diff --git a/.github/workflows/scans-images.yml b/.github/workflows/scans-images.yml index ba5b3c0..39f68ae 100644 --- a/.github/workflows/scans-images.yml +++ b/.github/workflows/scans-images.yml @@ -65,7 +65,7 @@ jobs: steps: - name: Run vulnerability scanner if: ${{ needs.build_info.outputs.is_main == 'true' || needs.build_info.outputs.is_release == 'true' }} - uses: aquasecurity/trivy-action@0.33.1 + uses: aquasecurity/trivy-action@0.34.0 with: image-ref: ${{ matrix.image }} severity: 'CRITICAL,HIGH,MEDIUM,LOW,UNKNOWN' @@ -79,14 +79,14 @@ jobs: sarif_file: 'trivy-results.sarif' - name: Update GitHub Dependency Graph if: ${{ needs.build_info.outputs.is_main == 'true' || needs.build_info.outputs.is_release == 'true' }} - uses: aquasecurity/trivy-action@0.33.1 + uses: aquasecurity/trivy-action@0.34.0 with: image-ref: ${{ matrix.image }} format: github output: sbom.github.json github-pat: ${{ secrets.GITHUB_TOKEN }} - name: Generate CycloneDX SBOM - uses: aquasecurity/trivy-action@0.33.1 + uses: aquasecurity/trivy-action@0.34.0 with: image-ref: ${{ matrix.image }} format: cyclonedx diff --git a/.github/workflows/scans-repo.yml b/.github/workflows/scans-repo.yml index eceac08..bfb13a4 100644 --- a/.github/workflows/scans-repo.yml +++ b/.github/workflows/scans-repo.yml @@ -25,7 +25,7 @@ jobs: - uses: actions/checkout@v6 - name: Run vulnerability scanner if: ${{ env.is_release == 'true' || env.is_main == 'true' }} - uses: aquasecurity/trivy-action@0.33.1 + uses: aquasecurity/trivy-action@0.34.0 with: scan-type: 'fs' image-ref: . @@ -40,7 +40,7 @@ jobs: sarif_file: 'trivy-results.sarif' - name: Update GitHub Dependency Graph if: ${{ env.is_release == 'true' || env.is_main == 'true' }} - uses: aquasecurity/trivy-action@0.33.1 + uses: aquasecurity/trivy-action@0.34.0 with: scan-type: 'fs' image-ref: . @@ -48,7 +48,7 @@ jobs: output: sbom.github.json github-pat: ${{ secrets.GITHUB_TOKEN }} - name: Generate CycloneDX SBOM - uses: aquasecurity/trivy-action@0.33.1 + uses: aquasecurity/trivy-action@0.34.0 with: scan-type: 'fs' image-ref: .