diff --git a/.github/workflows/reusable-container-image-scan.yml b/.github/workflows/reusable-container-image-scan.yml index 173d9ebc..baff0f88 100644 --- a/.github/workflows/reusable-container-image-scan.yml +++ b/.github/workflows/reusable-container-image-scan.yml @@ -77,6 +77,6 @@ jobs: severity: 'HIGH,CRITICAL' - name: Upload Trivy scan results to GitHub Security tab if: ${{ steps.get-digests.outputs.destination != null }} - uses: github/codeql-action/upload-sarif@3ab4101902695724f9365a384f86c1074d94e18c # 3.24.7 + uses: github/codeql-action/upload-sarif@23acc5c183826b7a8a97bce3cecc52db901f8251 # 3.25.10 with: sarif_file: "trivy-results.sarif"