Skip to content

chore(deps): update floci/floci-gcp docker digest to 102db65 #2682

chore(deps): update floci/floci-gcp docker digest to 102db65

chore(deps): update floci/floci-gcp docker digest to 102db65 #2682

Triggered via pull request September 2, 2026 17:14
Status Success
Total duration 32s
Artifacts –

verify-sha-pinning.yml

on: pull_request
Fit to window
Zoom out
Zoom in

Annotations

2 warnings
verify
⚠️ aquasecurity/trivy-action@v0.36.0 — tag verification unavailable (test.yml:847): API access blocked (403) resolving tag "v0.36.0" in aquasecurity/trivy-action: Although you appear to have the correct authorization credentials, the `aquasecurity` organization has an IP allow list enabled, and your IP address is not permitted to access this resource. - https://docs.github.com/rest/git/refs#get-a-reference Allowlisted: The aquasecurity GitHub organization has enabled an IP allow list that blocks API access (git ref/tag lookups) from GitHub-hosted Actions runner IPs, for any caller, on any of their repos, including public ones — this is not specific to our token or workflow. Verified independently: the exact same 403 is reported against the sibling aquasecurity/tfsec-action, and trivy-cache-action's issue tracker explicitly confirms 'aquasecurity GitHub org now has IP allow list enabled, blocking API access'. Manually confirmed our pinned SHA is correct (dereferenced the v0.36.0 annotated tag directly against the GitHub API from a non-Actions IP; it matches) — this entry only silences the automated drift check, which the API access restriction makes impossible to run in CI, not the underlying security property.
verify
⚠️ aquasecurity/trivy-action@v0.36.0 — tag verification unavailable (build.yml:121): API access blocked (403) resolving tag "v0.36.0" in aquasecurity/trivy-action: Although you appear to have the correct authorization credentials, the `aquasecurity` organization has an IP allow list enabled, and your IP address is not permitted to access this resource. - https://docs.github.com/rest/git/refs#get-a-reference Allowlisted: The aquasecurity GitHub organization has enabled an IP allow list that blocks API access (git ref/tag lookups) from GitHub-hosted Actions runner IPs, for any caller, on any of their repos, including public ones — this is not specific to our token or workflow. Verified independently: the exact same 403 is reported against the sibling aquasecurity/tfsec-action, and trivy-cache-action's issue tracker explicitly confirms 'aquasecurity GitHub org now has IP allow list enabled, blocking API access'. Manually confirmed our pinned SHA is correct (dereferenced the v0.36.0 annotated tag directly against the GitHub API from a non-Actions IP; it matches) — this entry only silences the automated drift check, which the API access restriction makes impossible to run in CI, not the underlying security property.