45
45
pip-compile -o trivy_input/develop/requirements.txt requirements/requirements-dev.txt
46
46
47
47
- name : Run Trivy Scan (vuln)
48
- uses : aquasecurity/trivy-action@18f2510ee396bbf400402947b394f2dd8c87dbb0 # v0.29 .0
48
+ uses : aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # v0.30 .0
49
49
with :
50
50
scan-type : fs
51
51
format : " sarif"
@@ -55,12 +55,12 @@ jobs:
55
55
56
56
- name : Upload SARIF file
57
57
if : ${{ always() }}
58
- uses : github/codeql-action/upload-sarif@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3.28.8
58
+ uses : github/codeql-action/upload-sarif@1b549b9259bda1cb5ddde3b41741a82a2d15a841 # v3.28.8
59
59
with :
60
60
sarif_file : " trivy-results-vuln.sarif"
61
61
62
62
- name : Run Trivy Scan (spdx)
63
- uses : aquasecurity/trivy-action@18f2510ee396bbf400402947b394f2dd8c87dbb0 # v0.29 .0
63
+ uses : aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # v0.30 .0
64
64
with :
65
65
scan-type : fs
66
66
format : " spdx-json"
91
91
uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
92
92
93
93
- name : Run Trivy Scan (dockerfile and secrets)
94
- uses : aquasecurity/trivy-action@18f2510ee396bbf400402947b394f2dd8c87dbb0 # v0.29 .0
94
+ uses : aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # v0.30 .0
95
95
with :
96
96
scan-type : fs
97
97
format : " sarif"
@@ -101,7 +101,7 @@ jobs:
101
101
102
102
- name : Upload SARIF file
103
103
if : ${{ always() }}
104
- uses : github/codeql-action/upload-sarif@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3.28.8
104
+ uses : github/codeql-action/upload-sarif@1b549b9259bda1cb5ddde3b41741a82a2d15a841 # v3.28.8
105
105
with :
106
106
sarif_file : " trivy-results-misconfig.sarif"
107
107
@@ -137,7 +137,7 @@ jobs:
137
137
138
138
- name : Upload SARIF file
139
139
if : ${{ always() }}
140
- uses : github/codeql-action/upload-sarif@9e8d0789d4a0fa9ceb6b1738f7e269594bdd67f0 # v3.28.8
140
+ uses : github/codeql-action/upload-sarif@1b549b9259bda1cb5ddde3b41741a82a2d15a841 # v3.28.8
141
141
with :
142
142
sarif_file : bandit-results.sarif
143
143
@@ -165,7 +165,7 @@ jobs:
165
165
166
166
# Download artifacts with error handling
167
167
- name : Download all results
168
- uses : actions/download-artifact@fa0a91b85d4f404e444e00e005971372dc801d16 # v4.1.8
168
+ uses : actions/download-artifact@95815c38cf2ff2164869cbab79da8d1f422bc89e # v4.2.1
169
169
continue-on-error : true # Don't fail if some tools didn't generate results
170
170
with :
171
171
pattern : " *-results"
0 commit comments