From f8f92145e5b2617a4950db40d27488cb5ee294f9 Mon Sep 17 00:00:00 2001 From: "dependabot[bot]" <49699333+dependabot[bot]@users.noreply.github.com> Date: Thu, 12 Mar 2026 11:55:07 +0000 Subject: [PATCH] Upgrade: [dependabot] - bump aquasecurity/trivy-action Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) from 0.34.2 to 0.35.0. - [Release notes](https://github.com/aquasecurity/trivy-action/releases) - [Commits](https://github.com/aquasecurity/trivy-action/compare/97e0b3872f55f89b95b2f65b3dbab56962816478...57a97c7e7821a5776cebc9bb87c984fa69cba8f1) --- updated-dependencies: - dependency-name: aquasecurity/trivy-action dependency-version: 0.35.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] --- .github/workflows/quality-checks.yml | 14 +++++++------- 1 file changed, 7 insertions(+), 7 deletions(-) diff --git a/.github/workflows/quality-checks.yml b/.github/workflows/quality-checks.yml index c4d4fdf..2d0f0c5 100644 --- a/.github/workflows/quality-checks.yml +++ b/.github/workflows/quality-checks.yml @@ -204,7 +204,7 @@ jobs: cd src go mod vendor - name: Check licenses - uses: aquasecurity/trivy-action@97e0b3872f55f89b95b2f65b3dbab56962816478 + uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 with: scan-type: "fs" scan-ref: "." @@ -247,7 +247,7 @@ jobs: - name: Run unit tests run: make test - name: Generate SBOM - uses: aquasecurity/trivy-action@97e0b3872f55f89b95b2f65b3dbab56962816478 + uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 with: scan-type: "fs" scan-ref: "." @@ -264,7 +264,7 @@ jobs: - name: Check python vulnerabilities if: ${{ always() && steps.check_languages.outputs.uses_poetry == 'true'}} - uses: aquasecurity/trivy-action@97e0b3872f55f89b95b2f65b3dbab56962816478 + uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 with: scan-type: "fs" skip-files: "**/package-lock.json,**/go.mod,**/pom.xml" @@ -277,7 +277,7 @@ jobs: trivy-config: trivy.yaml - name: Check node vulnerabilities if: ${{ always() && steps.check_languages.outputs.uses_node == 'true' }} - uses: aquasecurity/trivy-action@97e0b3872f55f89b95b2f65b3dbab56962816478 + uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 with: scan-type: "fs" skip-files: "**/poetry.lock,**/go.mod,**/pom.xml" @@ -290,7 +290,7 @@ jobs: trivy-config: trivy.yaml - name: Check go vulnerabilities if: ${{ always() && steps.check_languages.outputs.uses_go == 'true' }} - uses: aquasecurity/trivy-action@97e0b3872f55f89b95b2f65b3dbab56962816478 + uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 with: scan-type: "fs" skip-files: "**/poetry.lock,**/package-lock.json,**/pom.xml" @@ -302,7 +302,7 @@ jobs: exit-code: "1" - name: Check java vulnerabilities if: ${{ always() && steps.check_languages.outputs.uses_java == 'true' }} - uses: aquasecurity/trivy-action@97e0b3872f55f89b95b2f65b3dbab56962816478 + uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 with: scan-type: "fs" skip-files: "**/poetry.lock,**/package-lock.json,**/go.mod" @@ -486,7 +486,7 @@ jobs: make docker-build - name: Check docker vulnerabilities - uses: aquasecurity/trivy-action@97e0b3872f55f89b95b2f65b3dbab56962816478 + uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 with: scan-type: "image" image-ref: ${{ matrix.docker_image }}