From 145c7d5f5704d70b150cb1fd4357855f62f27dff Mon Sep 17 00:00:00 2001 From: maziggy Date: Sun, 16 Aug 2026 10:16:21 +0200 Subject: [PATCH] Pin Trivy to a release that still exists (#2844) The scan pinned Trivy v0.69.1, which aquasecurity have since deleted -- retained releases now run v0.74.0 down to v0.69.2 and then jump back to v0.26.0. The tag survives, so setup-trivy resolves it, reports "found version: 0.69.1" and then exits 1 with no asset to fetch. This repository did not notice because the binary was coming back from the Actions cache on every run, which skips the download. Forks have no such cache, which is where it was reported from -- and the same failure was due here the first time that entry went cold. Both scans move to trivy-action v0.36.0 and Trivy v0.74.0; every input they pass is still declared in the new action. The comment records that this pin has to be bumped rather than left, and that a green run is not evidence it still resolves. The config scan is clean on v0.74.0, so the bump adds no new misconfiguration alerts. --- .github/workflows/security.yml | 20 ++++++++++++++++---- 1 file changed, 16 insertions(+), 4 deletions(-) diff --git a/.github/workflows/security.yml b/.github/workflows/security.yml index 0a330a1c0..e6b6f2b5d 100644 --- a/.github/workflows/security.yml +++ b/.github/workflows/security.yml @@ -76,14 +76,25 @@ jobs: - name: Build Docker image run: docker build -t bambuddy:security-scan . + # Bump `version` when it ages rather than leaving it. Old Trivy releases + # are deleted upstream — only the last handful of minors are kept — so a + # pin a few months stale still resolves as a tag but no longer has an + # asset behind it, and the install step exits 1 right after reporting it + # found the version (#2844). + # + # A green run here is not evidence the pin still works. On a repository + # that runs this often the binary comes back from the Actions cache and + # nothing is downloaded, so the breakage shows up first in forks, which + # have no cache, and reaches this repository only once the entry goes + # cold. - name: Run Trivy vulnerability scanner - uses: aquasecurity/trivy-action@v0.35.0 + uses: aquasecurity/trivy-action@v0.36.0 with: image-ref: 'bambuddy:security-scan' format: 'sarif' output: 'trivy-results.sarif' severity: 'CRITICAL,HIGH,MEDIUM' - version: 'v0.69.1' + version: 'v0.74.0' - name: Upload Trivy results to GitHub Security uses: github/codeql-action/upload-sarif@v4 @@ -92,15 +103,16 @@ jobs: sarif_file: trivy-results.sarif category: trivy + # Keep in step with the scan above — see the note there before changing. - name: Run Trivy for Dockerfile/IaC - uses: aquasecurity/trivy-action@v0.35.0 + uses: aquasecurity/trivy-action@v0.36.0 with: scan-type: 'config' scan-ref: '.' format: 'sarif' output: 'trivy-config-results.sarif' severity: 'CRITICAL,HIGH,MEDIUM' - version: 'v0.69.1' + version: 'v0.74.0' - name: Upload Trivy config results uses: github/codeql-action/upload-sarif@v4