Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Pin trivy scanner to v0.0.21 #2137

Merged
merged 1 commit into from Nov 1, 2021
Merged

Pin trivy scanner to v0.0.21 #2137

merged 1 commit into from Nov 1, 2021

Conversation

ciarams87
Copy link
Member

@ciarams87 ciarams87 commented Oct 28, 2021

Proposed changes

All the known vulnerabilities are being reported in the security tab, even if they have no fixes, and it looks to be because of a change made in the trivy action to always report all vulnerabilities in the sarif file (see https://github.com/aquasecurity/trivy-action/pull/73/files).

Pinning the trivy scanner to the previous version resolves the issue.

@github-actions github-actions bot added the chore Pull requests for routine tasks label Oct 28, 2021
@ciarams87 ciarams87 changed the title Test: Pin trivy scanner to v0.0.21 Pin trivy scanner to v0.0.21 Oct 28, 2021
@ciarams87 ciarams87 merged commit efbd962 into master Nov 1, 2021
@ciarams87 ciarams87 deleted the chore/pin-trivy-scanner branch November 1, 2021 11:10
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
chore Pull requests for routine tasks
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants