Skip to content

Commit

Permalink
Bump aquasecurity/trivy-action from 0.24.0 to 0.25.0
Browse files Browse the repository at this point in the history
Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) from 0.24.0 to 0.25.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](aquasecurity/trivy-action@6e7b7d1...f781cce)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
  • Loading branch information
dependabot[bot] authored Oct 8, 2024
1 parent 11f7859 commit 363e1fc
Show file tree
Hide file tree
Showing 7 changed files with 16 additions and 16 deletions.
6 changes: 3 additions & 3 deletions .github/workflows/ci-docker-build-publish-image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -100,15 +100,15 @@ jobs:
fi
- name: Run Trivy vulnerability scanner (primary)
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # pin@v0.24.0
uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # pin@v0.25.0
id: trivy-primary
continue-on-error: true
with:
image-ref: ${{ steps.set-image-name.outputs.image-name }}:${{ steps.set-image-tag.outputs.image-tag }}
exit-code: "1"
severity: "CRITICAL,HIGH"
- name: Run Trivy vulnerability scanner (fallback)
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # pin@v0.24.0
uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # pin@v0.25.0
if: steps.trivy-primary.outcome == 'failure'
id: trivy-fallback
env:
Expand All @@ -127,7 +127,7 @@ jobs:
echo "- SBOM: $SBOM_NAME" >> "$GITHUB_STEP_SUMMARY"
- name: Run Trivy SBOM generation
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # pin@v0.24.0
uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # pin@v0.25.0
continue-on-error: true
with:
scan-type: image
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/ci-quarkus-build-publish-image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -154,15 +154,15 @@ jobs:
--creation-time now
- name: Run Trivy vulnerability scanner (primary)
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # pin@v0.24.0
uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # pin@v0.25.0
id: trivy-primary
continue-on-error: true
with:
image-ref: ${{env.IMAGE-NAME}}:${{env.IMAGETAG}}
exit-code: "1"
severity: "CRITICAL,HIGH"
- name: Run Trivy vulnerability scanner (fallback)
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # pin@v0.24.0
uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # pin@v0.25.0
if: steps.trivy-primary.outcome == 'failure'
id: trivy-fallback
env:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/ci-quarkus-container-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -124,15 +124,15 @@ jobs:
artifact-name: sbom-${{steps.sbom-name.outputs.SBOM_ARTIFACT_ID}}-${{env.IMAGETAG}}.spdx

- name: Run Trivy vulnerability scanner (primary)
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # pin@v0.24.0
uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # pin@v0.25.0
id: trivy-primary
continue-on-error: true
with:
image-ref: ${{env.IMAGE-NAME}}:${{env.IMAGETAG}}
exit-code: "1"
severity: "CRITICAL,HIGH"
- name: Run Trivy vulnerability scanner (fallback)
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # pin@v0.24.0
uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # pin@v0.25.0
if: steps.trivy-primary.outcome == 'failure'
id: trivy-fallback
env:
Expand Down
6 changes: 3 additions & 3 deletions .github/workflows/ci-spring-boot-build-publish-image.yml
Original file line number Diff line number Diff line change
Expand Up @@ -187,7 +187,7 @@ jobs:
fi
- name: Run Trivy vulnerability scanner (primary)
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # pin@v0.24.0
uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # pin@v0.25.0
id: trivy-primary
continue-on-error: true
with:
Expand All @@ -197,7 +197,7 @@ jobs:
trivyignores: ${{ steps.set-trivyignore-path.outputs.trivyignore-path }}

- name: Run Trivy vulnerability scanner (fallback)
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # pin@v0.24.0
uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # pin@v0.25.0
if: steps.trivy-primary.outcome == 'failure'
id: trivy-fallback
env:
Expand All @@ -217,7 +217,7 @@ jobs:
echo "- SBOM: $SBOM_NAME" >> "$GITHUB_STEP_SUMMARY"
- name: Run Trivy SBOM generation
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # pin@v0.24.0
uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # pin@v0.25.0
continue-on-error: true
with:
scan-type: image
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/ci-spring-boot-container-scan.yml
Original file line number Diff line number Diff line change
Expand Up @@ -79,15 +79,15 @@ jobs:
run: mvn -DskipTests -B spring-boot:build-image --file pom.xml -Dspring-boot.build-image.imageName=${{ steps.set-image-name.outputs.image-name }}:${{ steps.set-image-tag.outputs.image-tag }} -Dspring-boot.build-image.builder=paketobuildpacks/${{ inputs.image-pack }}

- name: Run Trivy vulnerability scanner (primary)
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # pin@v0.24.0
uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # pin@v0.25.0
id: trivy-primary
continue-on-error: true
with:
image-ref: "${{ steps.set-image-name.outputs.image-name }}:${{ steps.set-image-tag.outputs.image-tag }}"
exit-code: "1"
severity: "CRITICAL,HIGH"
- name: Run Trivy vulnerability scanner (fallback)
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # pin@v0.24.0
uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # pin@v0.25.0
if: steps.trivy-primary.outcome == 'failure'
id: trivy-fallback
env:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/test-k6-build-docker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -45,15 +45,15 @@ jobs:
run: docker build --tag ${{env.IMAGE-NAME}}:${{env.IMAGETAG}} docker/

- name: Run Trivy vulnerability scanner (primary)
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # pin@v0.24.0
uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # pin@v0.25.0
id: trivy-primary
continue-on-error: true
with:
image-ref: ${{env.IMAGE-NAME}}:${{env.IMAGETAG}}
exit-code: "1"
severity: "CRITICAL,HIGH"
- name: Run Trivy vulnerability scanner (fallback)
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # pin@v0.24.0
uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # pin@v0.25.0
if: steps.trivy-primary.outcome == 'failure'
id: trivy-fallback
env:
Expand Down
4 changes: 2 additions & 2 deletions .github/workflows/test-k6-build-publish-docker.yml
Original file line number Diff line number Diff line change
Expand Up @@ -67,15 +67,15 @@ jobs:
run: docker build --tag ${{env.IMAGE_NAME}}:${{env.IMAGETAG}} docker/

- name: Run Trivy vulnerability scanner (primary)
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # pin@v0.24.0
uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # pin@v0.25.0
id: trivy-primary
continue-on-error: true
with:
image-ref: ${{env.IMAGE_NAME}}:${{env.IMAGETAG}}
exit-code: "1"
severity: "CRITICAL,HIGH"
- name: Run Trivy vulnerability scanner (fallback)
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # pin@v0.24.0
uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # pin@v0.25.0
if: steps.trivy-primary.outcome == 'failure'
id: trivy-fallback
env:
Expand Down

0 comments on commit 363e1fc

Please sign in to comment.