Commit 814fe5e
committed
fix: update trivy-action to v0.35.0 (post-compromise safe SHA) and pin trivy v0.69.3
The v0.33.1 SHA (b6643a29) was in the compromised range from the
March 19 supply chain attack. Updated to v0.35.0 (57a97c7e) which
is the verified safe release. Pinned trivy binary to v0.69.3 to
avoid 'missing release artifacts' failures on auto-detected versions.1 parent 798ae44 commit 814fe5e
1 file changed
Lines changed: 4 additions & 2 deletions
| Original file line number | Diff line number | Diff line change | |
|---|---|---|---|
| |||
168 | 168 | | |
169 | 169 | | |
170 | 170 | | |
171 | | - | |
| 171 | + | |
172 | 172 | | |
173 | 173 | | |
174 | 174 | | |
175 | 175 | | |
176 | 176 | | |
177 | 177 | | |
| 178 | + | |
178 | 179 | | |
179 | 180 | | |
180 | 181 | | |
181 | | - | |
| 182 | + | |
182 | 183 | | |
183 | 184 | | |
184 | 185 | | |
185 | 186 | | |
186 | 187 | | |
187 | 188 | | |
| 189 | + | |
188 | 190 | | |
189 | 191 | | |
190 | 192 | | |
| |||
0 commit comments