diff --git a/.github/workflows/build.yml b/.github/workflows/build.yml index 72059a7d..6dd28563 100644 --- a/.github/workflows/build.yml +++ b/.github/workflows/build.yml @@ -340,7 +340,7 @@ jobs: merge-multiple: true - name: Run Trivy vulnerability scanner if: ${{ github.event_name == 'pull_request' }} - uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # 0.35.0 + uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0 with: input: "images/${{ matrix.image }}.tar" format: "sarif" @@ -355,7 +355,7 @@ jobs: password: ${{ secrets.GITHUB_TOKEN }} - name: Run Trivy vulnerability scanner if: ${{ github.event_name != 'pull_request' }} - uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # 0.35.0 + uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # v0.36.0 with: image-ref: "ghcr.io/jeboehm/${{ matrix.image }}:latest" format: "sarif"