发布

  • fix(ci): upgrade trivy-action to v0.34.0 (CVE-2026-26189) (#2322)

    frostbyte_neo 发布于 2026-02-20 07:59:55 +00:00

    Bump aquasecurity/trivy-action from vulnerable master pin to v0.34.0
    which fixes CVE-2026-26189 (OS command injection via unsanitized inputs).

    This resolves the zizmor known-vulnerable-actions audit failure that
    blocks the release gate.

    下载附件