Merge pull request #2481 from dexidp/dependabot/github_actions/aquasecurity/trivy-action-0.2.5

This commit is contained in:
dependabot[bot] 2022-04-19 09:59:19 +00:00 committed by GitHub
commit e9a43bf3cd
No known key found for this signature in database
GPG Key ID: 4AEE18F83AFDEB23
2 changed files with 2 additions and 2 deletions

View File

@ -132,7 +132,7 @@ jobs:
echo ::set-output name=version::${VERSION} echo ::set-output name=version::${VERSION}
- name: Run Trivy vulnerability scanner - name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@0.2.4 uses: aquasecurity/trivy-action@0.2.5
with: with:
image-ref: "ghcr.io/dexidp/dex:${{ steps.details.outputs.version }}" image-ref: "ghcr.io/dexidp/dex:${{ steps.details.outputs.version }}"
format: "sarif" format: "sarif"

View File

@ -96,7 +96,7 @@ jobs:
org.opencontainers.image.documentation=https://dexidp.io/docs/ org.opencontainers.image.documentation=https://dexidp.io/docs/
- name: Run Trivy vulnerability scanner - name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@0.2.3 uses: aquasecurity/trivy-action@0.2.5
with: with:
image-ref: "ghcr.io/dexidp/dex:${{ steps.tags.outputs.version }}" image-ref: "ghcr.io/dexidp/dex:${{ steps.tags.outputs.version }}"
format: "template" format: "template"