Merge pull request #5715 from karmada-io/dependabot/github_actions/aquasecurity/trivy-action-0.28.0

build(deps): bump aquasecurity/trivy-action from 0.27.0 to 0.28.0
This commit is contained in:
karmada-bot 2024-10-21 14:17:31 +08:00 committed by GitHub
commit aca83a7689
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
3 changed files with 5 additions and 5 deletions

View File

@ -47,7 +47,7 @@ jobs:
export REGISTRY="docker.io/karmada" export REGISTRY="docker.io/karmada"
make image-${{ matrix.target }} make image-${{ matrix.target }}
- name: Run Trivy vulnerability scanner - name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@0.27.0 uses: aquasecurity/trivy-action@0.28.0
with: with:
image-ref: 'docker.io/karmada/${{ matrix.target }}:${{ matrix.karmada-version }}' image-ref: 'docker.io/karmada/${{ matrix.target }}:${{ matrix.karmada-version }}'
format: 'sarif' format: 'sarif'
@ -55,7 +55,7 @@ jobs:
vuln-type: 'os,library' vuln-type: 'os,library'
output: '${{ matrix.target }}:${{ matrix.karmada-version }}.trivy-results.sarif' output: '${{ matrix.target }}:${{ matrix.karmada-version }}.trivy-results.sarif'
- name: display scan results - name: display scan results
uses: aquasecurity/trivy-action@0.27.0 uses: aquasecurity/trivy-action@0.28.0
with: with:
image-ref: 'docker.io/karmada/${{ matrix.target }}:${{ matrix.karmada-version }}' image-ref: 'docker.io/karmada/${{ matrix.target }}:${{ matrix.karmada-version }}'
format: 'table' format: 'table'

View File

@ -42,7 +42,7 @@ jobs:
export REGISTRY="docker.io/karmada" export REGISTRY="docker.io/karmada"
make image-${{ matrix.target }} make image-${{ matrix.target }}
- name: Run Trivy vulnerability scanner - name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@0.27.0 uses: aquasecurity/trivy-action@0.28.0
with: with:
image-ref: 'docker.io/karmada/${{ matrix.target }}:latest' image-ref: 'docker.io/karmada/${{ matrix.target }}:latest'
format: 'sarif' format: 'sarif'
@ -50,7 +50,7 @@ jobs:
vuln-type: 'os,library' vuln-type: 'os,library'
output: 'trivy-results.sarif' output: 'trivy-results.sarif'
- name: display scan results - name: display scan results
uses: aquasecurity/trivy-action@0.27.0 uses: aquasecurity/trivy-action@0.28.0
with: with:
image-ref: 'docker.io/karmada/${{ matrix.target }}:latest' image-ref: 'docker.io/karmada/${{ matrix.target }}:latest'
format: 'table' format: 'table'

View File

@ -167,7 +167,7 @@ jobs:
steps: steps:
- uses: actions/checkout@v4 - uses: actions/checkout@v4
- name: Generate sbom for karmada file system - name: Generate sbom for karmada file system
uses: aquasecurity/trivy-action@0.27.0 uses: aquasecurity/trivy-action@0.28.0
with: with:
scan-type: 'fs' scan-type: 'fs'
format: 'spdx' format: 'spdx'