Skip to content

Fix/trivy supply chain remediation v2#3036

Merged
FrankApiyo merged 3 commits intotrivy-actions-updatefrom
fix/trivy-supply-chain-remediation-v2
Mar 24, 2026
Merged

Fix/trivy supply chain remediation v2#3036
FrankApiyo merged 3 commits intotrivy-actions-updatefrom
fix/trivy-supply-chain-remediation-v2

Conversation

@ukanga
Copy link
Copy Markdown
Member

@ukanga ukanga commented Mar 24, 2026

No description provided.

ukanga added 3 commits March 24, 2026 16:44
Upgrade trivy binary from v0.69.1 to v0.69.3 (latest safe
release). Pin all remaining GitHub Actions to immutable commit
SHAs to prevent supply chain attacks via mutable tag refs.

Ref: GHSA-69fq-xp46-6x23
Pin all third-party GitHub Actions to immutable commit SHAs
in docker-image-build.yml and ecr-image-build-alpine.yml to
prevent supply chain attacks via mutable tag references.
Enable weekly automated PRs for GitHub Actions version
updates to keep SHA pins current.
@FrankApiyo FrankApiyo merged commit aecd4fc into trivy-actions-update Mar 24, 2026
7 checks passed
@FrankApiyo FrankApiyo deleted the fix/trivy-supply-chain-remediation-v2 branch March 24, 2026 14:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants