diff --git a/.github/actions/trivy-scan/action.yml b/.github/actions/trivy-scan/action.yml index b5159767cd..13810cbb68 100644 --- a/.github/actions/trivy-scan/action.yml +++ b/.github/actions/trivy-scan/action.yml @@ -64,7 +64,7 @@ runs: scanners: 'vuln' ignore-unfixed: 'true' # A finding with no available fix is not actionable, so it must not gate timeout: '5m' - version: 'v0.71.2' + version: 'v0.72.0' # Not trivyignores: that input drops the .yaml extension Trivy parses by. env: TRIVY_IGNOREFILE: '.trivyignore.yaml' @@ -81,7 +81,7 @@ runs: scanners: 'vuln' ignore-unfixed: 'true' # A finding with no available fix is not actionable, so it must not gate timeout: '5m' - version: 'v0.71.2' + version: 'v0.72.0' # Not trivyignores: that input drops the .yaml extension Trivy parses by. env: TRIVY_IGNOREFILE: '.trivyignore.yaml' diff --git a/api/changelog.d/api-trivy-0720-pin.changed.md b/api/changelog.d/api-trivy-0720-pin.changed.md new file mode 100644 index 0000000000..5e399341c5 --- /dev/null +++ b/api/changelog.d/api-trivy-0720-pin.changed.md @@ -0,0 +1 @@ +Pin the container vulnerability scanner to Trivy v0.72.0, matching prowler-registry and partner-portal diff --git a/prowler/changelog.d/trivy-0720-pin.changed.md b/prowler/changelog.d/trivy-0720-pin.changed.md new file mode 100644 index 0000000000..5e399341c5 --- /dev/null +++ b/prowler/changelog.d/trivy-0720-pin.changed.md @@ -0,0 +1 @@ +Pin the container vulnerability scanner to Trivy v0.72.0, matching prowler-registry and partner-portal