - name : Checkout
52- uses : actions/checkout@v4
52+ uses : actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4
5353
5454 - name : Run Trivy in config mode for dockerfiles
55- uses : aquasecurity/trivy-action@master
55+ uses : aquasecurity/trivy-action@b2933f565dbc598b29947660e66259e3c7bc8561 # 0.20.0
5656 with :
5757 scan-type : config
5858 scan-ref : build/docker/
@@ -64,10 +64,10 @@ jobs:
6464 name : Scan licenses
6565 steps :
6666 - name : Checkout
67- uses : actions/checkout@v4
67+ uses : actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4
6868
6969 - name : Run Trivy in fs mode
70- uses : aquasecurity/trivy-action@master
70+ uses : aquasecurity/trivy-action@b2933f565dbc598b29947660e66259e3c7bc8561 # 0.20.0
7171 with :
7272 scan-type : fs
7373 scan-ref : .
@@ -83,11 +83,11 @@ jobs:
8383 name : Scan vulnerabilities
8484 steps :
8585 - name : Checkout
86- uses : actions/checkout@v4
86+ uses : actions/checkout@a5ac7e51b41094c92402da3b24376905380afc29 # v4
8787
8888 - name : Run Trivy in fs mode
8989 continue-on-error : true
90- uses : aquasecurity/trivy-action@master
90+ uses : aquasecurity/trivy-action@b2933f565dbc598b29947660e66259e3c7bc8561 # 0.20.0
9191 with :
9292 scan-type : fs
9393 scan-ref : .
9797 output : trivy-report.json
9898
9999 - name : Show report in human-readable format
100- uses : aquasecurity/trivy-action@master
100+ uses : aquasecurity/trivy-action@b2933f565dbc598b29947660e66259e3c7bc8561 # 0.20.0
101101 with :
102102 scan-type : convert
103103 vuln-type : ' '
@@ -107,7 +107,7 @@ jobs:
107107
108108 - name : Convert report to sarif
109109 if : ${{ inputs.upload-to-github-security-tab }}
110- uses : aquasecurity/trivy-action@master
110+ uses : aquasecurity/trivy-action@b2933f565dbc598b29947660e66259e3c7bc8561 # 0.20.0
111111 with :
112112 scan-type : convert
113113 vuln-type : ' '
@@ -118,13 +118,13 @@ jobs:
118118
119119 - name : Upload sarif report to GitHub Security tab
120120 if : ${{ inputs.upload-to-github-security-tab }}
121- uses : github/codeql-action/upload-sarif@v3
121+ uses : github/codeql-action/upload-sarif@187e591bef188a41dd329c95d7905134173654ae # v3
122122 with :
123123 sarif_file : trivy-report.sarif
124124
125125 - name : Convert report to csv
126126 if : ${{ inputs.export-csv }}
127- uses : aquasecurity/trivy-action@master
127+ uses : aquasecurity/trivy-action@b2933f565dbc598b29947660e66259e3c7bc8561 # 0.20.0
128128 with :
129129 scan-type : convert
130130 vuln-type : ' '
@@ -136,7 +136,7 @@ jobs:
136136
137137 - name : Upload CSV report as an artifact
138138 if : ${{ inputs.export-csv }}
139- uses : actions/upload-artifact@v4
139+ uses : actions/upload-artifact@65462800fd760344b1a7b4382951275a0abb4808 # v4
140140 with :
141141 name : trivy-report
142142 path : trivy-report.csv
0 commit comments