Skip to content

fix: update trivy-action from @master to @v0.35.0#319

Open
andreinovik-regula wants to merge 1 commit intomasterfrom
54074-fix-trivy-vulnerability
Open

fix: update trivy-action from @master to @v0.35.0#319
andreinovik-regula wants to merge 1 commit intomasterfrom
54074-fix-trivy-vulnerability

Conversation

@andreinovik-regula
Copy link
Copy Markdown

Summary

Pin aquasecurity/trivy-action from the floating @master tag to the stable @v0.35.0 release.

Changes

  • .github/workflows/trivy-scan.yaml: aquasecurity/trivy-action@masteraquasecurity/trivy-action@v0.35.0

Motivation

Using @master means the action can change at any time without notice, potentially breaking CI or introducing unexpected behavior. Pinning to a specific version ensures reproducible and predictable builds.

Ticket

https://redmine.regulaforensics.com/issues/54074

@andreinovik-regula andreinovik-regula requested a review from a team as a code owner April 7, 2026 11:32
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Development

Successfully merging this pull request may close these issues.

1 participant