-
Notifications
You must be signed in to change notification settings - Fork 1
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update aquasec/trivy docker tag to v0.54.1 #76
Merged
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
renovate
bot
changed the title
Update aquasec/trivy Docker tag to v0.50.0
Update aquasec/trivy Docker tag to v0.50.1
Mar 27, 2024
renovate
bot
force-pushed
the
renovate/aquasec-trivy-0.x
branch
from
March 27, 2024 11:22
fa5f936
to
9424dea
Compare
renovate
bot
force-pushed
the
renovate/aquasec-trivy-0.x
branch
from
April 22, 2024 16:09
9424dea
to
4bcaf62
Compare
renovate
bot
changed the title
Update aquasec/trivy Docker tag to v0.50.1
Update aquasec/trivy Docker tag to v0.50.2
Apr 22, 2024
renovate
bot
changed the title
Update aquasec/trivy Docker tag to v0.50.2
Update aquasec/trivy Docker tag to v0.50.4
Apr 24, 2024
renovate
bot
force-pushed
the
renovate/aquasec-trivy-0.x
branch
from
April 24, 2024 14:04
4bcaf62
to
8eb43a3
Compare
renovate
bot
changed the title
Update aquasec/trivy Docker tag to v0.50.4
chore(deps): update aquasec/trivy docker tag to v0.50.4
Apr 28, 2024
renovate
bot
changed the title
chore(deps): update aquasec/trivy docker tag to v0.50.4
chore(deps): update aquasec/trivy docker tag to v0.51.0
May 3, 2024
renovate
bot
force-pushed
the
renovate/aquasec-trivy-0.x
branch
2 times, most recently
from
May 4, 2024 09:42
4c21de8
to
1b88b78
Compare
renovate
bot
changed the title
chore(deps): update aquasec/trivy docker tag to v0.51.0
chore(deps): update aquasec/trivy docker tag to v0.51.1
May 4, 2024
renovate
bot
force-pushed
the
renovate/aquasec-trivy-0.x
branch
from
May 20, 2024 14:16
1b88b78
to
06592b5
Compare
renovate
bot
changed the title
chore(deps): update aquasec/trivy docker tag to v0.51.1
chore(deps): update aquasec/trivy docker tag to v0.51.2
May 20, 2024
renovate
bot
changed the title
chore(deps): update aquasec/trivy docker tag to v0.51.2
chore(deps): update aquasec/trivy docker tag to v0.51.3
May 24, 2024
renovate
bot
force-pushed
the
renovate/aquasec-trivy-0.x
branch
2 times, most recently
from
May 24, 2024 15:15
fd4f0b8
to
155ba57
Compare
renovate
bot
changed the title
chore(deps): update aquasec/trivy docker tag to v0.51.3
chore(deps): update aquasec/trivy docker tag to v0.51.4
May 24, 2024
renovate
bot
force-pushed
the
renovate/aquasec-trivy-0.x
branch
from
June 3, 2024 09:54
155ba57
to
eab665a
Compare
renovate
bot
changed the title
chore(deps): update aquasec/trivy docker tag to v0.51.4
chore(deps): update aquasec/trivy docker tag to v0.52.0
Jun 3, 2024
renovate
bot
force-pushed
the
renovate/aquasec-trivy-0.x
branch
from
June 10, 2024 12:40
eab665a
to
00301df
Compare
renovate
bot
changed the title
chore(deps): update aquasec/trivy docker tag to v0.52.0
chore(deps): update aquasec/trivy docker tag to v0.52.1
Jun 10, 2024
renovate
bot
force-pushed
the
renovate/aquasec-trivy-0.x
branch
from
June 14, 2024 10:28
00301df
to
3074477
Compare
renovate
bot
changed the title
chore(deps): update aquasec/trivy docker tag to v0.52.1
chore(deps): update aquasec/trivy docker tag to v0.52.2
Jun 14, 2024
renovate
bot
force-pushed
the
renovate/aquasec-trivy-0.x
branch
from
July 9, 2024 20:24
3074477
to
6bbeb33
Compare
renovate
bot
changed the title
chore(deps): update aquasec/trivy docker tag to v0.52.2
chore(deps): update aquasec/trivy docker tag to v0.53.0
Jul 9, 2024
renovate
bot
force-pushed
the
renovate/aquasec-trivy-0.x
branch
from
July 31, 2024 11:24
6bbeb33
to
b065099
Compare
renovate
bot
changed the title
chore(deps): update aquasec/trivy docker tag to v0.53.0
chore(deps): update aquasec/trivy docker tag to v0.54.0
Jul 31, 2024
renovate
bot
force-pushed
the
renovate/aquasec-trivy-0.x
branch
from
July 31, 2024 18:15
b065099
to
173088e
Compare
renovate
bot
changed the title
chore(deps): update aquasec/trivy docker tag to v0.54.0
chore(deps): update aquasec/trivy docker tag to v0.54.1
Jul 31, 2024
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.49.1
->0.54.1
Release Notes
aquasecurity/trivy (aquasec/trivy)
v0.54.1
Compare Source
Changelog
854c61d
release: v0.54.1 [release/v0.54] (#7282)334a1c2
fix(flag): incorrect behavior for deprected flag--clear-cache
[backport: release/v0.54] (#7285)f61725c
fix(java): Return error when trying to find a remote pom to avoid segfault [backport: release/v0.54] (#7283)a7b7117
fix(plugin): do not call GitHub content API for releases and tags [backport: release/v0.54] (#7279)v0.54.0
Compare Source
Features
log.FilePath()
function for logger (#7080) (1f5f348)--vuln-type
flag to--pkg-types
flag (#7104) (7cbdb0a)SPDX
andCycloneDX
reports (#7257) (4a2f492)--pkg-relationships
(#7237) (5c37361)Bug Fixes
*.deps.json
files (#7039) (5bc662b)nuget package dir not found
log only when checkingnuget
packages (#7194) (d76feba)pom
init
dir are not found (#7245) (4e54a7e)go-mvn-version
to removePackage
duplicates (#7088) (a7a304d)latest
version for filesyarn.lock
+package.json
(#7110) (54bb8bd)hugging-face-access-token
(#7216) (8c87194)Performance Improvements
bytes.Index
inemptyLineSplit
to cut allocation (#7065) (acbec05)v0.53.0
Compare Source
⚠ BREAKING CHANGES
Features
environment.yml
files (#6953) (654217a)maven-metadata.xml
files for remote snapshot repositories. (#6950) (1f8fca1)CycloneDX v1.6
(#6903) (09e50ce)Bug Fixes
file-patterns
and scan.conan2
cache dir (#6949) (38b35dd)advisory.url
(#6952) (417212e)image.inspect.Created
field only for non-empty values (#6948) (0af5730),
,or
, etc. (#6916) (52f7aa5)package-lock.json
file is broken (#6858) (cf5aa33)pnpm
with cyclic imports (#6857) (7d083bc)--insecure
(#7022) (3d02a31)poetry.lock
andpyproject.toml
in lowercase (#6852) (faa9d92)srcEpoch
when decoding SBOM files (#6866) (04af59c)purl
for maven pkgs (#7008) (a76e328)purl
forbitnami
pkg names (#6982) (7eabb92)Asymmetric Private Key
shouldn't start with space (#6867) (bb26445)v0.52.2
Compare Source
Changelog
8709d4f
release: v0.52.2 [release/v0.52] (#6896)a4b8ad7
ci: useubuntu-latest-m
runner [backport: release/v0.52] (#6933)2b711bc
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azidentity from 1.5.2 to 1.6.0 [backport: release/v0.52] (#6919)191d31e
test: bump docker API to 1.45 [backport: release/v0.52] (#6922)3f5874c
ci: bumpgithub.com/goreleaser/goreleaser
tov2.0.0
[backport: release/v0.52] (#6893)8f8c76a
fix(debian): take installed files from the origin layer [backport: release/v0.52] (#6892)v0.52.1
Compare Source
Changelog
a3caf06
release: v0.52.1 [release/v0.52] (#6877)01dbb42
fix(nodejs): fix infinite loop when package link frompackage-lock.json
file is broken [backport: release/v0.52] (#6888)f186d22
fix(sbom): don't overwritesrcEpoch
when decoding SBOM files [backport: release/v0.52] (#6881)093c0ae
fix(python): compare pkg names frompoetry.lock
andpyproject.toml
in lowercase [backport: release/v0.52] (#6878)6bfda76
Merge pull request #6879 from aquasecurity/backport-pr-6864-to-release/v0.5253850c8
docs: explain how VEX is applied (#6864)2211962
Merge pull request #6875 from aquasecurity/backport-pr-6857-to-release/v0.52a614b69
fix(nodejs): fix infinity loops forpnpm
with cyclic imports (#6857)v0.52.0
Compare Source
Features
requirement.txt
files (#6782) (29615be)requirement.txt
files (#6729) (2bc54ad)Bug Fixes
pip
deps forenvironment.yml
files (#6675) (150a773)gobinaries
(#6710) (c96f2a5).version
|.ver
(no prefixes) ldflags forgobinaries
(#6705) (afb4f9d)requirements.txt
files. (#6804) (ea3a124)convert
mode when scanning json file derived from sbom file (#6808) (f92ea09)Performance Improvements
v0.51.4
Changelog
c06f467
chore: downgrade trivy-checks and trivy-awsdf4f760
build: use main package instead of main.go (#6766)bf7a8ed
chore(deps): bump the common group across 1 directory with 29 updates (#6756)acb22c6
chore(deps): bump the aws group with 8 updates (#6738)9a3510f
chore(deps): bump the docker group with 2 updates (#6739)7806b37
ci: addgeneric
dir to deb deploy script (#6636)v0.51.2
Compare Source
Changelog
eadc6fb
fix: node-collector high and critical cves (#6707)cc489b1
Merge pull request from GHSA-xcq4-m2r3-cmrj013f71a
chore: auto-bump golang patch versions (#6711)113a5b2
fix(misconf): don't shift ignore rule related to code (#6708)733e5ac
fix(go): include only.version
|.ver
(no prefixes) ldflags forgobinaries
(#6705)d311e49
fix(go): add only non-empty root modules forgobinaries
(#6710)cf1a7bf
refactor: unify package addition and vulnerability scanning (#6579)d465d9d
fix: Golang version parsing from binaries w/GOEXPERIMENT (#6696)0af225c
fix(conda): add supportpip
deps forenvironment.yml
files (#6675)6f64d55
fix(misconf): skip Rego errors with a nil location (#6666)8c27430
fix(misconf): skip Rego errors with a nil location (#6638)c2b46d3
refactor: unify Library and Package structs (#6633)4368f11
fix: use of specified context to obtain cluster name (#6645)5ec62f8
docs: fix usage of image-config-scanners (#6635)v0.51.1
Compare Source
Changelog
8016b82
fix(fs): handle default skip dirs properly (#6628)7a25dad
fix(misconf): load cached tf modules (#6607)9c794c0
fix(misconf): do not use semver for parsing tf module versions (#6614)v0.51.0
Compare Source
⚡Release highlights and summary⚡
👉 https://github.com/aquasecurity/trivy/discussions/6622
Changelog
14c1024
refactor: move setting scanners when using compliance reports to flag parsing (#6619)998f750
feat: introduce package UIDs for improved vulnerability mapping (#6583)770b141
perf(misconf): Improve cause performance (#6586)3ccb1a0
docs: trivy-k8s new experiance remove un-used section (#6608)58cfd1b
chore(deps): bump github.com/docker/docker from 26.0.1+incompatible to 26.0.2+incompatible (#6612)715963d
docs: remove mention of GitLab Gold because it doesn't exist anymore (#6609)37da98d
feat(misconf): Use updated terminology for misconfiguration checks (#6476)cdee703
chore(deps): bump github.com/aws/aws-sdk-go-v2/feature/s3/manager from 1.15.15 to 1.16.15 (#6593)6a2225b
docs: usegeneric
link fromtrivy-repo
(#6606)a2a02de
docs: update trivy k8s with new experience (#6465)e739ab8
feat: support--skip-images
scanning flag (#6334)c6d5d85
BREAKING: add support for k8sdisable-node-collector
flag (#6311)194a814
chore(deps): bump github.com/zclconf/go-cty from 1.14.1 to 1.14.4 (#6601)03830c5
chore(deps): bump github.com/sigstore/rekor from 1.2.2 to 1.3.6 (#6599)8e814fa
chore(deps): bump google.golang.org/protobuf from 1.33.0 to 1.34.0 (#6597)2dc76ba
chore(deps): bump sigstore/cosign-installer from 3.4.0 to 3.5.0 (#6588)c17176b
chore(deps): bump github.com/testcontainers/testcontainers-go from 0.28.0 to 0.30.0 (#6595)bce70af
chore(deps): bump github.com/open-policy-agent/opa from 0.62.0 to 0.64.1 (#6596)4369a19
feat: add ubuntu 23.10 and 24.04 support (#6573)5566548
chore(deps): bump azure/setup-helm from 3.5 to 4 (#6590)a8af76a
chore(deps): bump actions/checkout from 4.1.2 to 4.1.4 (#6587)c8ed432
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ecr from 1.24.6 to 1.27.4 (#6598)551a46e
docs(go): add stdlib (#6580)261649b
chore(deps): bump github.com/containerd/containerd from 1.7.13 to 1.7.16 (#6592)acfddd4
chore(deps): bump github.com/go-openapi/runtime from 0.27.1 to 0.28.0 (#6600)419e3d2
feat(go): parse main mod version from build info settings (#6564)f0961d5
feat: respect custom exit code from plugin (#6584)a5d485c
docs: add asdf and mise installation method (#6063)29b8faf
feat(vuln): Handle scanning conan v2.x lockfiles (#6357)e3bef02
feat: add supportenvironment.yaml
files (#6569)916f6c6
fix: close plugin.yaml (#6577)8e6cd0e
fix: trivy k8s avoid deleting non-default node collector namespace (#6559)060d0bb
BREAKING: support excludekinds/namespaces
and includekinds/namespaces
(#6323)2d090ef
feat(go): add main module (#6574)6343e4f
feat: add relationships (#6563)a018ee1
ci: disableGo
cache forreusable-release.yaml
(#6572)5da053f
docs: mention--show-suppressed
is available in table (#6571)3d66cb8
chore: fix sqlite to support loong64 (#6511)9aca98c
fix(debian): sort dpkg info before parsing due to exclude directories (#6551)7811ad0
docs: update info about config file (#6547)fae710d
docs: remove RELEASE_VERSION from trivy.repo (#6546)d2d4022
fix(sbom): change error to warning for multiple OSes (#6541)164b025
fix(vuln): skip empty versions (#6542)5dd9bd4
feat(c): add license support for conan lock files (#6329)7c2017f
fix(terraform): Attribute and fileset fixes (#6544)63c9469
refactor: change warning if no vulnerability details are found (#6230)aa822c2
refactor(misconf): improve error handling in the Rego scanner (#6527)30cc88f
ci: use tmp dir inside Trivy repo dir for GoReleaser (#6533)e32215c
feat(go): parse main module of go binary files (#6530)d4da83c
chore(deps): bump golang.org/x/net from 0.21.0 to 0.23.0 (#6526)0d7d97d
refactor(misconf): simplify the retrieval of module annotations (#6528)9873cf3
chore(deps): bump github.com/hashicorp/go-getter from 1.7.3 to 1.7.4 (#6523)95c8fd9
docs(nodejs): add info about supported versions of pnpm lock files (#6510)12ec0df
feat(misconf): loading embedded checks as a fallback (#6502)9b7d713
fix(misconf): Parse JSON k8s manifests properly (#6490)13e72ec
refactor: remove parallel walk (#5180)a986199
fix: close pom.xml (#6507)46d5aba
fix(secret): convert severity for custom rules (#6500)34ab09d
fix(java): update logic to detectpom.xml
file snapshot artifacts from remote repositories (#6412)1ba5b59
fix: typo (#6283)4fab0f8
docs(k8s,image): fix command-line syntax issues (#6403)d770981
chore(deps): bump actions/checkout from 4.1.1 to 4.1.2 (#6435)4337068
fix(misconf): avoid panic if the scheme is not valid (#6496)d82d6cb
feat(image): goversion as stdlib (#6277)cfddfb3
fix: add color for error inside of log message (#6493)dfcb0f9
chore(deps): bump actions/add-to-project from 0.4.1 to 1.0.0 (#6438)183eaaf
docs: fix links to OPA docs (#6480)94d6e8c
refactor: replace zap with slog (#6466)336c47e
docs: update links to IaC schemas (#6477)06b4473
chore: bump Go to 1.22 (#6075)a51cedd
refactor(terraform): sync funcs with Terraform (#6415)53517d6
feat(misconf): add helm-api-version and helm-kube-version flag (#6332)ad544e9
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azidentity from 1.4.0 to 1.5.1 (#6426)089368d
chore(deps): bump github.com/go-openapi/strfmt from 0.22.0 to 0.23.0 (#6452)1163565
chore(deps): bump github.com/hashicorp/golang-lru/v2 from 2.0.6 to 2.0.7 (#6430)637da2b
chore(deps): bump aquaproj/aqua-installer from 2.2.0 to 3.0.0 (#6437)13190e9
fix(terraform): eval submodules (#6411)6bca7c3
refactor(terraform): remove unused options (#6446)8e4279b
refactor(terraform): remove unused file (#6445)e98c873
chore(deps): bump github.com/testcontainers/testcontainers-go to v0.28.0 (#6387)b1c2eab
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azcore from 1.9.0 to 1.10.0 (#6427)1c49a16
fix(misconf): Escape template value correctly (#6292)8dd0fcd
feat(misconf): add support for wildcard ignores (#6414)74e4c6e
fix(cloudformation): resolveDedicatedMasterEnabled
parsing issue (#6439)245c120
refactor(terraform): remove metrics collection (#6444)86714bf
feat(cloudformation): add support for logging and endpoint access for EKS (#6440)a758392
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.51.1 to 1.53.1 (#6424)4d00d8b
chore(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.27.4 to 1.27.10 (#6428)3ad2b3e
chore(deps): bump go.etcd.io/bbolt from 1.3.8 to 1.3.9 (#6429)8baccd7
fix(db): check schema version for image name only (#6410)e75a90f
chore(deps): bump github.com/google/wire from 0.5.0 to 0.6.0 (#6425)6625bd3
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.149.1 to 1.155.1 (#6433)826fe60
chore(deps): bump actions/cache from 4.0.0 to 4.0.2 (#6436)f23ed77
feat(misconf): Support private registries for misconf check bundle (#6327)df024e8
feat(cloudformation): inline ignore support for YAML templates (#6358)29dee32
feat(terraform): ignore resources by nested attributes (#6302)1a67472
perf(helm): load in-memory files (#6383)09e37b7
feat(aws): apply filter options to result (#6367)87a9aa6
feat(aws): quiet flag support (#6331)712dcd3
fix(misconf): clear location URI for SARIF (#6405)625f22b
test(cloudformation): add CF tests (#6315)6a2f6fd
fix(cloudformation): infer type after resolving a function (#6406)v0.50.4
Compare Source
Note
v0.50.3 hads a critical problem, and we deleted it and released v0.50.4.
Changelog
e47fd48
fix(sbom): change error to warning for multiple OSes (#6541)v0.50.2
Compare Source
Changelog
9aa9e17
ci: use tmp dir inside Trivy repo dir for GoReleaser (#6533)058f483
chore(deps): bump golang.org/x/net from 0.21.0 to 0.23.0 (#6526)9e3d2c5
chore(deps): bump github.com/hashicorp/go-getter from 1.7.3 to 1.7.4 (#6523)2ad8e33
fix(java): update logic to detectpom.xml
file snapshot artifacts from remote repositories (#6412)v0.50.1
Compare Source
Changelog
5f69937
fix(sbom): fix error when parent of SPDX Relationships is not a package. (#6399)258d153
fix(nodejs): mergeIndirect
,Dev
,ExternalReferences
fields for same deps frompackage-lock.json
files v2 or later (#6356)ade033a
docs: add info about support for package license detection infs
/repo
modes (#6381)f85c9fa
fix(nodejs): add support for parsingworkspaces
frompackage.json
as an object (#6231)9d7f5c9
fix: use0600
perms for tmp files for post analyzers (#6386)f148eb1
fix(helm): scan the subcharts once (#6382)97f95c4
docs(terraform): add file patterns for Terraform Plan (#6393)abd62ae
fix(terraform): сhecking SSE encryption algorithm validity (#6341)7c409fd
fix(java): parse modules frompom.xml
files once (#6312)1b68327
chore(deps): bump github.com/docker/docker from 25.0.3+incompatible to 25.0.5+incompatible (#6364)a2482c1
fix(server): add Locations forPackages
in client/server mode ([#6366](https://togithub.com/aquasecurConfiguration
📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.