Skip to content

Update Trivy action to a specific commit version#76

Merged
waskow-consensys merged 1 commit into
masterfrom
chore/trivy-patch-1
Mar 23, 2026
Merged

Update Trivy action to a specific commit version#76
waskow-consensys merged 1 commit into
masterfrom
chore/trivy-patch-1

Conversation

@BGos87

@BGos87 BGos87 commented Mar 23, 2026

Copy link
Copy Markdown
Contributor

Note

Low Risk
Low risk workflow-only change that pins the Trivy action to an exact commit to improve supply-chain reproducibility. Main risk is the pinned revision could behave differently than @master, potentially affecting CI scan results or failures.

Overview
Pins the CI Trivy scan step from aquasecurity/trivy-action@master to a specific commit SHA, making the vulnerability scanning workflow deterministic and less susceptible to upstream changes.

Written by Cursor Bugbot for commit 8c2b480. This will update automatically on new commits. Configure here.

@waskow-consensys waskow-consensys merged commit cbd7444 into master Mar 23, 2026
3 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants