-
Notifications
You must be signed in to change notification settings - Fork 8
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
chore(deps): update dependency trivy to v0.60.0 #273
Open
renovate
wants to merge
1
commit into
master
Choose a base branch
from
renovate/trivy-0.x
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
8aec5b5
to
5ae744b
Compare
5ae744b
to
e4189b2
Compare
e4189b2
to
8601e7f
Compare
8601e7f
to
0639717
Compare
0639717
to
0324438
Compare
0324438
to
a9c7aea
Compare
a9c7aea
to
58474b9
Compare
58474b9
to
ba1855c
Compare
ba1855c
to
6a1791b
Compare
6a1791b
to
00e84a0
Compare
00e84a0
to
ea83dbe
Compare
ea83dbe
to
2aec920
Compare
2aec920
to
c37c6fc
Compare
c37c6fc
to
becfcb8
Compare
becfcb8
to
410cb40
Compare
118b255
to
4ec602f
Compare
4ec602f
to
c89805a
Compare
c89805a
to
2c6dd6e
Compare
2c6dd6e
to
a2f273c
Compare
a2f273c
to
bb81bca
Compare
bb81bca
to
96e7abd
Compare
96e7abd
to
cdfa5d9
Compare
cdfa5d9
to
600a685
Compare
600a685
to
08b2f01
Compare
08b2f01
to
2314d9f
Compare
2314d9f
to
f592fef
Compare
f592fef
to
927b26c
Compare
927b26c
to
d227809
Compare
d227809
to
3e1e8db
Compare
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
Test plan: CI should pass with updated dependencies. No review required: this is an automated dependency update PR.
Release Notes
aquasecurity/trivy (trivy)
v0.60.0
Compare Source
Features
--vuln-severity-source
flag (#8269) (d464807)Bug Fixes
scope
fortrivy registry login
command (#8393) (8715e5d)PkgRelationships
(#8442) (f987e41)poetry
v2 support (#8323) (10cd98c)shortDescription
andfullDescription
fields for sarif reports (#8344) (3eb0b03)pkgFilePaths
map for all formats (#8380) (72ea4b0)v0.59.1
Compare Source
Changelog
9aabfd2
release: v0.59.1 [release/v0.59] (#8334)412c690
fix(misconf): do not log scanners when misconfig scanning is disabled [backport: release/v0.59] (#8349)98f9ba2
chore(deps): bump Go tov1.23.5
[backport: release/v0.59] (#8343)1741fdd
fix(python): addpoetry
v2 support [backport: release/v0.59] (#8335)3fd8e27
fix(sbom): preserve OS packages from multiple SBOMs [backport: release/v0.59] (#8333)v0.59.0
Compare Source
Features
--distro
flag to manually specify OS distribution for vulnerability scanning (#8070) (da17dc7)Bug Fixes
dpkg
packages with different filePaths from different layers (#8298) (846498d)--generate-default-config
command (#8046) (5e68bdc)BLOW_UNKNOWN
error to download DBs (#8060) (51f2123)project.*
props (#8050) (9d9f80d)usr/share/buildinfo/
dir to detect content sets (#8222) (f352f6b)unknown
dependencies (if exists) (#8104) (7558df7)hasExtractedLicensingInfos
field for licenses that are not listed in the SPDX (#8077) (aec8885)Performance Improvements
v0.58.2
Compare Source
Changelog
936f06a
release: v0.58.2 [release/v0.58] (#8216)f72d2bc
fix(misconf): allow null values only for tf variables [backport: release/v0.58] (#8238)2896367
fix(suse): SUSE - update OSType constants and references for compatility [backport: release/v0.58] (#8237)b733ecc
fix: CVE-2025-21613 and CVE-2025-21614 : go-git: argument injection via the URL field [backport: release/v0.58] (#8215)v0.58.1
Compare Source
⚡Release highlights and summary⚡
👉 https://github.com/aquasecurity/trivy/discussions/8171
Changelog
https://github.com/aquasecurity/trivy/blob/release/v0.58/CHANGELOG.md#0581-2024-12-24
v0.58.0
Compare Source
Features
workspaceRelationship
(#7889) (d622ca2)go.mod
main module in the parser (#7977) (5448ba2)flavors
support (#7858) (b9b383e)Bug Fixes
UID
for removed packages (#7887) (07915da)mirror.gcr.io
(#7953) (9988147)root/buildinfo/content_manifests/
contains files that are notcontentSets
files (#7912) (38775a5)[email protected]
schema for misconfigs insarif
report (#7898) (19aea4b)v0.57.1
Compare Source
⚡Release highlights and summary⚡
👉https://github.com/aquasecurity/trivy/discussions/7951
Changelog
https://github.com/aquasecurity/trivy/blob/release/v0.57/CHANGELOG.md#0571-2024-11-18
v0.57.0
Compare Source
⚠ BREAKING CHANGES
Features
trivy auth
(#7664) (27117f8)trivy auth
totrivy registry
(#7727) (633a7ab)CycloneDX
reports (#7507) (c225883)Bug Fixes
clean --all
deletes only relevant dirs (#7704) (672e886)version
andscope
from upper/rootdepManagement
anddependencies
into parents (#7541) (778df82)git clone
output to Stderr (#7561) (fdf203c)Annotation
instead ofAttributionTexts
forSPDX
formats (#7811) (f2bb9c6)v0.56.2
Compare Source
Changelog
f2252c8
release: v0.56.2 [release/v0.56] (#7694)f6700ec
fix(redhat): include arch in PURL qualifiers [backport: release/v0.56] (#7702)25d2540
fix(sbom): add options for DBs in private registries [backport: release/v0.56] (#7691)v0.56.1
Compare Source
Changelog
95dbf11
release: v0.56.1 [release/v0.56] (#7648)5dbdadf
fix(db): fix javadb downloading error handling [backport: release/v0.56] (#7646)v0.56.0
Compare Source
Features
pom.xml
dependency versions can't be detected (#7520) (b836232)--skip-*
for all included modules (#7579) (c0e8da3)Bug Fixes
DownloadedAt
fortrivy-java-db
(#7592) (13ef3e7)dependencyManagement
from root/child pom's for dependencies from parents (#7497) (5442949)ExperimentalModifiedFindings
(#7463) (7ff9aff)framework
aslibrary
when unmarshallingCycloneDX
files (#7527) (aeb7039)Performance Improvements
Reverts
test
scope forpom.xml
files (#7488) (b0222fe)v0.55.2
Compare Source
Changelog
928c7c0
release: v0.55.2 [release/v0.55] (#7523)14a058f
fix(java): usedependencyManagement
from root/child pom's for dependencies from parents [backport: release/v0.55] (#7521)990bc4e
chore(deps): bump alpine from 3.20.0 to 3.20.3 [backport: release/v0.55] (#7516)v0.55.1
Compare Source
⚡Release highlights and summary⚡
👉https://github.com/aquasecurity/trivy/discussions/7494
Changelog
https://github.com/aquasecurity/trivy/blob/release/v0.55/CHANGELOG.md#0551-2024-09-12
v0.55.0
Compare Source
⚠ BREAKING CHANGES
Features
toolchain
asstdlib
version forgo.mod
files (#7163) (2d80769)test
scope support forpom.xml
files (#7414) (2d97700)--path-prefix
flag for client/server mode (#7321) (24a4563)--detection-priority
flag for accuracy tuning (#7288) (fd8348d)Bug Fixes
--clear-cache
(#7281) (2a0e529)kind
andapiVersion
ofvolumeClaimTemplate
element (#7362) (da4ebfa)importers
to detect dev deps from pnpm-lock.yaml file (#7387) (fd9ed3a)Message
field inasff.tpl
template (#7401) (dd9733e)NOASSERTION
for licenses fields in SPDX formats (#7403) (c96dcdd).eyJ
keyword for JWT secret (#7410) (bf64003)Performance Improvements
v0.54.1
Compare Source
Changelog
854c61d
release: v0.54.1 [release/v0.54] (#7282)334a1c2
fix(flag): incorrect behavior for deprected flag--clear-cache
[backport: release/v0.54] (#7285)f61725c
fix(java): Return error when trying to find a remote pom to avoid segfault [backport: release/v0.54] (#7283)a7b7117
fix(plugin): do not call GitHub contenConfiguration
📅 Schedule: Branch creation - "on the 1st through 7th day of the month" in timezone America/Los_Angeles, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.