From 5d360d18a5d48582d0bd9f22339b1d3579f00ba7 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Tue, 26 Nov 2024 05:01:09 +0000 Subject: [PATCH] chore: bump aquasecurity/trivy-action in /.github/workflows (#464) --- .github/workflows/component-scan.yml | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/.github/workflows/component-scan.yml b/.github/workflows/component-scan.yml index b3793dd1..00b174fc 100644 --- a/.github/workflows/component-scan.yml +++ b/.github/workflows/component-scan.yml @@ -24,7 +24,7 @@ jobs: - name: Scan all the vulnerabilities and generate JSON report if: always() - uses: aquasecurity/trivy-action@0.28.0 + uses: aquasecurity/trivy-action@0.29.0 with: image-ref: image:latest vuln-type: 'os,library' @@ -36,7 +36,7 @@ jobs: - name: Save vulnerabilities report in tabular format if: always() - uses: aquasecurity/trivy-action@0.28.0 + uses: aquasecurity/trivy-action@0.29.0 with: scan-ref: trivy-results.json scan-type: convert @@ -46,7 +46,7 @@ jobs: - name: Display vulnerabilities report if: always() - uses: aquasecurity/trivy-action@0.28.0 + uses: aquasecurity/trivy-action@0.29.0 with: scan-ref: trivy-results.json scan-type: convert @@ -56,7 +56,7 @@ jobs: - name: Fail on high and critical vulnerabilities if: always() - uses: aquasecurity/trivy-action@0.28.0 + uses: aquasecurity/trivy-action@0.29.0 with: scan-ref: trivy-results.json scan-type: convert