Skip to content

pin to trivy 0.35.0#10

Merged
ecordell merged 1 commit intomainfrom
ecordell-patch-1
Mar 23, 2026
Merged

pin to trivy 0.35.0#10
ecordell merged 1 commit intomainfrom
ecordell-patch-1

Conversation

@ecordell
Copy link
Copy Markdown
Collaborator

@ecordell ecordell commented Mar 23, 2026

Description

Pin to an uncompromised sha. We got lucky that this job didn't run within the window.

References

https://socket.dev/blog/trivy-under-attack-again-github-actions-compromise

Signed-off-by: Evan Cordell <cordell.evan@gmail.com>
@ecordell ecordell merged commit be60d0a into main Mar 23, 2026
6 of 7 checks passed
@ecordell ecordell deleted the ecordell-patch-1 branch March 23, 2026 18:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants