diff --git a/.github/workflows/docker-build-push.yml b/.github/workflows/docker-build-push.yml index 47a8019e..62703074 100644 --- a/.github/workflows/docker-build-push.yml +++ b/.github/workflows/docker-build-push.yml @@ -81,7 +81,7 @@ jobs: sed -i 's/\\u0026#39;/\x27/g' scan-results/trivy-${{ inputs.variant }}-image-scan-low.sarif - name: Upload Trivy low severity cases scan results to GitHub Security - uses: github/codeql-action/upload-sarif@v3.27.5 + uses: github/codeql-action/upload-sarif@v3.27.6 with: sarif_file: scan-results/trivy-${{ inputs.variant }}-image-scan-low.sarif category: ${{ inputs.variant }}-image-scan-low-cases @@ -109,7 +109,7 @@ jobs: sed -i 's/\\u0026#39;/\x27/g' scan-results/trivy-${{ inputs.variant }}-image-scan.sarif - name: Upload Trivy scan results to GitHub Security - uses: github/codeql-action/upload-sarif@v3.27.5 + uses: github/codeql-action/upload-sarif@v3.27.6 if: always() with: # Path to SARIF file relative to the root of the repository diff --git a/.github/workflows/hadolint.yml b/.github/workflows/hadolint.yml index 4ad3000e..ab067a8a 100644 --- a/.github/workflows/hadolint.yml +++ b/.github/workflows/hadolint.yml @@ -28,7 +28,7 @@ jobs: output-file: ${{ inputs.dockerfile }}.sarif - name: Upload Hadolint results of ${{ inputs.dockerfile }} - uses: github/codeql-action/upload-sarif@v3.27.5 + uses: github/codeql-action/upload-sarif@v3.27.6 with: # Path to SARIF file relative to the root of the repository sarif_file: ${{ inputs.dockerfile }}.sarif diff --git a/.github/workflows/pr.yml b/.github/workflows/pr.yml index 067e8289..eddbb3e2 100644 --- a/.github/workflows/pr.yml +++ b/.github/workflows/pr.yml @@ -68,7 +68,7 @@ jobs: sed -i 's/\\u0026#39;/\x27/g' scan-results/trivy-${{ inputs.variant }}-image-scan-low.sarif - name: Upload Trivy low severity cases scan results to GitHub Security - uses: github/codeql-action/upload-sarif@v3.27.5 + uses: github/codeql-action/upload-sarif@v3.27.6 with: sarif_file: scan-results/trivy-${{ inputs.variant }}-image-scan-low.sarif category: ${{ inputs.variant }}-image-scan-low-cases @@ -96,7 +96,7 @@ jobs: sed -i 's/\\u0026#39;/\x27/g' scan-results/trivy-${{ inputs.variant }}-image-scan.sarif - name: Upload Trivy scan results to GitHub Security - uses: github/codeql-action/upload-sarif@v3.27.5 + uses: github/codeql-action/upload-sarif@v3.27.6 if: always() with: # Path to SARIF file relative to the root of the repository diff --git a/.github/workflows/trivy.yml b/.github/workflows/trivy.yml index acdd7c14..75a8490f 100644 --- a/.github/workflows/trivy.yml +++ b/.github/workflows/trivy.yml @@ -34,7 +34,7 @@ jobs: TRIVY_DB_REPOSITORY: public.ecr.aws/aquasecurity/trivy-db,aquasec/trivy-db,ghcr.io/aquasecurity/trivy-db - name: Upload Trivy scan results to GitHub Security - uses: github/codeql-action/upload-sarif@v3.27.5 + uses: github/codeql-action/upload-sarif@v3.27.6 with: # Path to SARIF file relative to the root of the repository sarif_file: trivy-repository-scan.sarif