Skip to content

Bump trivy to v0.69.3 and trivy-action to v0.35.0#2335

Open
vrajpurohitNR wants to merge 2 commits intopixie-io:mainfrom
vrajpurohitNR:vijay/trivy_version_update
Open

Bump trivy to v0.69.3 and trivy-action to v0.35.0#2335
vrajpurohitNR wants to merge 2 commits intopixie-io:mainfrom
vrajpurohitNR:vijay/trivy_version_update

Conversation

@vrajpurohitNR
Copy link

Summary

Bumps aquasecurity/trivy-action from v0.29.0 to v0.35.0 in trivy_fs.yaml and explicitly pins trivy scanner version to 0.69.3 via the trivy-version input
Updates trivy download URL and SHA256 checksum in Chef attributes for Linux (v0.64.1 → v0.69.3)
Updates trivy download URL and SHA256 checksum in Chef attributes for macOS (v0.64.1 → v0.69.3)

@vrajpurohitNR vrajpurohitNR requested review from a team as code owners March 23, 2026 10:10
Signed-off-by: vrajpurohit <vrajpurohit@newrelic.com>
@vrajpurohitNR vrajpurohitNR force-pushed the vijay/trivy_version_update branch from 9e26217 to ad3b971 Compare March 23, 2026 10:13
Signed-off-by: vrajpurohit <vrajpurohit@newrelic.com>
steps:
- uses: actions/checkout@11bd71901bbe5b1630ceea73d27597364c9af683 # v4.2.2
- uses: aquasecurity/trivy-action@18f2510ee396bbf400402947b394f2dd8c87dbb0 # v0.29.0
- uses: aquasecurity/trivy-action@0.35.0
Copy link
Member

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

pin the hash here. pinning the sha is precisely what helps us protect against supply chain attacks that rewrite old tags.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants