2323
2424 steps :
2525 - name : Checkout repository
26- uses : actions/checkout@8e8c483db84b4bee98b60c0593521ed34d9990e8 # v6
26+ uses : actions/checkout@de0fac2e4500dabe0009e67214ff5f5447ce83dd # v6
2727
2828 - name : Run Trivy vulnerability scanner on source code
2929 uses : aquasecurity/trivy-action@master
@@ -35,12 +35,12 @@ jobs:
3535 severity : " CRITICAL"
3636
3737 - name : Upload Trivy scan results to GitHub Security tab
38- uses : github/codeql-action/upload-sarif@b20883b0cd1f46c72ae0ba6d1090936928f9fa30 # v4
38+ uses : github/codeql-action/upload-sarif@0d579ffd059c29b07949a3cce3983f0780820c98 # v4
3939 with :
4040 sarif_file : " trivy-results.sarif"
4141
4242 - name : Log in to the Container registry
43- uses : docker/login-action@5e57cd118135c172c3672efd75eb46360885c0ef # v3
43+ uses : docker/login-action@c94ce9fb468520275223c153574b00df6fe4bcc9 # v3
4444 with :
4545 registry : ${{ env.REGISTRY }}
4646 username : ${{ github.actor }}
5353 images : ${{ env.REGISTRY }}/${{ env.IMAGE_NAME }}
5454
5555 - name : Build and push Docker image
56- uses : docker/build-push-action@263435318d21b8e681c14492fe198d362a7d2c83 # v6
56+ uses : docker/build-push-action@10e90e3645eae34f1e60eeb005ba3a3d33f178e8 # v6
5757 id : build
5858 with :
5959 context : .
6969 output : " trivy-image-results.sarif"
7070
7171 - name : Upload Trivy scan results to GitHub Security tab
72- uses : github/codeql-action/upload-sarif@b20883b0cd1f46c72ae0ba6d1090936928f9fa30 # v4
72+ uses : github/codeql-action/upload-sarif@0d579ffd059c29b07949a3cce3983f0780820c98 # v4
7373 with :
7474 sarif_file : " trivy-image-results.sarif"
7575 category : " Trivy Container Scanning"
0 commit comments