diff --git a/.github/workflows/docker-build-push.yml b/.github/workflows/docker-build-push.yml index 4d700cd8..abb27ca7 100644 --- a/.github/workflows/docker-build-push.yml +++ b/.github/workflows/docker-build-push.yml @@ -72,7 +72,7 @@ jobs: ${{ env.IMAGE_NAME }}:test-${{ inputs.variant }} - name: Upload Trivy low severity cases scan results to GitHub Security - uses: github/codeql-action/upload-sarif@v3.23.2 + uses: github/codeql-action/upload-sarif@v3.24.0 with: sarif_file: scan-results/trivy-${{ inputs.variant }}-image-scan-low.sarif category: ${{ inputs.variant }}-image-scan-low-cases @@ -93,7 +93,7 @@ jobs: ${{ env.IMAGE_NAME }}:test-${{ inputs.variant }} - name: Upload Trivy scan results to GitHub Security - uses: github/codeql-action/upload-sarif@v3.23.2 + uses: github/codeql-action/upload-sarif@v3.24.0 if: always() with: # Path to SARIF file relative to the root of the repository diff --git a/.github/workflows/hadolint.yml b/.github/workflows/hadolint.yml index 25e0dbf0..00f69ab1 100644 --- a/.github/workflows/hadolint.yml +++ b/.github/workflows/hadolint.yml @@ -28,7 +28,7 @@ jobs: output-file: ${{ inputs.dockerfile }}.sarif - name: Upload Hadolint results of ${{ inputs.dockerfile }} - uses: github/codeql-action/upload-sarif@v3.23.2 + uses: github/codeql-action/upload-sarif@v3.24.0 with: # Path to SARIF file relative to the root of the repository sarif_file: ${{ inputs.dockerfile }}.sarif diff --git a/.github/workflows/pr.yml b/.github/workflows/pr.yml index ecbb479c..f37cecbe 100644 --- a/.github/workflows/pr.yml +++ b/.github/workflows/pr.yml @@ -60,7 +60,7 @@ jobs: ${{ env.IMAGE_NAME }}:test-${{ inputs.variant }} - name: Upload Trivy low severity cases scan results to GitHub Security - uses: github/codeql-action/upload-sarif@v3.23.2 + uses: github/codeql-action/upload-sarif@v3.24.0 with: sarif_file: scan-results/trivy-${{ inputs.variant }}-image-scan-low.sarif category: ${{ inputs.variant }}-image-scan-low-cases @@ -81,7 +81,7 @@ jobs: ${{ env.IMAGE_NAME }}:test-${{ inputs.variant }} - name: Upload Trivy scan results to GitHub Security - uses: github/codeql-action/upload-sarif@v3.23.2 + uses: github/codeql-action/upload-sarif@v3.24.0 if: always() with: # Path to SARIF file relative to the root of the repository diff --git a/.github/workflows/trivy.yml b/.github/workflows/trivy.yml index 2f50ac9f..13aa7e3f 100644 --- a/.github/workflows/trivy.yml +++ b/.github/workflows/trivy.yml @@ -25,7 +25,7 @@ jobs: output: "trivy-repository-scan.sarif" - name: Upload Trivy scan results to GitHub Security - uses: github/codeql-action/upload-sarif@v3.23.2 + uses: github/codeql-action/upload-sarif@v3.24.0 with: # Path to SARIF file relative to the root of the repository sarif_file: trivy-repository-scan.sarif