diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 036c7adb..eff8ad6a 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -18,7 +18,7 @@ jobs: uses: actions/checkout@v3 - name: Run Trivy vulnerability scanner in repo mode - uses: aquasecurity/trivy-action@0.7.1 + uses: aquasecurity/trivy-action@0.10.0 if: ${{ ! github.event.schedule }} # Do not run inline checks when running periodically with: scan-type: fs @@ -28,7 +28,7 @@ jobs: skip-files: 'tests/integration/consumer-producer/pom.xml' - name: Run Trivy vulnerability scanner sarif output - uses: aquasecurity/trivy-action@0.7.1 + uses: aquasecurity/trivy-action@0.10.0 if: ${{ github.event.schedule }} # Generate sarif when running periodically with: scan-type: fs