Skip to content

Commit 87247b4

Browse files
authored
Merge pull request #31 from trustyai-explainability/tarilabs-patch-1
Pin Trivy action to specific commit version
2 parents 296a84b + 0d2f38f commit 87247b4

1 file changed

Lines changed: 3 additions & 3 deletions

File tree

.github/workflows/security.yml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -41,7 +41,7 @@ jobs:
4141
run: poetry install --with dev
4242

4343
- name: Run Trivy filesystem scan
44-
uses: aquasecurity/trivy-action@master
44+
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0.35.0
4545
with:
4646
scan-type: "fs"
4747
scan-ref: "."
@@ -51,7 +51,7 @@ jobs:
5151
exit-code: "0"
5252

5353
- name: Run Trivy dependency scan
54-
uses: aquasecurity/trivy-action@master
54+
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0.35.0
5555
with:
5656
scan-type: "fs"
5757
scan-ref: "."
@@ -62,7 +62,7 @@ jobs:
6262
exit-code: "0"
6363

6464
- name: Check for critical and high vulnerabilities
65-
uses: aquasecurity/trivy-action@master
65+
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0.35.0
6666
with:
6767
scan-type: "fs"
6868
scan-ref: "."

0 commit comments

Comments
 (0)