Merge pull request #18331 from etcd-io/dependabot/github_actions/aquasecurity/trivy-action-0.24.0

build(deps): bump aquasecurity/trivy-action from 0.23.0 to 0.24.0
This commit is contained in:
James Blair 2024-07-16 08:33:14 +12:00 committed by GitHub
commit 6158097ad4
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -60,7 +60,7 @@ jobs:
run: |
docker load < /tmp/etcd-img.tar
- name: trivy-scan
uses: aquasecurity/trivy-action@7c2007bcb556501da015201bcba5aa14069b74e2 # v0.23.0
uses: aquasecurity/trivy-action@6e7b7d1fd3e4fef0c5fa8cce1229c54b2c9bd0d8 # v0.24.0
with:
image-ref: 'gcr.io/etcd-development/etcd:v3.6.99-${{ matrix.platforms }}'
severity: 'CRITICAL,HIGH'