Repository navigation
ci: Bump trivy-action to v0.36.0 to fix Trivy scans - #420
Merged
Merged
Conversation
scq
approved these changes
Oct 8, 2026
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Fixes #400.
The Trivy repo and image scans have failed since late April 2026. trivy-action v0.33.1 installs Trivy v0.65.0 by default, and that release no longer exists on GitHub (releases v0.27 to v0.69.1 were removed). setup-trivy fails to download the binary, the scan step exits 1, and the SARIF upload then fails with
Path does not exist.Changes:
aquasecurity/trivy-actionfrom v0.33.1 to v0.36.0 (pinned to commited142fd) in both workflows. v0.36.0 installs Trivy v0.70.0 and setup-trivy v0.2.6.format: templatewith@/contrib/sarif.tplforformat: 'sarif'. Trivy now warns that the template is deprecated.limit-severities-for-sarif: true. Without it, SARIF output ignoresseverityand uploads every severity. This keeps the Security tab to CRITICAL and HIGH, as the old template did.Trivy itself is left at the action's default v0.70.0. v0.75.0 is out but is only a week old.
Testing Instructions
gh workflow run scan-images.yml --repo <fork> --ref ci/400-bump-trivy-actionsarif.tpl is deprecatedwarning.Both were run on
313838e: repo scan run 37726376617 and image scan run 37726383764 (on the fork) passed.After merge, re-check that both workflows are enabled. They were disabled while #400 was open.
Checklist
bin/directory run correctly on both MacOS and WSLtbuild container && tup container)config.phpare compatible with our oldest supported Totara version, our newest Totara version, and Moodle