Merge pull request #4887 from karmada-io/dependabot/github_actions/aquasecurity/trivy-action-0.19.0

Bump aquasecurity/trivy-action from 0.12.0 to 0.19.0
This commit is contained in:
karmada-bot 2024-05-04 14:25:09 +08:00 committed by GitHub
commit f2b079f29f
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194
1 changed files with 2 additions and 2 deletions

View File

@ -34,7 +34,7 @@ jobs:
export REGISTRY="docker.io/karmada"
make image-${{ matrix.target }}
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@0.12.0
uses: aquasecurity/trivy-action@0.19.0
with:
image-ref: 'docker.io/karmada/${{ matrix.target }}:latest'
format: 'sarif'
@ -42,7 +42,7 @@ jobs:
vuln-type: 'os,library'
output: 'trivy-results.sarif'
- name: display scan results
uses: aquasecurity/trivy-action@0.12.0
uses: aquasecurity/trivy-action@0.19.0
with:
image-ref: 'docker.io/karmada/${{ matrix.target }}:latest'
format: 'table'