Skip to content

fix: pin aquasecurity/trivy-action to verified-safe v0.35.0#1385

Closed
Copilot wants to merge 2 commits intomainfrom
copilot/fix-trivy-action-security-issue
Closed

fix: pin aquasecurity/trivy-action to verified-safe v0.35.0#1385
Copilot wants to merge 2 commits intomainfrom
copilot/fix-trivy-action-security-issue

Conversation

Copy link
Contributor

Copilot AI commented Mar 20, 2026

aquasecurity/trivy-action v0.69.4 is confirmed compromised; only v0.35.0 and v0.2.6 are currently verified safe.

Changes

  • .github/workflows/container-scan.yml: Update all four trivy-action usages from v0.33.1 → v0.35.0
# Before
uses: aquasecurity/trivy-action@b6643a29fecd7f34b3597bc6acb0a98b03d33ff8 # v0.33.1

# After
uses: aquasecurity/trivy-action@57a97c7e7821a5776cebc9bb87c984fa69cba8f1 # v0.35.0

📍 Connect Copilot coding agent with Jira, Azure Boards or Linear to delegate work to Copilot in one click without leaving your project management tool.

Copilot AI changed the title [WIP] Fix security alert for compromised Aqua Security Trivy Action fix: pin aquasecurity/trivy-action to verified-safe v0.35.0 Mar 20, 2026
Copilot AI requested a review from mnkiefer March 20, 2026 18:03
@mnkiefer
Copy link

@mnkiefer mnkiefer closed this Mar 20, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Security Alert: Compromised Aqua Security Trivy Action (v0.69.4 and possibly others)

2 participants