Skip to content

Commit bd5692f

Browse files
authored
Merge pull request #6432 from karmada-io/dependabot/github_actions/aquasecurity/trivy-action-0.31.0
Bump aquasecurity/trivy-action from 0.30.0 to 0.31.0
2 parents bc4348d + ead9434 commit bd5692f

File tree

3 files changed

+5
-5
lines changed

3 files changed

+5
-5
lines changed

.github/workflows/ci-image-scanning-on-schedule.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -47,7 +47,7 @@ jobs:
4747
export REGISTRY="docker.io/karmada"
4848
make image-${{ matrix.target }}
4949
- name: Run Trivy vulnerability scanner
50-
uses: aquasecurity/trivy-action@0.30.0
50+
uses: aquasecurity/trivy-action@0.31.0
5151
env:
5252
ACTIONS_RUNTIME_TOKEN: ${{ secrets.GITHUB_TOKEN }}
5353
TRIVY_DB_REPOSITORY: ghcr.io/aquasecurity/trivy-db,public.ecr.aws/aquasecurity/trivy-db
@@ -58,7 +58,7 @@ jobs:
5858
vuln-type: 'os,library'
5959
output: '${{ matrix.target }}:${{ matrix.karmada-version }}.trivy-results.sarif'
6060
- name: display scan results
61-
uses: aquasecurity/trivy-action@0.30.0
61+
uses: aquasecurity/trivy-action@0.31.0
6262
env:
6363
TRIVY_SKIP_DB_UPDATE: true # Avoid updating the vulnerability db as it was cached in the previous step.
6464
with:

.github/workflows/ci-image-scanning.yaml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -42,7 +42,7 @@ jobs:
4242
export REGISTRY="docker.io/karmada"
4343
make image-${{ matrix.target }}
4444
- name: Run Trivy vulnerability scanner
45-
uses: aquasecurity/trivy-action@0.30.0
45+
uses: aquasecurity/trivy-action@0.31.0
4646
env:
4747
ACTIONS_RUNTIME_TOKEN: ${{ secrets.GITHUB_TOKEN }}
4848
TRIVY_DB_REPOSITORY: ghcr.io/aquasecurity/trivy-db,public.ecr.aws/aquasecurity/trivy-db
@@ -53,7 +53,7 @@ jobs:
5353
vuln-type: 'os,library'
5454
output: 'trivy-results.sarif'
5555
- name: display scan results
56-
uses: aquasecurity/trivy-action@0.30.0
56+
uses: aquasecurity/trivy-action@0.31.0
5757
env:
5858
TRIVY_SKIP_DB_UPDATE: true # Avoid updating the vulnerability db as it was cached in the previous step.
5959
with:

.github/workflows/release.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -167,7 +167,7 @@ jobs:
167167
steps:
168168
- uses: actions/checkout@v4
169169
- name: Generate sbom for karmada file system
170-
uses: aquasecurity/trivy-action@0.30.0
170+
uses: aquasecurity/trivy-action@0.31.0
171171
with:
172172
scan-type: 'fs'
173173
format: 'spdx'

0 commit comments

Comments
 (0)