[fix][sec] Upgrade Trivy GitHub Action to 0.35.0#25372
[fix][sec] Upgrade Trivy GitHub Action to 0.35.0#25372merlimat wants to merge 3 commits intoapache:masterfrom
Conversation
The trivy-action repository was compromised in a supply chain attack where an attacker force-pushed malicious payloads to 75 out of 76 version tags. References: - aquasecurity/trivy-action#541 - https://github.com/aquasecurity/trivy-action/releases/tag/v0.35.0 - https://github.com/aquasecurity/trivy/discussions/10265
|
We need to get the action allowed by ASF in the https://github.com/apache/infrastructure-actions repository first. I created apache/infrastructure-actions#546 to handle that. After that, we could use |
|
Trivy was blocked again by ASF: apache/infrastructure-actions@b6d723b |
|
@merlimat Trivy action is blocked by ASF. It was first approved, but after that it was blocked by apache/infrastructure-actions@b6d723b . I don't know the reason for this (yet). I'll request it again. |
Co-authored-by: Lari Hotari <lhotari@users.noreply.github.com>
|
Waiting for apache/infrastructure-actions#573 to be approved and merged. |
|
I created https://github.com/lhotari/sandboxed-trivy-action so that we would be able to harden the security and continue to use trivy. I'm testing it in lhotari#219. |
Motivation
The
aquasecurity/trivy-actionrepository was compromised in a supply chain attack where an attacker force-pushed malicious payloads to 75 out of 76 version tags. Version 0.35.0 is the first safe release after the incident.References:
Modifications
Upgrade
aquasecurity/trivy-actionfrom0.26.0to0.35.0in CI workflow.Documentation
doc-not-neededMatching PR in forked repository
No response
Label checklist
ready-to-testarea/test