ci: bump trivy to 0.70.0 (M0.2)
v0.50.0 release tarball doesn't exist on GitHub releases (404). Pin to v0.70.0 which is the current latest. Refs: M0.2
This commit is contained in:
@@ -50,7 +50,7 @@ jobs:
|
|||||||
shell: bash
|
shell: bash
|
||||||
run: |
|
run: |
|
||||||
set -euo pipefail
|
set -euo pipefail
|
||||||
TRIVY_VERSION=0.50.0
|
TRIVY_VERSION=0.70.0
|
||||||
curl -fsSL "https://github.com/aquasecurity/trivy/releases/download/v${TRIVY_VERSION}/trivy_${TRIVY_VERSION}_Linux-64bit.tar.gz" \
|
curl -fsSL "https://github.com/aquasecurity/trivy/releases/download/v${TRIVY_VERSION}/trivy_${TRIVY_VERSION}_Linux-64bit.tar.gz" \
|
||||||
| tar -xz -C /tmp trivy
|
| tar -xz -C /tmp trivy
|
||||||
/tmp/trivy fs --severity HIGH,CRITICAL --exit-code 1 --no-progress --skip-dirs node_modules,target,dist .
|
/tmp/trivy fs --severity HIGH,CRITICAL --exit-code 1 --no-progress --skip-dirs node_modules,target,dist .
|
||||||
|
|||||||
Reference in New Issue
Block a user