Pin aquasecurity/trivy-action version in workflows

This commit is contained in:
Théophile Diot 2024-01-03 12:14:11 +00:00
parent 2b0540f442
commit 9578179269
No known key found for this signature in database
GPG key ID: 248FEA4BAE400D06

View file

@ -115,7 +115,7 @@ jobs:
# Check OS vulnerabilities
- name: Check OS vulnerabilities
if: ${{ inputs.CACHE_SUFFIX != 'arm' }}
uses: aquasecurity/trivy-action@91713af97dc80187565512baba96e4364e983601 # master
uses: aquasecurity/trivy-action@d43c1f16c00cfd3978dde6c07f4bbcf9eb6993ca # v0.16.1
with:
vuln-type: os
skip-dirs: /root/.cargo