6262 # Human-readable output in logs
6363 # This NEVER fails the job; it’s only for visibility
6464 - name : Display vulnerabilities (table format)
65- uses : aquasecurity/trivy-action@0.34 .0
65+ uses : aquasecurity/trivy-action@0.35 .0
6666 with :
6767 image-ref : torrust-tracker-deployer/${{ matrix.image.name }}:latest
6868 format : " table"
7676 # - Trivy sometimes exits with 1 even when no vulns exist
7777 # - GitHub Security UI is responsible for enforcement
7878 - name : Generate SARIF (Code Scanning)
79- uses : aquasecurity/trivy-action@0.34 .0
79+ uses : aquasecurity/trivy-action@0.35 .0
8080 with :
8181 image-ref : torrust-tracker-deployer/${{ matrix.image.name }}:latest
8282 format : " sarif"
@@ -114,7 +114,7 @@ jobs:
114114
115115 steps :
116116 - name : Display vulnerabilities (table format)
117- uses : aquasecurity/trivy-action@0.34 .0
117+ uses : aquasecurity/trivy-action@0.35 .0
118118 with :
119119 image-ref : ${{ matrix.image }}
120120 format : " table"
@@ -124,7 +124,7 @@ jobs:
124124 # Third-party images should NEVER block CI.
125125 # We only report findings to GitHub Security.
126126 - name : Generate SARIF (Code Scanning)
127- uses : aquasecurity/trivy-action@0.34 .0
127+ uses : aquasecurity/trivy-action@0.35 .0
128128 with :
129129 image-ref : ${{ matrix.image }}
130130 format : " sarif"
0 commit comments