Skip to content

chore: update trivy to v0.69.3#360

Open
shabaraba wants to merge 1 commit intomainfrom
chore/update-trivy
Open

chore: update trivy to v0.69.3#360
shabaraba wants to merge 1 commit intomainfrom
chore/update-trivy

Conversation

@shabaraba
Copy link
Copy Markdown
Member

Why

The Trivy vulnerability scanner used in the yamory-scan workflow was significantly outdated. Updating to the latest version ensures:

  • More accurate vulnerability detection with updated vulnerability database
  • Improved scanning performance and reliability
  • Access to new features and bug fixes released since v0.36.1

What

  • Updated Trivy version from 0.36.1 to 0.69.3 in .github/workflows/yamory-scan.yaml
  • Updated SHA256 checksum for the new version

How to test

  1. Trigger the yamory-scan workflow by publishing a container image
  2. Verify the workflow completes successfully with the new Trivy version
  3. Confirm the vulnerability scan results are generated correctly

Checklist

  • Read CONTRIBUTING.md
  • Updated documentation if it is required.
  • Added tests if it is required.
  • Passed pnpm lint and pnpm test on the root directory.

@shabaraba shabaraba requested a review from a team as a code owner March 19, 2026 07:53
@shabaraba shabaraba requested review from chihiro-adachi and nameless-mc and removed request for a team March 19, 2026 07:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants