uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0.35.0
Across our 5 Kubernetes orgs (kubernetes, kubernetes-sigs, kubernetes-csi, kubernetes-client, etcd-io), the following repos are using trivy scanner in github action workflows.
This is a tracking issue for the security update of
aquasecurity/trivy-actionacross Kubernetes organization repositories.Ref: aquasecurity/trivy#10425
Recommended fix: update all references to use SHA-pinned version:
ref: https://cs.k8s.io/?q=(trivy-action%7Csetup-trivy)%40(v0%7Cmaster)&i=nope&literal=nope&files=.github%2Fworkflows%2F*&excludeFiles=&repos=
Across our 5 Kubernetes orgs (kubernetes, kubernetes-sigs, kubernetes-csi, kubernetes-client, etcd-io), the following repos are using trivy scanner in github action workflows.
Among them, following two already use SHA-pinned trivy-action:
And rest of the following need to be updated:
Please note - below repos need a git submodule update once the respective PR for
release-toolsrepo is merged kubernetes-csi/csi-release-tools#295