Skip to content

Commit fc0d123

Browse files
PenguinzTechclaude
andcommitted
security: pin trivy-action to v0.35.0 (supply chain fix)
Trivy ecosystem supply chain attack (GHSA-69fq-xp46-6x23, March 19-20 2026): - aquasecurity/trivy-action @master and v0.0.1-v0.34.0 force-pushed with malware - Pinning to clean aquasecurity/trivy-action@v0.35.0 (uses trivy v0.69.3) Co-Authored-By: Claude Sonnet 4.6 <noreply@anthropic.com>
1 parent 42cfaa1 commit fc0d123

4 files changed

Lines changed: 5 additions & 5 deletions

File tree

.github/workflows/build-and-test.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -305,7 +305,7 @@ jobs:
305305
uses: actions/checkout@v4
306306

307307
- name: Run Trivy vulnerability scanner
308-
uses: aquasecurity/trivy-action@master
308+
uses: aquasecurity/trivy-action@v0.35.0
309309
with:
310310
scan-type: 'fs'
311311
scan-ref: '.'

.github/workflows/ci.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -93,7 +93,7 @@ jobs:
9393
uses: actions/checkout@v4
9494

9595
- name: Run Trivy vulnerability scanner
96-
uses: aquasecurity/trivy-action@master
96+
uses: aquasecurity/trivy-action@v0.35.0
9797
with:
9898
scan-type: 'fs'
9999
scan-ref: '.'

.github/workflows/modular-lb-ci.yml

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -269,7 +269,7 @@ jobs:
269269
- uses: actions/checkout@v4
270270

271271
- name: Run Trivy vulnerability scanner
272-
uses: aquasecurity/trivy-action@master
272+
uses: aquasecurity/trivy-action@v0.35.0
273273
with:
274274
scan-type: 'fs'
275275
scan-ref: '.'

.github/workflows/security.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -104,14 +104,14 @@ jobs:
104104
docker build -t marchproxy/proxy:scan --target proxy .
105105
106106
- name: Run Trivy container scan - Manager
107-
uses: aquasecurity/trivy-action@master
107+
uses: aquasecurity/trivy-action@v0.35.0
108108
with:
109109
image-ref: 'marchproxy/manager:scan'
110110
format: 'sarif'
111111
output: 'trivy-manager-results.sarif'
112112

113113
- name: Run Trivy container scan - Proxy
114-
uses: aquasecurity/trivy-action@master
114+
uses: aquasecurity/trivy-action@v0.35.0
115115
with:
116116
image-ref: 'marchproxy/proxy:scan'
117117
format: 'sarif'

0 commit comments

Comments
 (0)