Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
pin to a trivy version that does not detect the built image as spiced…
…b 0.0.1 Trivy recently started inferring the version of the binary as of 0.51.0, see aquasecurity/trivy#6564 The version used generated by go releaser is 0.0.1-next, and trivy detects that as version 0.0.1 of SpiceDB, and flags that as having CVEs, even though it's not really version 0.0.1.
- Loading branch information