fix(ci): update trivy-action to use master #3296
Closed
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Problem
In
ci.yaml
, we have a job calledtrivy-scan-repo
which scans the repo for vulnerabilities usingtrivy-action
. It then uploads those results to the GitHub Security tab. It's failing due to this error (see logs):This issue was filed back in December 2020 and fixed in `trivy on March 23 (see PR).
According to the maintainers, this fix should be in
trivy-action
because:Reference: aquasecurity/trivy-action#22 (comment)
UPDATE: they're looking into it
Reference: aquasecurity/trivy-action#22 (comment)