-
Notifications
You must be signed in to change notification settings - Fork 246
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Cannot run trivy as of today, problem with dependency #409
Comments
@DmitriyLewen I think this PR is the culprit #406 I think this action needs to add Here is my issue:
PS: adding |
@cafesanu I'm getting the same error: |
Here's the offending commit, at least in the |
Hello all! We are already working on |
Using actions from unverified repositories is a major security concern for us so your work is appreciated @DmitriyLewen . |
Encountered in |
FYI - i created aquasecurity/setup-trivy#5 to use |
FYI - @DmitriyLewen opened a PR where he bumped the |
This way this is bundled is the blueprint for how supply chain attacks works. I hope this get fixed soon. |
New (v0.28.0) release of trivy-action should address this. Please give it a try. |
Solved in https://github.com/aquasecurity/trivy-action/releases/tag/0.28.0. |
Looks like |
Starting today, the job fails with:
The text was updated successfully, but these errors were encountered: