diff --git a/.github/workflows/component-scan.yml b/.github/workflows/component-scan.yml index b3793dd1..00b174fc 100644 --- a/.github/workflows/component-scan.yml +++ b/.github/workflows/component-scan.yml @@ -24,7 +24,7 @@ jobs: - name: Scan all the vulnerabilities and generate JSON report if: always() - uses: aquasecurity/trivy-action@0.28.0 + uses: aquasecurity/trivy-action@0.29.0 with: image-ref: image:latest vuln-type: 'os,library' @@ -36,7 +36,7 @@ jobs: - name: Save vulnerabilities report in tabular format if: always() - uses: aquasecurity/trivy-action@0.28.0 + uses: aquasecurity/trivy-action@0.29.0 with: scan-ref: trivy-results.json scan-type: convert @@ -46,7 +46,7 @@ jobs: - name: Display vulnerabilities report if: always() - uses: aquasecurity/trivy-action@0.28.0 + uses: aquasecurity/trivy-action@0.29.0 with: scan-ref: trivy-results.json scan-type: convert @@ -56,7 +56,7 @@ jobs: - name: Fail on high and critical vulnerabilities if: always() - uses: aquasecurity/trivy-action@0.28.0 + uses: aquasecurity/trivy-action@0.29.0 with: scan-ref: trivy-results.json scan-type: convert