diff --git a/.github/workflows/docker.yml b/.github/workflows/docker.yml index 9257b26fc50..a1b436e3fae 100644 --- a/.github/workflows/docker.yml +++ b/.github/workflows/docker.yml @@ -104,7 +104,7 @@ jobs: # Scan for vulnerabilities in built container image after pushes to mainline branch. - name: Run Trivy container image vulnerabity scan if: github.event_name == 'push' && github.ref == 'refs/heads/master' && (steps.check.outputs.python || steps.check.outputs.frontend || steps.check.outputs.docker) && matrix.build_preset == 'lean' - uses: aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # v0.33.1 + uses: aquasecurity/trivy-action@c1824fd6edce30d7ab345a9989de00bbd46ef284 # v0.34.0 with: image-ref: ${{ env.IMAGE_TAG }} format: 'sarif'