diff --git a/.github/workflows/lint.yaml b/.github/workflows/lint.yaml index 5378802..9e8c603 100644 --- a/.github/workflows/lint.yaml +++ b/.github/workflows/lint.yaml @@ -75,12 +75,11 @@ jobs: id: "goreleaser" with: distribution: "goreleaser-pro" - # Pinning to version 2.2.0 to get around a regression in 2.3.0. - version: "2.2.0" + version: "2.3.2" args: "release -f .goreleaser.docker.yml --clean --split --snapshot" env: GORELEASER_KEY: "${{ secrets.GORELEASER_KEY }}" - name: "Obtain container image to scan" - run: 'echo "IMAGE_VERSION=$(jq .version dist/linux_amd64/metadata.json --raw-output)" >> $GITHUB_ENV' + run: 'echo "IMAGE_VERSION=$(jq .version dist/linux_amd64_v1/metadata.json --raw-output)" >> $GITHUB_ENV' - name: "run trivy on release image" run: "docker run -v /var/run/docker.sock:/var/run/docker.sock aquasec/trivy image --format table --exit-code 1 --ignore-unfixed --vuln-type os,library --no-progress --severity CRITICAL,HIGH,MEDIUM authzed/zed:v${{ env.IMAGE_VERSION }}-amd64" diff --git a/.github/workflows/release.yaml b/.github/workflows/release.yaml index 77b4f1a..4dbaf5c 100644 --- a/.github/workflows/release.yaml +++ b/.github/workflows/release.yaml @@ -21,8 +21,7 @@ jobs: - uses: "goreleaser/goreleaser-action@v6" with: distribution: "goreleaser-pro" - # Pinning to v2.2.0 to work around a regression in 2.3.0 - version: &goreleaser_version "2.2.0" + version: &goreleaser_version "2.3.2" args: "release --clean" env: GITHUB_TOKEN: "${{ secrets.GITHUB_TOKEN }}"