Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
61 commits
Select commit Hold shift + click to select a range
7028789
chore(deps): update dependency anchore/grype to v0.117.0
renovate[bot] Aug 10, 2026
16578f8
chore(deps): update dependency anchore/grype to v0.117.0 (#1234)
Wikid82 Aug 10, 2026
ece95c7
chore(deps): update dependency anchore/syft to v1.51.0
renovate[bot] Aug 10, 2026
a02f621
Propagate changes from main into development (#1233)
Wikid82 Aug 11, 2026
e613bc2
Merge branch 'development' into renovate/anchore-syft-1.x
Wikid82 Aug 11, 2026
1ac0c71
chore(deps): update dependency anchore/syft to v1.51.0 (#1240)
Wikid82 Aug 11, 2026
362b643
chore(deps): update github-actions-non-major
renovate[bot] Aug 11, 2026
d4b772f
chore(deps): update github-actions-non-major (#1241)
Wikid82 Aug 11, 2026
076b430
fix: correct output formatting for latest npm version check
Wikid82 Aug 11, 2026
f41a3f5
fix: update golang.org/x/crypto to v0.55.0 and golang.org/x/text to v…
Wikid82 Aug 11, 2026
e1c6f49
chore(deps): update npm dependencies
Wikid82 Aug 11, 2026
6436226
fix: avoid npm-check-updates crash on multi-entry overrides update
Wikid82 Aug 11, 2026
ae56a67
chore(deps): update module golang.org/x/crypto to v0.55.0
renovate[bot] Aug 11, 2026
d89288c
chore(deps): update module golang.org/x/crypto to v0.55.0 (#1243)
Wikid82 Aug 11, 2026
d89ad49
chore(deps): update dependency @testing-library/user-event to ^14.6.4
renovate[bot] Aug 12, 2026
975be9c
chore(deps): update dependency @testing-library/user-event to ^14.6.4…
Wikid82 Aug 12, 2026
a51ae85
chore(deps): update golang.org/x/net to v0.58.0
Wikid82 Aug 12, 2026
9fd0c77
chore(deps): update @napi-rs/wasm-runtime to v1.2.3 and other depende…
Wikid82 Aug 12, 2026
6fa8fa4
chore(deps): update @oxc-project/types and @rolldown bindings to vers…
Wikid82 Aug 12, 2026
ea52229
fix: add pinned-Syft fallback for transient SBOM generation failures
Wikid82 Aug 12, 2026
47b8dc9
chore(deps): update dependency github/codeql-cli-binaries to v2.26.3
renovate[bot] Aug 12, 2026
b6af07c
fix: extend renovate syft version tracking to sbom-action input and n…
Wikid82 Aug 12, 2026
99f7ba9
fix: add attribution section to settings.json for commit and PR tracking
Wikid82 Aug 12, 2026
ddc209b
fix: retry grype installer against transient GitHub failures
Wikid82 Aug 12, 2026
4eccb0c
chore(deps): update dependency github/codeql-cli-binaries to v2.26.3 …
Wikid82 Aug 12, 2026
d370fed
chore(deps): update dependency anchore/syft to v1.51.0
renovate[bot] Aug 12, 2026
d54ad47
chore(deps): update dependency anchore/syft to v1.51.0 (#1246)
Wikid82 Aug 12, 2026
673044d
chore(deps): update module golang.org/x/net to v0.58.0
renovate[bot] Aug 12, 2026
07f4cc0
chore(deps): update module golang.org/x/net to v0.58.0 (#1247)
Wikid82 Aug 13, 2026
e82c161
chore(deps): update logrus to v1.10.0 and add golang.org/x/sys v0.13.0
Wikid82 Aug 13, 2026
7a6caf7
chore(deps): update logrus to v1.10.0
Wikid82 Aug 13, 2026
0778efc
chore(deps): update baseline-browser-mapping to v2.11.14
Wikid82 Aug 13, 2026
d252a92
chore(deps): update github-actions-non-major
renovate[bot] Aug 13, 2026
f3c6e46
chore(deps): update github-actions-non-major (#1248)
Wikid82 Aug 14, 2026
ac26ef6
chore: bump Go toolchain to 1.26.6 and update golang.org/x deps
Wikid82 Aug 14, 2026
c510085
chore: bump electron-to-chromium to 1.5.406
Wikid82 Aug 14, 2026
939ddb7
chore(deps): update go-non-major
renovate[bot] Aug 14, 2026
6bf066f
feat(security): add opt-in SARIF output mode to local Semgrep script …
Wikid82 Aug 14, 2026
a0aa941
fix(security): patch vulnerable transitive dependency in bundled Crow…
Wikid82 Aug 14, 2026
2fbecf0
feat(security): add pinned Semgrep SAST scan to CI, mirroring local p…
Wikid82 Aug 14, 2026
7c6fb04
docs: document Semgrep CI scan in SECURITY.md and ARCHITECTURE.md
Wikid82 Aug 14, 2026
3257028
fix: correct jq escaping bug in PR Trivy findings renderer
Wikid82 Aug 14, 2026
9dc2be4
chore(deps): track pinned Semgrep image in Renovate
Wikid82 Aug 14, 2026
035387e
docs: finalize Semgrep CI plan, QA report, and manual test tracking
Wikid82 Aug 14, 2026
da8d13c
docs: mark Semgrep Renovate follow-up resolved
Wikid82 Aug 14, 2026
d6bceaa
chore(deps): update go-non-major (#1249)
Wikid82 Aug 14, 2026
2865177
chore(deps): update actions/upload-artifact action to v7
renovate[bot] Aug 14, 2026
334d0a0
fix: revert nightly SBOM format from CycloneDX to SPDX-JSON
Wikid82 Aug 14, 2026
ad246fe
chore: drop stale nosemgrep suppressions on shared WS upgrader
Wikid82 Aug 14, 2026
438b2c8
chore: drop last stale nosemgrep suppression on shared WS upgrader
Wikid82 Aug 14, 2026
e1f5eef
fix: restore nosemgrep suppressions for shared WS upgrader origin check
Wikid82 Aug 14, 2026
b32e099
fix(security): make origin check visible to static analysis at every …
Wikid82 Aug 14, 2026
6a84ab8
chore(deps): update actions/upload-artifact action to v7 (#1250)
Wikid82 Aug 14, 2026
7cf1da5
fix(security): patch vulnerable transitive dependency in bundled Crow…
Wikid82 Aug 14, 2026
fcdbb0b
chore(deps): update module github.com/klauspost/compress to v1.19.2
renovate[bot] Aug 14, 2026
b9384e9
chore(deps): update module github.com/klauspost/compress to v1.19.2 (…
Wikid82 Aug 14, 2026
3e9dd35
chore(deps): update dependency aquasecurity/trivy to v0.74.0
renovate[bot] Aug 14, 2026
7db4e98
chore(deps): update dependency aquasecurity/trivy to v0.74.0 (#1252)
Wikid82 Aug 14, 2026
3e0cf11
chore(docker): update GeoLite2-Country.mmdb checksum
Wikid82 Aug 16, 2026
13ec148
chore(docker): update GeoLite2-Country.mmdb checksum (#1254)
Wikid82 Aug 16, 2026
29b79ff
Merge remote-tracking branch 'origin/main' into nightly
Wikid82 Aug 17, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
4 changes: 4 additions & 0 deletions .claude/settings.json
Original file line number Diff line number Diff line change
Expand Up @@ -10,5 +10,9 @@
},
"worktree": {
"bgIsolation": "none"
},
"attribution": {
"commit": "",
"pr": ""
}
}
32 changes: 31 additions & 1 deletion .github/renovate.json
Original file line number Diff line number Diff line change
Expand Up @@ -244,6 +244,19 @@
"datasourceTemplate": "golang-version",
"versioningTemplate": "semver"
},
{
"customType": "regex",
"description": "Track pinned Semgrep container image digest in the Semgrep CI workflow",
"managerFilePatterns": [
"/^\\.github/workflows/semgrep\\.yml$/"
],
"matchStrings": [
"#\\s*renovate:\\s*datasource=docker\\s+depName=semgrep/semgrep\\s*\\n\\s*image:\\s*semgrep/semgrep:(?<currentValue>[^@\\s]+)@(?<currentDigest>sha256:[a-f0-9]+)"
],
"depNameTemplate": "semgrep/semgrep",
"datasourceTemplate": "docker",
"versioningTemplate": "docker"
},
{
"customType": "regex",
"description": "Track NODE_VERSION in Actions workflows",
Expand Down Expand Up @@ -275,11 +288,15 @@
"description": "Track Syft version in workflows and scripts",
"managerFilePatterns": [
"/^\\.github/workflows/nightly-build\\.yml$/",
"/^\\.github/workflows/docker-build\\.yml$/",
"/^\\.github/workflows/supply-chain-pr\\.yml$/",
"/^\\.github/workflows/supply-chain-verify\\.yml$/",
"/^\\.github/skills/security-scan-docker-image-scripts/run\\.sh$/"
],
"matchStrings": [
"SYFT_VERSION=\\\"v(?<currentValue>[^\\\"\\s]+)\\\"",
"set_default_env \\\"SYFT_VERSION\\\" \\\"v(?<currentValue>[^\\\"]+)\\\""
"set_default_env \\\"SYFT_VERSION\\\" \\\"v(?<currentValue>[^\\\"]+)\\\"",
"syft-version:\\s*v(?<currentValue>[^\\s]+)"
],
"depNameTemplate": "anchore/syft",
"datasourceTemplate": "github-releases",
Expand Down Expand Up @@ -396,6 +413,19 @@
"datasourceTemplate": "go",
"versioningTemplate": "semver"
},
{
"customType": "regex",
"description": "Track github.com/klauspost/compress version ARG in Dockerfile",
"managerFilePatterns": [
"/^Dockerfile$/"
],
"matchStrings": [
"#\\s*renovate:\\s*datasource=go\\s+depName=github\\.com/klauspost/compress\\s*\\nARG KLAUSPOST_COMPRESS_VERSION=(?<currentValue>[^\\s]+)"
],
"depNameTemplate": "github.com/klauspost/compress",
"datasourceTemplate": "go",
"versioningTemplate": "semver"
},
{
"customType": "regex",
"description": "Track golang-jwt/jwt v5 in go.mod via github-tags (workaround: Renovate go datasource no-result for /vN module paths)",
Expand Down
2 changes: 1 addition & 1 deletion .github/skills/examples/gorm-scanner-ci-workflow.yml
Original file line number Diff line number Diff line change
Expand Up @@ -25,7 +25,7 @@ jobs:
- name: Setup Go
uses: actions/setup-go@b7ad1dad31e06c5925ef5d2fc7ad053ef454303e # v7
with:
go-version: "1.26.5"
go-version: "1.26.6"

- name: Run GORM Security Scanner
id: gorm-scan
Expand Down
6 changes: 3 additions & 3 deletions .github/skills/security-scan-docker-image-scripts/run.sh
Original file line number Diff line number Diff line change
Expand Up @@ -35,7 +35,7 @@ fi
# Check Grype
if ! command -v grype >/dev/null 2>&1; then
log_error "Grype not found - install from: https://github.com/anchore/grype"
log_error "Installation: curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sh -s -- -b /usr/local/bin v0.116.1"
log_error "Installation: curl -sSfL https://raw.githubusercontent.com/anchore/grype/main/install.sh | sh -s -- -b /usr/local/bin v0.117.0"
error_exit "Grype is required for vulnerability scanning" 2
fi

Expand All @@ -50,8 +50,8 @@ SYFT_INSTALLED_VERSION=$(syft version | grep -oP 'Version:\s*\Kv?[0-9]+\.[0-9]+\
GRYPE_INSTALLED_VERSION=$(grype version | grep -oP 'Version:\s*\Kv?[0-9]+\.[0-9]+\.[0-9]+' | head -1 || echo "unknown")

# Set defaults matching CI workflow
set_default_env "SYFT_VERSION" "v1.50.0"
set_default_env "GRYPE_VERSION" "v0.116.1"
set_default_env "SYFT_VERSION" "v1.51.0"
set_default_env "GRYPE_VERSION" "v0.117.0"
set_default_env "IMAGE_TAG" "charon:local"
set_default_env "FAIL_ON_SEVERITY" "Critical,High"

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/benchmark.yml
Original file line number Diff line number Diff line change
Expand Up @@ -12,7 +12,7 @@ concurrency:
cancel-in-progress: true

env:
GO_VERSION: '1.26.5'
GO_VERSION: '1.26.6'
GOTOOLCHAIN: local

# Minimal permissions at workflow level; write permissions granted at job level for push only
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/codecov-upload.yml
Original file line number Diff line number Diff line change
Expand Up @@ -28,7 +28,7 @@ concurrency:
cancel-in-progress: true

env:
GO_VERSION: '1.26.5'
GO_VERSION: '1.26.6'
NODE_VERSION: '24.19.0'
GOTOOLCHAIN: local

Expand Down
8 changes: 4 additions & 4 deletions .github/workflows/codeql.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ concurrency:

env:
GOTOOLCHAIN: local
GO_VERSION: '1.26.5'
GO_VERSION: '1.26.6'

permissions:
contents: read
Expand Down Expand Up @@ -52,7 +52,7 @@ jobs:
run: bash scripts/ci/check-codeql-parity.sh

- name: Initialize CodeQL
uses: github/codeql-action/init@5595ccaf912efad79be6eef63a5619ff05969be3 # v4
uses: github/codeql-action/init@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4
with:
languages: ${{ matrix.language }}
queries: security-and-quality
Expand Down Expand Up @@ -92,11 +92,11 @@ jobs:
run: mkdir -p sarif-results

- name: Autobuild
uses: github/codeql-action/autobuild@5595ccaf912efad79be6eef63a5619ff05969be3 # v4
uses: github/codeql-action/autobuild@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4

- name: Perform CodeQL Analysis
id: codeql_analyze
uses: github/codeql-action/analyze@5595ccaf912efad79be6eef63a5619ff05969be3 # v4
uses: github/codeql-action/analyze@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4
with:
category: "/language:${{ matrix.language }}"
output: sarif-results/${{ matrix.language }}
Expand Down
72 changes: 59 additions & 13 deletions .github/workflows/docker-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -912,7 +912,7 @@ jobs:
format: 'table'
severity: 'CRITICAL,HIGH'
exit-code: '0'
version: 'v0.73.0'
version: 'v0.74.0'
trivyignores: '.trivyignore'
continue-on-error: true

Expand All @@ -925,7 +925,7 @@ jobs:
format: 'sarif'
output: 'trivy-results.sarif'
severity: 'CRITICAL,HIGH'
version: 'v0.73.0'
version: 'v0.74.0'
trivyignores: '.trivyignore'
continue-on-error: true

Expand All @@ -941,7 +941,7 @@ jobs:

- name: Upload Trivy results
if: env.TRIGGER_EVENT != 'pull_request' && steps.trivy-check.outputs.exists == 'true'
uses: github/codeql-action/upload-sarif@f205ea1c3313d32999d8d6a48b4f6530d4437b38 # v4.37.4
uses: github/codeql-action/upload-sarif@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7
with:
sarif_file: 'trivy-results.sarif'
category: ${{ env.TRIVY_SARIF_CATEGORY }}
Expand All @@ -964,22 +964,68 @@ jobs:

# Generate SBOM (Software Bill of Materials) for supply chain security
# Only for production builds (main/development) - feature branches use downstream supply-chain-pr.yml
# anchore/sbom-action resolves the pinned syft release tag against the GitHub
# API at job runtime; transient upstream 5xx/rate-limit errors there fail the
# step even though the pin itself is valid, so continue-on-error + a
# deterministic pinned-Syft fallback (below) makes this resilient.
- name: Generate SBOM
id: sbom_primary
continue-on-error: true
uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0
if: env.TRIGGER_EVENT != 'pull_request' && needs.setup.outputs.is_feature_push != 'true'
with:
image: ${{ env.GHCR_REGISTRY }}/${{ env.IMAGE_NAME }}@${{ steps.merge.outputs.digest }}
format: cyclonedx-json
output-file: sbom.cyclonedx.json
syft-version: v1.45.1
syft-version: v1.51.0

- name: Generate SBOM fallback with pinned Syft
if: env.TRIGGER_EVENT != 'pull_request' && needs.setup.outputs.is_feature_push != 'true' && always()
run: |
set -euo pipefail

if [[ "${{ steps.sbom_primary.outcome }}" == "success" ]] && [[ -s sbom.cyclonedx.json ]] && jq -e . sbom.cyclonedx.json >/dev/null 2>&1; then
echo "Primary SBOM generation succeeded with valid JSON; skipping fallback"
exit 0
fi

echo "Primary SBOM generation failed or produced missing/invalid output; using deterministic Syft fallback"

SYFT_VERSION="v1.51.0"
OS="$(uname -s | tr '[:upper:]' '[:lower:]')"
ARCH="$(uname -m)"
case "$ARCH" in
x86_64) ARCH="amd64" ;;
aarch64|arm64) ARCH="arm64" ;;
*) echo "Unsupported architecture: $ARCH"; exit 1 ;;
esac

TARBALL="syft_${SYFT_VERSION#v}_${OS}_${ARCH}.tar.gz"
BASE_URL="https://github.com/anchore/syft/releases/download/${SYFT_VERSION}"

curl -fsSLo "$TARBALL" "${BASE_URL}/${TARBALL}"
curl -fsSLo checksums.txt "${BASE_URL}/syft_${SYFT_VERSION#v}_checksums.txt"

grep " ${TARBALL}$" checksums.txt > checksum_line.txt
sha256sum -c checksum_line.txt

tar -xzf "$TARBALL" syft
chmod +x syft

DIGEST="${{ steps.merge.outputs.digest }}"
if [[ -z "$DIGEST" ]]; then
echo "::error::Digest from merge step is empty; the merge step did not complete successfully"
exit 1
fi
./syft "${{ env.GHCR_REGISTRY }}/${{ env.IMAGE_NAME }}@${DIGEST}" -o cyclonedx-json=sbom.cyclonedx.json

# Create verifiable attestation for the SBOM
# (actions/attest-sbom is deprecated; actions/attest supports sbom-path natively)
# GitHub's OIDC token endpoint occasionally fails transiently
# ("CI: no tokens available"), so retry once before failing the build
- name: Attest SBOM
id: attest-sbom
uses: actions/attest@508db95dd578ae2727ebd6217d5ba78e4fbda05d # v4.2.1
uses: actions/attest@1e69f48acb82d1966a394da916b4c1698aa569d6 # v4.2.2
if: env.TRIGGER_EVENT != 'pull_request' && needs.setup.outputs.is_feature_push != 'true'
continue-on-error: true
with:
Expand Down Expand Up @@ -1152,7 +1198,7 @@ jobs:
trivyignores: '.trivyignore'
severity: 'CRITICAL,HIGH'
exit-code: '0'
version: 'v0.73.0'
version: 'v0.74.0'

- name: Run Trivy scan on PR image (SARIF - blocking)
id: trivy-scan
Expand All @@ -1167,7 +1213,7 @@ jobs:
# Keep scanning strict for CRITICAL/HIGH; fail is enforced explicitly
# at the end so SARIF upload and summaries still run.
exit-code: '1'
version: 'v0.73.0'
version: 'v0.74.0'
continue-on-error: true

- name: Check Trivy PR SARIF exists
Expand All @@ -1182,7 +1228,7 @@ jobs:

- name: Upload Trivy scan results
if: always() && steps.trivy-pr-check.outputs.exists == 'true'
uses: github/codeql-action/upload-sarif@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
uses: github/codeql-action/upload-sarif@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7
with:
sarif_file: 'trivy-pr-results.sarif'
category: ${{ env.TRIVY_SARIF_CATEGORY }}
Expand Down Expand Up @@ -1285,15 +1331,15 @@ jobs:
$result.ruleId
// ($result.rule // {} | .id)
// (
if ($result.ruleIndex != null and (($run.tool.driver.rules? // null) | type) == \"array\") then
($run.tool.driver.rules[$result.ruleIndex].id // \"unknown\")
if ($result.ruleIndex != null and (($run.tool.driver.rules? // null) | type) == "array") then
($run.tool.driver.rules[$result.ruleIndex].id // "unknown")
else
\"unknown\"
"unknown"
end
)
)) | package: \((
($result.message.text // \"\")
| (try capture(\"(?i)(?:Package|PkgName|Pkg|Library)\\\\s*[:=]\\\\s*`?(?<pkg>[A-Za-z0-9._+:+-]+)`?\").pkg catch \"n/a\")
($result.message.text // "")
| (try capture("(?i)(?:Package|PkgName|Pkg|Library)\\s*[:=]\\s*`?(?<pkg>[A-Za-z0-9._+:/-]+)`?").pkg catch "n/a")
))"
' "${SARIF_PATH}"; then
echo "- unable to render parsed findings"
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/e2e-tests-split.yml
Original file line number Diff line number Diff line change
Expand Up @@ -83,7 +83,7 @@ on:

env:
NODE_VERSION: '24.19.0'
GO_VERSION: '1.26.5'
GO_VERSION: '1.26.6'
GOTOOLCHAIN: local
DOCKERHUB_REGISTRY: docker.io
IMAGE_NAME: ${{ github.repository_owner }}/charon
Expand Down
22 changes: 10 additions & 12 deletions .github/workflows/nightly-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -15,7 +15,7 @@ on:
default: "false"

env:
GO_VERSION: '1.26.5'
GO_VERSION: '1.26.6'
NODE_VERSION: '24.19.0'
GOTOOLCHAIN: local
GHCR_REGISTRY: ghcr.io
Expand Down Expand Up @@ -285,9 +285,9 @@ jobs:
uses: anchore/sbom-action@e22c389904149dbc22b58101806040fa8d37a610 # v0.24.0
with:
image: ${{ env.GHCR_REGISTRY }}/${{ env.IMAGE_NAME }}@${{ steps.resolve_digest.outputs.digest }}
format: cyclonedx-json
format: spdx-json
output-file: sbom-nightly.json
syft-version: v1.45.1
syft-version: v1.51.0

- name: Generate SBOM fallback with pinned Syft
if: always()
Expand All @@ -301,7 +301,7 @@ jobs:

echo "Primary SBOM generation failed or produced missing/invalid output; using deterministic Syft fallback"

SYFT_VERSION="v1.50.0"
SYFT_VERSION="v1.51.0"
OS="$(uname -s | tr '[:upper:]' '[:lower:]')"
ARCH="$(uname -m)"
case "$ARCH" in
Expand All @@ -327,7 +327,7 @@ jobs:
echo "::error::Digest from resolve_digest step is empty; the digest-resolution step did not complete successfully"
exit 1
fi
./syft "${{ env.GHCR_REGISTRY }}/${{ env.IMAGE_NAME }}@${DIGEST}" -o cyclonedx-json=sbom-nightly.json
./syft "${{ env.GHCR_REGISTRY }}/${{ env.IMAGE_NAME }}@${DIGEST}" -o spdx-json=sbom-nightly.json

- name: Verify SBOM artifact
if: always()
Expand All @@ -336,11 +336,9 @@ jobs:
test -s sbom-nightly.json
jq -e . sbom-nightly.json >/dev/null
jq -e '
.bomFormat == "CycloneDX"
and (.specVersion | type == "string" and length > 0)
and has("version")
and has("metadata")
and (.components | type == "array")
(.spdxVersion | type == "string" and length > 0)
and has("SPDXID")
and (.packages | type == "array")
' sbom-nightly.json >/dev/null

- name: Upload SBOM artifact
Expand Down Expand Up @@ -614,11 +612,11 @@ jobs:
image-ref: ${{ env.GHCR_REGISTRY }}/${{ env.IMAGE_NAME }}:nightly@${{ needs.build-and-push-nightly.outputs.digest }}
format: 'sarif'
output: 'trivy-nightly.sarif'
version: 'v0.73.0'
version: 'v0.74.0'
trivyignores: '.trivyignore'

- name: Upload Trivy results
uses: github/codeql-action/upload-sarif@5595ccaf912efad79be6eef63a5619ff05969be3 # v4.37.6
uses: github/codeql-action/upload-sarif@ff2f1c621b7f889edc0d3c761ac2e6a3f8cdb0dd # v4.37.7
with:
sarif_file: 'trivy-nightly.sarif'
category: 'trivy-nightly'
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/orthrus-build.yml
Original file line number Diff line number Diff line change
Expand Up @@ -29,7 +29,7 @@ env:
GHCR_REGISTRY: ghcr.io
DOCKERHUB_REGISTRY: docker.io
IMAGE_NAME: wikid82/orthrus
GO_VERSION: '1.26.5'
GO_VERSION: '1.26.6'

permissions:
contents: read
Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/quality-checks.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ permissions:
checks: write

env:
GO_VERSION: '1.26.5'
GO_VERSION: '1.26.6'
NODE_VERSION: '24.19.0'
GOTOOLCHAIN: local

Expand Down
2 changes: 1 addition & 1 deletion .github/workflows/renovate.yml
Original file line number Diff line number Diff line change
Expand Up @@ -16,7 +16,7 @@ permissions:
issues: write

env:
GO_VERSION: '1.26.5'
GO_VERSION: '1.26.6'

jobs:
renovate:
Expand Down
Loading
Loading