@@ -30,25 +30,25 @@ jobs:
30
30
runs-on : ubuntu-latest
31
31
steps :
32
32
- name : Check out the repo
33
- uses : actions/checkout@v4.1.7
33
+ uses : actions/checkout@v4.2.2
34
34
35
35
- name : Set up Docker Buildx
36
- uses : docker/setup-buildx-action@v3
36
+ uses : docker/setup-buildx-action@v3.11.1
37
37
38
38
- name : Log in to Docker Hub
39
- uses : docker/login-action@v3.3 .0
39
+ uses : docker/login-action@v3.4 .0
40
40
with :
41
41
username : ${{ secrets.DOCKERHUB_USERNAME }}
42
42
password : ${{ secrets.DOCKERHUB_TOKEN }}
43
43
44
44
- name : Extract metadata (tags, labels) for Docker
45
45
id : meta
46
- uses : docker/metadata-action@v5.5.1
46
+ uses : docker/metadata-action@v5.7.0
47
47
with :
48
48
images : georgedavisibexlabs/publish-sarif-to-jira
49
49
50
50
- name : Build and push Docker image
51
- uses : docker/build-push-action@v6.6.1
51
+ uses : docker/build-push-action@v6.18.0
52
52
with :
53
53
context : .
54
54
file : Dockerfile
58
58
labels : ${{ steps.meta.outputs.labels }}
59
59
60
60
- name : Update Docker Hub description
61
- uses : peter-evans/dockerhub-description@v4.0.0
61
+ uses : peter-evans/dockerhub-description@v4.0.2
62
62
with :
63
63
username : ${{ secrets.DOCKERHUB_USERNAME }}
64
64
password : ${{ secrets.DOCKERHUB_TOKEN }}
@@ -68,15 +68,15 @@ jobs:
68
68
enable-url-completion : true
69
69
70
70
- name : Run Trivy Image scanner
71
- uses : aquasecurity/trivy-action@0.24 .0
71
+ uses : aquasecurity/trivy-action@0.32 .0
72
72
with :
73
73
scan-type : ' image'
74
74
image-ref : ' georgedavisibexlabs/publish-sarif-to-jira:main'
75
75
limit-severities-for-sarif : true
76
76
trivy-config : .github/config/trivy-sarif.yaml
77
77
78
78
- name : Upload Trivy Image scan results
79
- uses : actions/upload-artifact@v4.3.6
79
+ uses : actions/upload-artifact@v4.6.2
80
80
with :
81
81
name : trivy-image-scan-results
82
82
path : trivy-image-scan-results.sarif
0 commit comments