Merge pull request #18151 from etcd-io/dependabot/github_actions/aquasecurity/trivy-action-0.22.0

build(deps): bump aquasecurity/trivy-action from 0.21.0 to 0.22.0
This commit is contained in:
James Blair 2024-06-11 20:19:56 +12:00 committed by GitHub
commit 4f9808d9a7
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -60,7 +60,7 @@ jobs:
run: |
docker load < /tmp/etcd-img.tar
- name: trivy-scan
uses: aquasecurity/trivy-action@fd25fed6972e341ff0007ddb61f77e88103953c2 # v0.21.0
uses: aquasecurity/trivy-action@595be6a0f6560a0a8fc419ddf630567fc623531d # v0.22.0
with:
image-ref: 'gcr.io/etcd-development/etcd:v3.6.99-${{ matrix.platforms }}'
severity: 'CRITICAL,HIGH'