diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 680e505..ddd7441 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -27,7 +27,7 @@ jobs: run: docker build -t evershelf:scan . - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@0.31.0 + uses: aquasecurity/trivy-action@v0.36.0 with: image-ref: 'evershelf:scan' format: 'sarif' @@ -53,7 +53,7 @@ jobs: uses: actions/checkout@v4 - name: Run Trivy filesystem scanner - uses: aquasecurity/trivy-action@0.31.0 + uses: aquasecurity/trivy-action@v0.36.0 with: scan-type: 'fs' scan-ref: '.'