File tree Expand file tree Collapse file tree 5 files changed +10
-10
lines changed Expand file tree Collapse file tree 5 files changed +10
-10
lines changed Original file line number Diff line number Diff line change @@ -29,11 +29,11 @@ jobs:
2929 sudo apt-get update
3030 sudo apt-get install -y libze1 libze-dev
3131 - name : Initialize CodeQL
32- uses : github/codeql-action/init@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3
32+ uses : github/codeql-action/init@2d92b76c45b91eb80fc44c74ce3fce0ee94e8f9d # v3
3333 with :
3434 languages : ' go'
3535
3636 - name : Perform CodeQL Analysis
37- uses : github/codeql-action/analyze@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3
37+ uses : github/codeql-action/analyze@2d92b76c45b91eb80fc44c74ce3fce0ee94e8f9d # v3
3838 with :
3939 category : " /language:go"
Original file line number Diff line number Diff line change 6969 run : |
7070 ORG=${{ inputs.registry }} TAG=${{ inputs.image_tag }} make ${IMAGE_NAME} BUILDER=docker
7171 - name : Trivy scan for image
72- uses : aquasecurity/trivy-action@dc5a429b52fcf669ce959baa2c2dd26090d2a6c4 # 0.32 .0
72+ uses : aquasecurity/trivy-action@f9424c10c36e288d5fa79bd3dfd1aeb2d6eae808 # 0.33 .0
7373 with :
7474 scan-type : image
7575 image-ref : ${{ inputs.registry }}/${{ matrix.image }}:${{ inputs.image_tag }}
Original file line number Diff line number Diff line change 2626 results_format : sarif
2727 publish_results : true
2828 - name : " Upload results to security"
29- uses : github/codeql-action/upload-sarif@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3
29+ uses : github/codeql-action/upload-sarif@2d92b76c45b91eb80fc44c74ce3fce0ee94e8f9d # v3
3030 with :
3131 sarif_file : results.sarif
Original file line number Diff line number Diff line change 3232 - name : Checkout
3333 uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v4
3434 - name : Run Trivy in config mode for deployments
35- uses : aquasecurity/trivy-action@dc5a429b52fcf669ce959baa2c2dd26090d2a6c4 # 0.32 .0
35+ uses : aquasecurity/trivy-action@f9424c10c36e288d5fa79bd3dfd1aeb2d6eae808 # 0.33 .0
3636 with :
3737 scan-type : config
3838 scan-ref : deployments/
5050 - name : Checkout
5151 uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v4
5252 - name : Run Trivy in config mode for dockerfiles
53- uses : aquasecurity/trivy-action@dc5a429b52fcf669ce959baa2c2dd26090d2a6c4 # 0.32 .0
53+ uses : aquasecurity/trivy-action@f9424c10c36e288d5fa79bd3dfd1aeb2d6eae808 # 0.33 .0
5454 with :
5555 scan-type : config
5656 scan-ref : build/docker/
6464 - name : Checkout
6565 uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v4
6666 - name : Run Trivy in fs mode
67- uses : aquasecurity/trivy-action@dc5a429b52fcf669ce959baa2c2dd26090d2a6c4 # 0.32 .0
67+ uses : aquasecurity/trivy-action@f9424c10c36e288d5fa79bd3dfd1aeb2d6eae808 # 0.33 .0
6868 with :
6969 scan-type : fs
7070 scan-ref : .
8181 - name : Checkout
8282 uses : actions/checkout@08c6903cd8c0fde910a37f88322edcfb5dd907a8 # v4
8383 - name : Run Trivy in fs mode
84- uses : aquasecurity/trivy-action@dc5a429b52fcf669ce959baa2c2dd26090d2a6c4 # 0.32 .0
84+ uses : aquasecurity/trivy-action@f9424c10c36e288d5fa79bd3dfd1aeb2d6eae808 # 0.33 .0
8585 with :
8686 scan-type : fs
8787 scan-ref : .
Original file line number Diff line number Diff line change 2222 - name : Run Trivy in fs mode
2323 # Don't fail in case of vulnerabilities, report them in the next step
2424 continue-on-error : true
25- uses : aquasecurity/trivy-action@dc5a429b52fcf669ce959baa2c2dd26090d2a6c4 # 0.32 .0
25+ uses : aquasecurity/trivy-action@f9424c10c36e288d5fa79bd3dfd1aeb2d6eae808 # 0.33 .0
2626 with :
2727 scan-type : fs
2828 scan-ref : .
3131 format : sarif
3232 output : trivy-report.sarif
3333 - name : Upload sarif report to GitHub Security tab
34- uses : github/codeql-action/upload-sarif@3c3833e0f8c1c83d449a7478aa59c036a9165498 # v3
34+ uses : github/codeql-action/upload-sarif@2d92b76c45b91eb80fc44c74ce3fce0ee94e8f9d # v3
3535 with :
3636 sarif_file : trivy-report.sarif
You can’t perform that action at this time.
0 commit comments