| ▲ | cpuguy83 3 hours ago | |
This attack was not mitigated by hash pinning. The setup-trivy action installs the latest version of trivy unless you specify a version. | ||
| ▲ | AdrienPoupa 2 hours ago | parent [-] | |
Oh, I was referring to `aquasecurity/trivy-action` that was changed with a malicious entrypoint for affected tags. Pinned commits were not affected. | ||