diff --git a/.github/workflows/build_util.yml b/.github/workflows/build_util.yml index 1b63fa9..5a8e96c 100644 --- a/.github/workflows/build_util.yml +++ b/.github/workflows/build_util.yml @@ -15,7 +15,7 @@ jobs: - uses: actions/checkout@v3 - name: Run Trivy vulnerability scanner in repo mode - uses: aquasecurity/trivy-action@v2 + uses: aquasecurity/trivy-action@v0.33.1 with: format: "sarif" output: "trivy-results.sarif" @@ -25,7 +25,7 @@ jobs: severity: "CRITICAL,HIGH" - name: Upload Trivy scan results to GitHub Security tab - uses: github/codeql-action/upload-sarif@0.33.1 + uses: github/codeql-action/upload-sarif@v2 with: sarif_file: "trivy-results.sarif"