diff --git a/.github/workflows/trivy.yml b/.github/workflows/trivy.yml index 76ff2fb..7b8b8be 100644 --- a/.github/workflows/trivy.yml +++ b/.github/workflows/trivy.yml @@ -17,7 +17,7 @@ jobs: docker build -t docker.io/my-organization/my-app:${{ github.sha }} . - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@0.28.0 + uses: aquasecurity/trivy-action@915b19bbe73b92a6cf82a1bc12b087c9a19a5fe2 # 0.28.0 with: image-ref: 'docker.io/my-organization/my-app:${{ github.sha }}' format: 'sarif'