Closed dependabot[bot] closed 1 week ago
The provided code change updates the GitHub Actions workflow file to use the latest version of the Trivy vulnerability scanner, which improves the project's security posture by performing comprehensive file system scans, focusing on critical and high-severity vulnerabilities, and generating SARIF output for easy integration with other security tools.
We ran 9 analyzers
against 1 file
and 0 analyzers
had findings. 9 analyzers
had no findings.
:green_circle: Risk threshold not exceeded.
Superseded by #185.
Bumps aquasecurity/trivy-action from 0.24.0 to 0.27.0.
Release notes
Sourced from aquasecurity/trivy-action's releases.
Commits
5681af8
fix: set envs only when passed (#405)8078967
chore: update description for scanners and format inputs (#407)0fa0cdb
ci: usesetup-trivy
to install Trivy (#406)a20de54
feat: store artifacts in cache by default (#399)1b8b83d
docs: add usage info aboutaction/cache
for trivy databases (#397)f781cce
feat(trivy): Bump to support v0.56.1 (#387)54f21d8
ci: sync trivy-checks version 1 (#398)89b14e5
Upgrade GitHub actions (#374)97646fe
chore: use checks bundle snapshot from trivy-action (#388)d9cd5b1
fix(Makefile): recursive option typo (#371)Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting
@dependabot rebase
.Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR: - `@dependabot rebase` will rebase this PR - `@dependabot recreate` will recreate this PR, overwriting any edits that have been made to it - `@dependabot merge` will merge this PR after your CI passes on it - `@dependabot squash and merge` will squash and merge this PR after your CI passes on it - `@dependabot cancel merge` will cancel a previously requested merge and block automerging - `@dependabot reopen` will reopen this PR if it is closed - `@dependabot close` will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually - `@dependabot show