Merge pull request #263 from fosrl/dependabot/github_actions/aquasecurity/trivy-action-0.35.0

chore(deps): bump aquasecurity/trivy-action from 0.34.2 to 0.35.0
This commit is contained in:
Marc Schäfer
2026-04-03 14:33:52 +02:00
committed by GitHub

View File

@@ -759,7 +759,7 @@ jobs:
cosign public-key --key env://COSIGN_PRIVATE_KEY >/dev/null cosign public-key --key env://COSIGN_PRIVATE_KEY >/dev/null
- name: Generate SBOM (SPDX JSON) from GHCR digest - name: Generate SBOM (SPDX JSON) from GHCR digest
uses: aquasecurity/trivy-action@97e0b3872f55f89b95b2f65b3dbab56962816478 # v0.34.2 uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0.35.0
with: with:
image-ref: ${{ env.GHCR_REF }} image-ref: ${{ env.GHCR_REF }}
format: spdx-json format: spdx-json