@@ -130,7 +130,7 @@ jobs:
130130
131131 - name : Install cosign
132132 if : github.event_name != 'pull_request'
133- uses : sigstore/cosign-installer@f713795cb21599bc4e5c4b58cbad1da852d7eeb9 # v3
133+ uses : sigstore/cosign-installer@398d4b0eeef1380460a10c8013a76f728fb906ac # v3
134134
135135 - name : Sign frontend image
136136 if : github.event_name != 'pull_request'
@@ -162,7 +162,7 @@ jobs:
162162
163163 - name : Comment on PR if cosign verify failed
164164 if : failure() && github.event_name == 'pull_request'
165- uses : actions/github-script@f28e40c7f34bde8b3046d885e986cb6290c5673b # v7
165+ uses : actions/github-script@3a2844b7e9c422d3c10d287c895573f7108da1b3 # v9.0.0
166166 with :
167167 script : |
168168 await github.rest.issues.createComment({
@@ -174,7 +174,7 @@ jobs:
174174
175175 - name : Trivy scan frontend
176176 if : github.event_name != 'pull_request'
177- uses : aquasecurity/trivy-action@0.28 .0
177+ uses : aquasecurity/trivy-action@v0.36 .0
178178 continue-on-error : true
179179 with :
180180 image-ref : ghcr.io/${{ env.NAMESPACE }}/${{ env.FRONTEND_IMAGE_NAME }}@${{ steps.build-frontend.outputs.digest }}
@@ -185,7 +185,7 @@ jobs:
185185
186186 - name : Trivy scan backend
187187 if : github.event_name != 'pull_request'
188- uses : aquasecurity/trivy-action@0.28 .0
188+ uses : aquasecurity/trivy-action@v0.36 .0
189189 continue-on-error : true
190190 with :
191191 image-ref : ghcr.io/${{ env.NAMESPACE }}/${{ env.BACKEND_IMAGE_NAME }}@${{ steps.build-backend.outputs.digest }}
0 commit comments