Skip to content

Commit 4957e14

Browse files
committed
Pin actions to SHA
1 parent 4ae63fa commit 4957e14

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

.github/workflows/security-scan.yaml

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -33,7 +33,7 @@ jobs:
3333
fi
3434
3535
- name: Run Trivy vulnerability scan
36-
uses: aquasecurity/trivy-action@0.28.0
36+
uses: aquasecurity/trivy-action@77137e9dc3ab1b329b7c8a38c2eb7475850a14e8
3737
with:
3838
scan-type: 'fs'
3939
scan-ref: '.'
@@ -43,7 +43,7 @@ jobs:
4343
exit-code: '0'
4444

4545
- name: Check for critical and high vulnerabilities
46-
uses: aquasecurity/trivy-action@0.28.0
46+
uses: aquasecurity/trivy-action@77137e9dc3ab1b329b7c8a38c2eb7475850a14e8
4747
with:
4848
scan-type: 'fs'
4949
scan-ref: '.'
@@ -92,7 +92,7 @@ jobs:
9292
pip install bandit[sarif]
9393
9494
- name: Run Bandit Security Scan
95-
uses: PyCQA/bandit-action@v1
95+
uses: PyCQA/bandit-action@67a458d90fa11fb1463e91e7f4c8f068b5863c7f
9696
with:
9797
targets: "."
9898
exclude: "tests"

0 commit comments

Comments
 (0)