Skip to content

Pin trivy action to commit of 0.35.0 tag#257

Open
jnummelin wants to merge 1 commit intok0sproject:mainfrom
jnummelin:pin-trivy-to-sha-of-0.35.0
Open

Pin trivy action to commit of 0.35.0 tag#257
jnummelin wants to merge 1 commit intok0sproject:mainfrom
jnummelin:pin-trivy-to-sha-of-0.35.0

Conversation

@jnummelin
Copy link
Copy Markdown
Member

@jnummelin jnummelin commented Mar 22, 2026

Since the trivy action repo has been compromised and some (all?) tags rewritten, we need to pin to a direct commit so avoid such things leaking to our pipelines.

Since the repo has been compromised and some (all?) tags rewritten, we need to pin to a direct commit so avoid such things leaking to our pipelines.

Signed-off-by: Jussi Nummelin <jnummelin@mirantis.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant