diff --git a/.github/workflows/main.yml b/.github/workflows/main.yml index eeec241..fc28742 100644 --- a/.github/workflows/main.yml +++ b/.github/workflows/main.yml @@ -95,7 +95,7 @@ jobs: run: cosign sign --yes ${{ steps.imgdigest.outputs.digest }} - name: Create SBOM if: github.ref == 'refs/heads/master' - uses: aquasecurity/trivy-action@f781cce5aab226378ee181d764ab90ea0be3cdd8 # ratchet:aquasecurity/trivy-action@0.25.0 + uses: aquasecurity/trivy-action@a20de5420d57c4102486cdd9578b45609c99d7eb # ratchet:aquasecurity/trivy-action@0.26.0 with: scan-type: 'image' format: 'cyclonedx'