diff --git a/.github/workflows/pr-operator.yml b/.github/workflows/pr-operator.yml index 60dd972..7fe0878 100644 --- a/.github/workflows/pr-operator.yml +++ b/.github/workflows/pr-operator.yml @@ -282,7 +282,7 @@ jobs: load: true - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # 0.35.0 + uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # 0.36.0 with: scan-type: image image-ref: ${{ env.OPERATOR_IMAGE_REPOSITORY }}:latest-${{ steps.setup-build-step.outputs.platform_os }}-${{ steps.setup-build-step.outputs.platform_arch }} @@ -290,7 +290,7 @@ jobs: output: "operator-${{ steps.setup-build-step.outputs.platform_os }}-${{ steps.setup-build-step.outputs.platform_arch }}-cosignvuln.json" - name: Run Trivy SBOM generator - uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # 0.35.0 + uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # 0.36.0 with: scan-type: image image-ref: ${{ env.OPERATOR_IMAGE_REPOSITORY }}:latest-${{ steps.setup-build-step.outputs.platform_os }}-${{ steps.setup-build-step.outputs.platform_arch }} @@ -411,7 +411,7 @@ jobs: load: true - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # 0.35.0 + uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # 0.36.0 with: scan-type: image image-ref: ${{ env.BUNDLE_IMAGE_REPOSITORY }}:latest-${{ steps.setup-build-step.outputs.platform_os }}-${{ steps.setup-build-step.outputs.platform_arch }} @@ -419,7 +419,7 @@ jobs: output: "bundle-${{ steps.setup-build-step.outputs.platform_os }}-${{ steps.setup-build-step.outputs.platform_arch }}-cosignvuln.json" - name: Run Trivy SBOM generator - uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # 0.35.0 + uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # 0.36.0 with: scan-type: image image-ref: ${{ env.BUNDLE_IMAGE_REPOSITORY }}:latest-${{ steps.setup-build-step.outputs.platform_os }}-${{ steps.setup-build-step.outputs.platform_arch }} diff --git a/.github/workflows/release-operator.yml b/.github/workflows/release-operator.yml index da596ad..bcbf9ed 100644 --- a/.github/workflows/release-operator.yml +++ b/.github/workflows/release-operator.yml @@ -344,7 +344,7 @@ jobs: cosign sign --yes ${IMAGE_URI} - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # 0.35.0 + uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # 0.36.0 env: TRIVY_USERNAME: ${{ secrets.REGISTRY_USERNAME }} TRIVY_PASSWORD: ${{ secrets.REGISTRY_PASSWORD }} @@ -355,7 +355,7 @@ jobs: output: "cosign-vuln.json" - name: Run Trivy SBOM generator - uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # 0.35.0 + uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # 0.36.0 env: TRIVY_USERNAME: ${{ secrets.REGISTRY_USERNAME }} TRIVY_PASSWORD: ${{ secrets.REGISTRY_PASSWORD }} @@ -576,7 +576,7 @@ jobs: cosign sign --yes ${IMAGE_URI} - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # 0.35.0 + uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # 0.36.0 env: TRIVY_USERNAME: ${{ secrets.REGISTRY_USERNAME }} TRIVY_PASSWORD: ${{ secrets.REGISTRY_PASSWORD }} @@ -587,7 +587,7 @@ jobs: output: "cosign-vuln.json" - name: Run Trivy SBOM generator - uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # 0.35.0 + uses: aquasecurity/trivy-action@ed142fd0673e97e23eac54620cfb913e5ce36c25 # 0.36.0 env: TRIVY_USERNAME: ${{ secrets.REGISTRY_USERNAME }} TRIVY_PASSWORD: ${{ secrets.REGISTRY_PASSWORD }}