@@ -39,12 +39,12 @@ jobs:
3939 go-version-file : " go.mod"
4040
4141 - name : Initialize CodeQL
42- uses : github/codeql-action/init@19b2f06db2b6f5108140aeb04014ef02b648f789 # v4.31.11
42+ uses : github/codeql-action/init@c793b717bc78562f491db7b0e93a3a178b099162 # v4.32.5
4343 with :
4444 languages : go
4545
4646 - name : Perform CodeQL Analysis
47- uses : github/codeql-action/analyze@19b2f06db2b6f5108140aeb04014ef02b648f789 # v4.31.11
47+ uses : github/codeql-action/analyze@c793b717bc78562f491db7b0e93a3a178b099162 # v4.32.5
4848 with :
4949 category : " /language:go"
5050
@@ -82,28 +82,28 @@ jobs:
8282 echo "image=code-marketplace:scan" >> "$GITHUB_OUTPUT"
8383
8484 - name : Run Trivy vulnerability scanner (table output for logs)
85- uses : aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # v0.33.1
85+ uses : aquasecurity/trivy-action@97e0b3872f55f89b95b2f65b3dbab56962816478 # v0.34.2
8686 with :
8787 image-ref : ${{ steps.build.outputs.image }}
8888 format : " table"
8989 severity : " LOW,MEDIUM,HIGH,CRITICAL"
9090
9191 - name : Run Trivy vulnerability scanner (SARIF output for GitHub)
92- uses : aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # v0.33.1
92+ uses : aquasecurity/trivy-action@97e0b3872f55f89b95b2f65b3dbab56962816478 # v0.34.2
9393 with :
9494 image-ref : ${{ steps.build.outputs.image }}
9595 format : " sarif"
9696 output : " trivy-results.sarif"
9797 severity : " LOW,MEDIUM,HIGH,CRITICAL"
9898
9999 - name : Upload Trivy scan results to GitHub Security tab
100- uses : github/codeql-action/upload-sarif@19b2f06db2b6f5108140aeb04014ef02b648f789 # v4.31.11
100+ uses : github/codeql-action/upload-sarif@c793b717bc78562f491db7b0e93a3a178b099162 # v4.32.5
101101 with :
102102 sarif_file : " trivy-results.sarif"
103103 category : " Trivy"
104104
105105 - name : Upload Trivy scan results as artifact
106- uses : actions/upload-artifact@b7c566a772e6b6bfb58ed0dc250532a479d7789f # v6 .0.0
106+ uses : actions/upload-artifact@bbbca2ddaa5d8feaa63e36b76fdaad77386f024f # v7 .0.0
107107 with :
108108 name : trivy-results
109109 path : trivy-results.sarif
0 commit comments