Merge pull request #18000 from etcd-io/dependabot/github_actions/aquasecurity/trivy-action-0.20.0

build(deps): bump aquasecurity/trivy-action from 0.19.0 to 0.20.0
This commit is contained in:
James Blair 2024-05-14 06:42:13 +12:00 committed by GitHub
commit dbd1e40e19
No known key found for this signature in database
GPG Key ID: B5690EEEBB952194

View File

@ -60,7 +60,7 @@ jobs:
run: |
docker load < /tmp/etcd-img.tar
- name: trivy-scan
uses: aquasecurity/trivy-action@d710430a6722f083d3b36b8339ff66b32f22ee55 # v0.19.0
uses: aquasecurity/trivy-action@b2933f565dbc598b29947660e66259e3c7bc8561 # v0.20.0
with:
image-ref: 'gcr.io/etcd-development/etcd:v3.6.99-${{ matrix.platforms }}'
severity: 'CRITICAL,HIGH'