diff --git a/.github/workflows/component-scan.yml b/.github/workflows/component-scan.yml index 12e5a833..98aa08f1 100644 --- a/.github/workflows/component-scan.yml +++ b/.github/workflows/component-scan.yml @@ -24,7 +24,7 @@ jobs: - name: Scan all the vulnerabilities and generate JSON report if: always() - uses: aquasecurity/trivy-action@0.27.0 + uses: aquasecurity/trivy-action@0.28.0 with: image-ref: image:latest format: 'json' @@ -33,7 +33,7 @@ jobs: - name: Save vulnerabilities report in tabular format if: always() - uses: aquasecurity/trivy-action@0.27.0 + uses: aquasecurity/trivy-action@0.28.0 with: image-ref: trivy-results.json scan-type: convert @@ -43,7 +43,7 @@ jobs: - name: Display vulnerabilities report if: always() - uses: aquasecurity/trivy-action@0.27.0 + uses: aquasecurity/trivy-action@0.28.0 with: image-ref: trivy-results.json scan-type: convert @@ -51,7 +51,7 @@ jobs: - name: Fail on high and critical vulnerabilities if: always() - uses: aquasecurity/trivy-action@0.27.0 + uses: aquasecurity/trivy-action@0.28.0 with: image-ref: trivy-results.json scan-type: convert