Skip to content

build(deps): Bump aquasecurity/trivy-action from 0.28.0 to 0.36.0 in the actions-minor-and-patch group across 1 directory#1

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-minor-and-patch-d884b4a175
Open

build(deps): Bump aquasecurity/trivy-action from 0.28.0 to 0.36.0 in the actions-minor-and-patch group across 1 directory#1
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/github_actions/actions-minor-and-patch-d884b4a175

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github May 4, 2026

Copy link
Copy Markdown

Bumps the actions-minor-and-patch group with 1 update in the / directory: aquasecurity/trivy-action.

Updates aquasecurity/trivy-action from 0.28.0 to 0.36.0

Release notes

Sourced from aquasecurity/trivy-action's releases.

v0.36.0

What's Changed

New Contributors

Full Changelog: aquasecurity/trivy-action@v0.35.0...v0.36.0

Release: 0.35.0

What's Changed

Full Changelog: aquasecurity/trivy-action@0.34.2...0.35.0

Release: v0.35.0

This release is a duplicate of 0.35.0 which was not compromised.

As part of our response to the recent supply chain attack, we have migrated all tags to use the v prefix (e.g., v0.35.0 instead of 0.35.0). Going forward, all new releases will use the v prefix convention.

We have intentionally kept the 0.35.0 tag intact to avoid breaking existing workflows that depend on it.

If you are currently using 0.35.0, your workflows are safe — no action is required.

Release: v0.34.0

Full Changelog: aquasecurity/trivy-action@v0.33.1...v0.34.0

Release: v0.33.1

What's Changed

Full Changelog: aquasecurity/trivy-action@v0.33.0...v0.33.1

... (truncated)

Commits

@dependabot @github

dependabot Bot commented on behalf of github May 4, 2026

Copy link
Copy Markdown
Author

Labels

The following labels could not be found: ci, dependencies. Please create them before Dependabot can add them to a pull request.

Please fix the above issues or remove invalid values from dependabot.yml.

@dependabot dependabot Bot changed the title Bump aquasecurity/trivy-action from 0.28.0 to 0.36.0 in the actions-minor-and-patch group build(deps): Bump aquasecurity/trivy-action from 0.28.0 to 0.36.0 in the actions-minor-and-patch group across 1 directory Jun 22, 2026
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-minor-and-patch-d884b4a175 branch from ee53499 to 228cdfd Compare June 22, 2026 03:08
@github-actions

github-actions Bot commented Jun 22, 2026

Copy link
Copy Markdown

🚀 Release preview

Next version on merge to main: none

semantic-release dry-run output
[3:09:44 AM] [semantic-release] › ℹ  Running semantic-release version 24.2.9
[3:09:45 AM] [semantic-release] › ✔  Loaded plugin "verifyConditions" from "@semantic-release/changelog"
[3:09:45 AM] [semantic-release] › ✔  Loaded plugin "verifyConditions" from "@semantic-release/npm"
[3:09:45 AM] [semantic-release] › ✔  Loaded plugin "verifyConditions" from "@semantic-release/git"
[3:09:45 AM] [semantic-release] › ✔  Loaded plugin "verifyConditions" from "@semantic-release/github"
[3:09:45 AM] [semantic-release] › ✔  Loaded plugin "analyzeCommits" from "@semantic-release/commit-analyzer"
[3:09:45 AM] [semantic-release] › ✔  Loaded plugin "generateNotes" from "@semantic-release/release-notes-generator"
[3:09:45 AM] [semantic-release] › ✔  Loaded plugin "prepare" from "@semantic-release/changelog"
[3:09:45 AM] [semantic-release] › ✔  Loaded plugin "prepare" from "@semantic-release/npm"
[3:09:45 AM] [semantic-release] › ✔  Loaded plugin "prepare" from "@semantic-release/git"
[3:09:45 AM] [semantic-release] › ✔  Loaded plugin "publish" from "@semantic-release/npm"
[3:09:45 AM] [semantic-release] › ✔  Loaded plugin "publish" from "@semantic-release/github"
[3:09:45 AM] [semantic-release] › ✔  Loaded plugin "addChannel" from "@semantic-release/npm"
[3:09:45 AM] [semantic-release] › ✔  Loaded plugin "addChannel" from "@semantic-release/github"
[3:09:45 AM] [semantic-release] › ✔  Loaded plugin "success" from "@semantic-release/github"
[3:09:45 AM] [semantic-release] › ✔  Loaded plugin "fail" from "@semantic-release/github"
[3:09:46 AM] [semantic-release] › ℹ  This test run was triggered on the branch refs/pull/1/merge, while semantic-release is configured to only publish from main, therefore a new version won’t be published.

If next_version is none, your commits don't trigger a release. Use feat: for minor, fix: / perf: for patch, or feat!: for major.

@github-advanced-security

Copy link
Copy Markdown

You are seeing this message because GitHub Code Scanning has recently been set up for this repository, or this pull request contains the workflow file for the Code Scanning tool.

What Enabling Code Scanning Means:

  • The 'Security' tab will display more code scanning analysis results (e.g., for the default branch).
  • Depending on your configuration and choice of analysis tool, future pull requests will be annotated with code scanning analysis results.
  • You will be able to see the analysis results for the pull request's branch on this overview once the scans have completed and the checks have passed.

For more information about GitHub Code Scanning, check out the documentation.

Bumps the actions-minor-and-patch group with 1 update in the / directory: [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action).


Updates `aquasecurity/trivy-action` from 0.28.0 to 0.36.0
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](aquasecurity/trivy-action@0.28.0...v0.36.0)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-version: 0.36.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: actions-minor-and-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/github_actions/actions-minor-and-patch-d884b4a175 branch from 228cdfd to c5e45eb Compare July 20, 2026 03:09
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant