From 9db74e920b64e59d85a89a1698e95242e5194574 Mon Sep 17 00:00:00 2001 From: "we-renovate[bot]" <162337394+we-renovate[bot]@users.noreply.github.com> Date: Mon, 9 Dec 2024 07:33:10 +0000 Subject: [PATCH] fix(deps): update wetransform/gha-trivy action to v2.3.3 --- .github/workflows/dockerfile.yml | 2 +- .github/workflows/gradle-library.yml | 2 +- .github/workflows/gradle-service.yml | 6 +++--- .github/workflows/play-service.yml | 2 +- .github/workflows/scan-images.yml | 4 ++-- 5 files changed, 8 insertions(+), 8 deletions(-) diff --git a/.github/workflows/dockerfile.yml b/.github/workflows/dockerfile.yml index 1e75c8c..f2519f1 100644 --- a/.github/workflows/dockerfile.yml +++ b/.github/workflows/dockerfile.yml @@ -62,7 +62,7 @@ jobs: labels: ${{ steps.meta.outputs.labels }} - name: Vulnerability check - uses: wetransform/gha-trivy@b8d2a2bcd7930fd3ce380c930bfd772d8f236112 # v2.3.2 + uses: wetransform/gha-trivy@8d25c5cf8d4016470d9a8d43d0398b5c9a1c8a09 # v2.3.3 with: image-ref: "${{ inputs.image }}:${{ inputs.tag }}" create-test-report: true diff --git a/.github/workflows/gradle-library.yml b/.github/workflows/gradle-library.yml index e899081..33f22ff 100644 --- a/.github/workflows/gradle-library.yml +++ b/.github/workflows/gradle-library.yml @@ -199,7 +199,7 @@ jobs: - name: Vulnerability scan if: ${{ !inputs.skip-scan }} - uses: wetransform/gha-trivy@b8d2a2bcd7930fd3ce380c930bfd772d8f236112 # v2.3.2 + uses: wetransform/gha-trivy@8d25c5cf8d4016470d9a8d43d0398b5c9a1c8a09 # v2.3.3 with: junit-test-output: "${{ inputs.multi-module && 'trivy-gha-scan/build/test-results/trivy.xml' || 'build/test-results/trivy.xml' }}" # added to unit test report report-retention-days: 30 diff --git a/.github/workflows/gradle-service.yml b/.github/workflows/gradle-service.yml index 1c5a4d3..6c51fed 100644 --- a/.github/workflows/gradle-service.yml +++ b/.github/workflows/gradle-service.yml @@ -219,7 +219,7 @@ jobs: - name: Vulnerability scan if: ${{ !inputs.skip-scan }} - uses: wetransform/gha-trivy@b8d2a2bcd7930fd3ce380c930bfd772d8f236112 # v2.3.2 + uses: wetransform/gha-trivy@8d25c5cf8d4016470d9a8d43d0398b5c9a1c8a09 # v2.3.3 with: image-ref: 'docker.io/${{ inputs.image-tag }}' junit-test-output: "${{ inputs.multi-module && 'trivy-gha-scan/build/test-results/trivy.xml' || 'build/test-results/trivy.xml' }}" # added to unit test report @@ -227,7 +227,7 @@ jobs: report-tag: ${{ inputs.image-tag }} - name: Vulnerability scan (Image 2) - uses: wetransform/gha-trivy@b8d2a2bcd7930fd3ce380c930bfd772d8f236112 # v2.3.2 + uses: wetransform/gha-trivy@8d25c5cf8d4016470d9a8d43d0398b5c9a1c8a09 # v2.3.3 if: ${{ !inputs.skip-scan && inputs.image-tag-2 != '' }} with: image-ref: 'docker.io/${{ inputs.image-tag-2 }}' @@ -236,7 +236,7 @@ jobs: report-tag: ${{ inputs.image-tag-2 }} - name: Vulnerability scan (Image 3) - uses: wetransform/gha-trivy@b8d2a2bcd7930fd3ce380c930bfd772d8f236112 # v2.3.2 + uses: wetransform/gha-trivy@8d25c5cf8d4016470d9a8d43d0398b5c9a1c8a09 # v2.3.3 if: ${{ !inputs.skip-scan && inputs.image-tag-3 != '' }} with: image-ref: 'docker.io/${{ inputs.image-tag-3 }}' diff --git a/.github/workflows/play-service.yml b/.github/workflows/play-service.yml index 9864207..d921c19 100644 --- a/.github/workflows/play-service.yml +++ b/.github/workflows/play-service.yml @@ -98,7 +98,7 @@ jobs: run: mkdir -p ${{ inputs.junit-test-folder }} - name: Vulnerability scan - uses: wetransform/gha-trivy@b8d2a2bcd7930fd3ce380c930bfd772d8f236112 # v2.3.2 + uses: wetransform/gha-trivy@8d25c5cf8d4016470d9a8d43d0398b5c9a1c8a09 # v2.3.3 with: image-ref: 'docker.io/${{ inputs.image-tag }}' junit-test-output: "${{ inputs.junit-test-folder }}/trivy.xml" # added to unit test report diff --git a/.github/workflows/scan-images.yml b/.github/workflows/scan-images.yml index 9152de7..8bb0b45 100644 --- a/.github/workflows/scan-images.yml +++ b/.github/workflows/scan-images.yml @@ -86,7 +86,7 @@ jobs: docker pull ${{ matrix.image }} - name: Vulnerability scan - uses: wetransform/gha-trivy@b8d2a2bcd7930fd3ce380c930bfd772d8f236112 # v2.3.2 + uses: wetransform/gha-trivy@8d25c5cf8d4016470d9a8d43d0398b5c9a1c8a09 # v2.3.3 with: image-ref: ${{ matrix.image }} create-test-report: ${{ inputs.create-test-report }} @@ -176,7 +176,7 @@ jobs: # Scan merged SBOM for an overview, but trivy fails for mixed OS dependencies, so disabled by default - name: Scan merged SBOM if: ${{ inputs.merge-sboms && inputs.scan-merged-sbom }} - uses: wetransform/gha-trivy@b8d2a2bcd7930fd3ce380c930bfd772d8f236112 # v2.3.2 + uses: wetransform/gha-trivy@8d25c5cf8d4016470d9a8d43d0398b5c9a1c8a09 # v2.3.3 with: scan-ref: merged/sbom.json create-test-report: false