Today is the first time I've looked at using an open source tool and actually gone an checked their github actions scripts to make sure they are maintaining them properly. (this is a #trivy sub-toot).