feat(setup-trivy): use latest as default version

This commit is contained in:
2025-11-08 19:45:02 +01:00
parent 0c324d36cf
commit 64bb0256b4
+15 -4
View File
@@ -9,7 +9,7 @@ inputs:
version: version:
description: "Trivy version to download (e.g., latest)" description: "Trivy version to download (e.g., latest)"
required: false required: false
default: "v0.66.0" default: "latest"
runs: runs:
using: "composite" using: "composite"
@@ -27,21 +27,32 @@ runs:
;; ;;
esac esac
echo "ARCH=$ARCH" >> $GITHUB_OUTPUT echo "ARCH=$ARCH" >> $GITHUB_OUTPUT
- name: Resolve version
shell: bash
id: version
run: |
set -e
if [ "${{ inputs.version }}" = "latest" ]; then
VERSION=$(curl -s https://api.github.com/repos/aquasecurity/trivy/releases/latest | jq -r '.tag_name')
else
VERSION="${{ inputs.version }}"
fi
echo "VERSION=$VERSION" >> $GITHUB_OUTPUT
- name: Cache Trivy binary - name: Cache Trivy binary
id: cache-trivy id: cache-trivy
uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4 uses: actions/cache@0057852bfaa89a56745cba8c7296529d2fc39830 # v4
with: with:
path: /usr/local/bin/trivy path: /usr/local/bin/trivy
key: trivy-${{ inputs.version }}-${{ steps.arch.outputs.arch }} key: trivy-${{ steps.version.outputs.version }}-${{ steps.arch.outputs.arch }}
restore-keys: | restore-keys: |
trivy-${{ inputs.version }}-${{ steps.arch.outputs.arch }} trivy-${{ steps.version.outputs.version }}-${{ steps.arch.outputs.arch }}
- name: Download and install Trivy - name: Download and install Trivy
if: steps.cache-trivy.outputs.cache-hit != 'true' if: steps.cache-trivy.outputs.cache-hit != 'true'
shell: bash shell: bash
run: | run: |
set -e set -e
VERSION="${{ inputs.version }}" VERSION="${{ steps.version.outputs.version }}"
mkdir -p /usr/local/bin mkdir -p /usr/local/bin