Skip to content

Trivy CVE Dependency Scanner #90

Trivy CVE Dependency Scanner

Trivy CVE Dependency Scanner #90

Workflow file for this run

name: Trivy CVE Dependency Scanner
on:
workflow_dispatch:
schedule:
- cron: '0 0 * * *'
jobs:
trivy-scan:

Check failure on line 9 in .github/workflows/trivy-scan.yml

View workflow run for this annotation

GitHub Actions / Trivy CVE Dependency Scanner

Invalid workflow file

The workflow is not valid. .github/workflows/trivy-scan.yml (Line: 9, Col: 3): Error calling workflow 'carvel-dev/release-scripts/.github/workflows/trivy-scan.yml@main'. The nested job 'scan' is requesting 'security-events: write', but is only allowed 'security-events: none'.
uses: carvel-dev/release-scripts/.github/workflows/trivy-scan.yml@main
with:
repo: carvel-dev/kapp
tool: kapp
goVersion: '1.22'
secrets:
githubToken: ${{ secrets.GITHUB_TOKEN }}
slackWebhookURL: ${{ secrets.SLACK_WEBHOOK_URL }}