File tree Expand file tree Collapse file tree 5 files changed +10
-10
lines changed Expand file tree Collapse file tree 5 files changed +10
-10
lines changed Original file line number Diff line number Diff line change @@ -29,11 +29,11 @@ jobs:
29
29
sudo apt-get update
30
30
sudo apt-get install -y libze1 libze-dev
31
31
- name : Initialize CodeQL
32
- uses : github/codeql-action/init@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3
32
+ uses : github/codeql-action/init@fca7ace96b7d713c7035871441bd52efbe39e27e # v3
33
33
with :
34
34
languages : ' go'
35
35
36
36
- name : Perform CodeQL Analysis
37
- uses : github/codeql-action/analyze@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3
37
+ uses : github/codeql-action/analyze@fca7ace96b7d713c7035871441bd52efbe39e27e # v3
38
38
with :
39
39
category : " /language:go"
Original file line number Diff line number Diff line change 70
70
run : |
71
71
ORG=${{ inputs.registry }} TAG=${{ inputs.image_tag }} make ${IMAGE_NAME} BUILDER=docker
72
72
- name : Trivy scan for image
73
- uses : aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # 0.30 .0
73
+ uses : aquasecurity/trivy-action@76071ef0d7ec797419534a183b498b4d6366cf37 # 0.31 .0
74
74
with :
75
75
scan-type : image
76
76
image-ref : ${{ inputs.registry }}/${{ matrix.image }}:${{ inputs.image_tag }}
Original file line number Diff line number Diff line change 26
26
results_format : sarif
27
27
publish_results : true
28
28
- name : " Upload results to security"
29
- uses : github/codeql-action/upload-sarif@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3
29
+ uses : github/codeql-action/upload-sarif@fca7ace96b7d713c7035871441bd52efbe39e27e # v3
30
30
with :
31
31
sarif_file : results.sarif
Original file line number Diff line number Diff line change 32
32
- name : Checkout
33
33
uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
34
34
- name : Run Trivy in config mode for deployments
35
- uses : aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # 0.30 .0
35
+ uses : aquasecurity/trivy-action@76071ef0d7ec797419534a183b498b4d6366cf37 # 0.31 .0
36
36
with :
37
37
scan-type : config
38
38
scan-ref : deployments/
50
50
- name : Checkout
51
51
uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
52
52
- name : Run Trivy in config mode for dockerfiles
53
- uses : aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # 0.30 .0
53
+ uses : aquasecurity/trivy-action@76071ef0d7ec797419534a183b498b4d6366cf37 # 0.31 .0
54
54
with :
55
55
scan-type : config
56
56
scan-ref : build/docker/
64
64
- name : Checkout
65
65
uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
66
66
- name : Run Trivy in fs mode
67
- uses : aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # 0.30 .0
67
+ uses : aquasecurity/trivy-action@76071ef0d7ec797419534a183b498b4d6366cf37 # 0.31 .0
68
68
with :
69
69
scan-type : fs
70
70
scan-ref : .
81
81
- name : Checkout
82
82
uses : actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4
83
83
- name : Run Trivy in fs mode
84
- uses : aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # 0.30 .0
84
+ uses : aquasecurity/trivy-action@76071ef0d7ec797419534a183b498b4d6366cf37 # 0.31 .0
85
85
with :
86
86
scan-type : fs
87
87
scan-ref : .
Original file line number Diff line number Diff line change 22
22
- name : Run Trivy in fs mode
23
23
# Don't fail in case of vulnerabilities, report them in the next step
24
24
continue-on-error : true
25
- uses : aquasecurity/trivy-action@6c175e9c4083a92bbca2f9724c8a5e33bc2d97a5 # 0.30 .0
25
+ uses : aquasecurity/trivy-action@76071ef0d7ec797419534a183b498b4d6366cf37 # 0.31 .0
26
26
with :
27
27
scan-type : fs
28
28
scan-ref : .
31
31
format : sarif
32
32
output : trivy-report.sarif
33
33
- name : Upload sarif report to GitHub Security tab
34
- uses : github/codeql-action/upload-sarif@ff0a06e83cb2de871e5a09832bc6a81e7276941f # v3
34
+ uses : github/codeql-action/upload-sarif@fca7ace96b7d713c7035871441bd52efbe39e27e # v3
35
35
with :
36
36
sarif_file : trivy-report.sarif
You can’t perform that action at this time.
0 commit comments