build(deps): bump aquasecurity/trivy-action from 0.8.0 to 0.9.0 (#5900)

This commit is contained in:
dependabot[bot] 2023-02-06 07:21:34 -08:00 committed by GitHub
parent b7279d1f66
commit 04341e0ab8
No known key found for this signature in database
GPG key ID: 4AEE18F83AFDEB23

View file

@ -20,7 +20,7 @@ jobs:
- name: Checkout code
uses: actions/checkout@v3
- name: Run Trivy vulnerability scanner
uses: aquasecurity/trivy-action@9ab158e8597f3b310480b9a69402b419bc03dbd5 # master
uses: aquasecurity/trivy-action@cff3e9a7f62c41dd51975266d0ae235709e39c41 # master
with:
image-ref: 'docker.io/coredns/coredns:${{ matrix.versions }}'
severity: 'CRITICAL,HIGH'