generated from cayne/template
chore(deps): update dependency trivy to v0.74.0 #7
Loading…
Reference in a new issue
No description provided.
Delete branch "renovate/trivy-0.x"
Deleting a branch is permanent. Although the deleted branch may continue to exist for a short time before it actually gets removed, it CANNOT be undone in most cases. Continue?
This PR contains the following updates:
latest→0.74.0Release Notes
aquasecurity/trivy (trivy)
v0.74.0Features
Bug Fixes
v0.73.0Features
Bug Fixes
v0.72.0⚠ BREAKING CHANGES
Features
Bug Fixes
Continuous Integration
v0.71.2Changelog
055a5c8release: v0.71.2 [release/v0.71] (#10871)875328afix(deps): bump alpine to 3.24.1 [backport: release/v0.71] (#10870)998f7b3chore(deps): bump the common group with 4 updates [backport: release/v0.71] (#10867)v0.71.1Changelog
164b383release: v0.71.1 [release/v0.71] (#10818)a72d9a4fix(oci): validate artifact filename3dd9847fix: forward ospkg detector options through ospkg.NewScanner [backport: release/v0.71] (#10825)a62cbe4fix(vex): load VEX documents from within the repository directory [backport: release/v0.71] (#10821)43d1d26fix: surface the original analysis error instead of context cancellation [backport: release/v0.71] (#10812)ac7696cci: expect GitHub App bot as backport PR author [backport: release/v0.71] (#10815)v0.71.0Features
Bug Fixes
v0.69.3Changelog
6fb20c8release: v0.69.3 [release/v0.69] (#10293)dabefecfix(deps): bump github.com/go-git/go-git/v5 from 5.16.4 to 5.16.5 [backport: release/v0.69] (#10291)v0.69.0⚠ BREAKING CHANGES
Features
package-lock.jsonfile (#9983) (b64d5ad)Bug Fixes
Performance Improvements
Code Refactoring
v0.66.0Features
Bug Fixes
package.jsonfile (#9349) (03d039f)filecomponent type ofCycloneDX(#9372) (aa7cf43)v0.65.0Features
--serverflag (#9270) (ed4640e)Bug Fixes
filepathwhen removing duplicate packages (#9142) (4d10a81)GFDL-NIV-1.1andGFDL-NIV-1.2into Trivy mapping (#9116) (a692f29)LaxSplitLicenses(#9232) (b4193d0)*.listto*.md5sumsfiles fordpkg(#9131) (f224de3)root.iopackages (#9117) (c2ddd44)for_eachon a map returns a resource for every key (#9156) (153318f)v0.63.0Features
Minimum Trivy Version(#8880) (3b2a397)Bug Fixes
--skip-dirand--skip-filesflags forsbomcommand (#8886) (69a5fa1)--complianceflag (#8881) (35e8889)Relationshipfield support (#8939) (22f040f)rpc(#8872) (38f17c9)lo.IsNilto checkVEXfrom OCI artifact (#8858) (e97af98)Performance Improvements
v0.61.0Features
Bug Fixes
dpkgs(#8623) (346f5b3)--report all(#8613) (dbb6f28)otherLicenseswithout normalize (#8502) (e5072f1)--file-patternsflag for all post analyzers (#7365) (8b88238)Performance Improvements
v0.60.0Features
--vuln-severity-sourceflag (#8269) (d464807)Bug Fixes
scopefortrivy registry logincommand (#8393) (8715e5d)PkgRelationships(#8442) (f987e41)poetryv2 support (#8323) (10cd98c)shortDescriptionandfullDescriptionfields for sarif reports (#8344) (3eb0b03)pkgFilePathsmap for all formats (#8380) (72ea4b0)v0.59.0Features
--distroflag to manually specify OS distribution for vulnerability scanning (#8070) (da17dc7)Bug Fixes
dpkgpackages with different filePaths from different layers (#8298) (846498d)--generate-default-configcommand (#8046) (5e68bdc)BLOW_UNKNOWNerror to download DBs (#8060) (51f2123)project.*props (#8050) (9d9f80d)usr/share/buildinfo/dir to detect content sets (#8222) (f352f6b)unknowndependencies (if exists) (#8104) (7558df7)hasExtractedLicensingInfosfield for licenses that are not listed in the SPDX (#8077) (aec8885)Performance Improvements
v0.58.0Features
workspaceRelationship(#7889) (d622ca2)go.modmain module in the parser (#7977) (5448ba2)flavorssupport (#7858) (b9b383e)Bug Fixes
UIDfor removed packages (#7887) (07915da)mirror.gcr.io(#7953) (9988147)root/buildinfo/content_manifests/contains files that are notcontentSetsfiles (#7912) (38775a5)git@github.comschema for misconfigs insarifreport (#7898) (19aea4b)v0.57.0⚠ BREAKING CHANGES
Features
trivy auth(#7664) (27117f8)trivy authtotrivy registry(#7727) (633a7ab)CycloneDXreports (#7507) (c225883)Bug Fixes
clean --alldeletes only relevant dirs (#7704) (672e886)versionandscopefrom upper/rootdepManagementanddependenciesinto parents (#7541) (778df82)git cloneoutput to Stderr (#7561) (fdf203c)Annotationinstead ofAttributionTextsforSPDXformats (#7811) (f2bb9c6)v0.55.0⚠ BREAKING CHANGES
Features
toolchainasstdlibversion forgo.modfiles (#7163) (2d80769)testscope support forpom.xmlfiles (#7414) (2d97700)--path-prefixflag for client/server mode (#7321) (24a4563)--detection-priorityflag for accuracy tuning (#7288) (fd8348d)Bug Fixes
--clear-cache(#7281) (2a0e529)kindandapiVersionofvolumeClaimTemplateelement (#7362) (da4ebfa)importersto detect dev deps from pnpm-lock.yaml file (#7387) (fd9ed3a)Messagefield inasff.tpltemplate (#7401) (dd9733e)NOASSERTIONfor licenses fields in SPDX formats (#7403) (c96dcdd).eyJkeyword for JWT secret (#7410) (bf64003)Performance Improvements
v0.53.0⚠ BREAKING CHANGES
Features
environment.ymlfiles (#6953) (654217a)maven-metadata.xmlfiles for remote snapshot repositories. (#6950) (1f8fca1)CycloneDX v1.6(#6903) (09e50ce)Bug Fixes
file-patternsand scan.conan2cache dir (#6949) (38b35dd)advisory.url(#6952) (417212e)image.inspect.Createdfield only for non-empty values (#6948) (0af5730),,or, etc. (#6916) (52f7aa5)package-lock.jsonfile is broken (#6858) (cf5aa33)pnpmwith cyclic imports (#6857) (7d083bc)--insecure(#7022) (3d02a31)poetry.lockandpyproject.tomlin lowercase (#6852) (faa9d92)srcEpochwhen decoding SBOM files (#6866) (04af59c)purlfor maven pkgs (#7008) (a76e328)purlforbitnamipkg names (#6982) (7eabb92)Asymmetric Private Keyshouldn't start with space (#6867) (bb26445)v0.52.0Features
requirement.txtfiles (#6782) (29615be)requirement.txtfiles (#6729) (2bc54ad)Bug Fixes
pipdeps forenvironment.ymlfiles (#6675) (150a773)gobinaries(#6710) (c96f2a5).version|.ver(no prefixes) ldflags forgobinaries(#6705) (afb4f9d)requirements.txtfiles. (#6804) (ea3a124)convertmode when scanning json file derived from sbom file (#6808) (f92ea09)Performance Improvements
v0.26.0Changelog
a0047a7feat(alpine): warn mixing versions (#2000)d786655Update ASFF template (#1914)a02cf65chore(deps): replacecontainerd/containerdversion to fix CVE-2022-23648 (#1994)613e38cchore(deps): bump alpine from 3.15.3 to 3.15.4 (#1993)3b6d65btest(go): add integration tests for gomod (#1989)22f5b93fix(python): fixed panic when scan .egg archive (#1992)485637cfix(go): set correct go modules type (#1990)6fdb554feat(alpine): support apk repositories (#1987)d9bddb9docs: add CBL-Mariner (#1982)1cf1873docs(go): fix version (#1986)d77dbe8feat(go): support go.mod in Go 1.17+ (#1985)32bd1e4ci: fix URLs in the PR template (#1972)94a5a18ci: add semantic pull requests check (#1968)72d94b2docs(issue): added docs for wrong detection issues (#1961)v0.25.3Changelog
d4e3df8fix(downloadDB): add dbRepositoryFlag to repository and rootfs commands (#1956)7e48cc1fix(misconf): update BurntSushi/toml for fix runtime error (#1948)c9efa8cfix(misconf): Update fanal/defsec to resolve missing metadata issues (#1947)52b7154feat(jar): allow setting Maven Central URL using environment variable (#1939)21f7a41chore(chart): update Trivy version in HelmChart to 0.25.0 (#1931)ff2b3d1chore(chart): remove version comments (#1933)v0.24.4Changelog
06659f1fix(docker): Getting images without a tag (#1852)a91cc50docs(gitlab-ci): Use environment variables TRIVY_CACHE_DIR and TRIVY_NO_PROGRESS (#1801)v0.24.2Changelog
eebf9c8fix(pom): keep an order of dependencies (#1784)971092bchore: bump up Go to 1.17 (#1781)2f2d822chore(deps): bump actions/setup-python from 2 to 3 (#1776)a2afd6echore(deps): bump golangci/golangci-lint-action from 2 to 3.1.0 (#1777)Docker images
docker pull aquasec/trivy:0.24.2docker pull ghcr.io/aquasecurity/trivy:0.24.2docker pull public.ecr.aws/aquasecurity/trivy:0.24.2v0.24.1Changelog
a423b99fix(python): correct handling pip package names with a hyphen (#1771)a069ad7doc(docker): fix command to run trivy with docker on linux (#1761)015055efeat(helm): Add support for custom labels (#1767)cbaa363chore(helm): bump chart to trivy 0.24.0 (#1762)bec02f0docs: remove erroneous command (#1763)Docker images
docker pull aquasec/trivy:0.24.1docker pull ghcr.io/aquasecurity/trivy:0.24.1docker pull public.ecr.aws/aquasecurity/trivy:0.24.1v0.24.0Changelog
d7f8b92chore(deps): bump github.com/spf13/afero from 1.6.0 to 1.8.1 (#1708)59ea0d5fix(option): warn list-all-pkgs only with the table format (#1755)c788676feat(option): warn "--list-all-pkgs" with "--format table" (#1632)58ade46feat(report): add support for CycloneDX (#1081)77cab6echore(deps): update the defsec and tfsec versions (#1747)2ede15dfix(scanner): fix skip of language-specific files when scanning rootf… (#1751)d266c74chore(deps): bump github.com/google/wire from 0.4.0 to 0.5.0 (#1712)4423396feat(report): considering App.Writer when printing results (#1722)356ae30chore(deps): replacesatoriversion and skipping examples folder (#1745)477dc7dbuild: add s390x container images (#1726)89b8d7ffeat(template) Add misconfigurations to junit report (#1724)219b71bchore(deps): bump github.com/twitchtv/twirp (#1709)aa6e1ebfeat(client): configure TLS InsecureSkipVerify for server connection (#1287)de6c3cbfix(rpc): Supports RPC calls for new identifier CustomResource (#1605)b7d4d1echore(deps): bump go.uber.org/zap from 1.20.0 to 1.21.0 (#1705)e6c029dchore(deps): bump github.com/caarlos0/env/v6 from 6.0.0 to 6.9.1 (#1707)ec6cb1afeat(helm): Parameterise ServiceAccount annotations (#1677)7dfc16cchore(deps): bump github.com/hashicorp/go-getter from 1.5.2 to 1.5.11 (#1710)42d8fd6chore(deps): bump github.com/cheggaaa/pb/v3 from 3.0.3 to 3.0.8 (#1704)c3ef203chore(deps): bump github.com/open-policy-agent/opa from 0.36.1 to 0.37.2 (#1711)274103echore(dependabot): enable gomod monthly (#1699)e618d83fix(gitlab tpl): escape double quote (#1635)3b0b2edbuild: Makemake protocbe consistent (#1682)5c8d098feat(purl): add generate purl package utilities (#1574)11f4f81refactor: move result structs under types (#1696)6db2092feat(mariner): add support for CBL-Mariner 2.0 (#1694)8898bb0docs(gitlab-ci): fix Script in GitLab CI Example #168833d0833chore: Upgrade helm chart version (#1683)13874d8chore(mod): update Go dependencies (#1681)f26a06bdocs: fix typos in markdown docs (#1674)e2821a4docs: update documentation for image scanning of tar files to use a tag present on Docker Hub (#1671)ef8a1affix(repo): --no-progress suppresses git output (#1669)Docker images
docker pull aquasec/trivy:0.24.0docker pull ghcr.io/aquasecurity/trivy:0.24.0docker pull public.ecr.aws/aquasecurity/trivy:0.24.0v0.23.0Changelog
449add2docs: add ACR navigator (#1651)cb9afc8fix: update example Rego files and docs (#1628)78b2b89feat(option): show a link to GitHub Discussions for --light deprecation (#1650)52fd3c2fix(sarif): fix the warning message (#1647)8d5882brefactor: migrate to prefixed buckets (#1644)84dd33ffeat(mariner): add support for CBL-Mariner (#1640)9e903a1docs: commercial use available (#1641)f4c746afeat: support azure acr (#1611)420f8abfeat(os-pkg): add data sources (#1636)d2827cbfeat(redhat): support build info in RHEL (#807)ce703cefix: change links in pull_request_template to static URLs (#1634)50bb938feat(lang-pkg): add data sources (#1625)a31ddbefeat(detector): support custom detector (#1615)3a4e18adocs(contribution): change role who should resolve comments (#1618)8ba6836docs: add PR template (#1602)f5c5573feat(rocky): support Rocky Linux (#1570)eab2b42Add the ability to set dockerhub credentials in the helm chart (#1569)cabd18dfeat(cache): redis TLS support (#1297)02c3c36feat(java): add support for PAR files (#1599)4f7b768refactor(rust): move rust-advisory-db to OSV (#1591)d754cb8feat: log ignored vulnerabilities on debug (#1378)a936e67chore(mod): hcl2json deps update (#1585)af116d3fix(rpm): do not ignore installed files via third-party rpm (#1594)b507360feat(fs): allow scanning a single file (#1578)7fcbf44refactor(python): drop Safety DB (#1580)478d279feat: added insecure tls skip to scan git repo (#1528)33bd41bSupress git clone output (#1590)39a1008fix(alma): skip modular package because MODULARITYLABEL is not set (#1588)37abd61feat(photon os): added EOL dates check (#1587)78de33edocs: update supported os (#1586)2205462BREAKING: remove root command (#1579)28ddcf1docs: add Rust to Language-specific Packages Table (#1577)df134c7docs: update int doc for gitlab ci (#1575)8da20c8BREAKING: migrate the sarif template to Go code (#1437)714b5carefactor: remove unused field (#1567)51e152bchore(deps): bump helm/chart-testing-action from 2.1.0 to 2.2.0 (#1554)884daffdocs: gitlab integration (#1381)2a8336bfeat(alma): support AlmaLinux (#1238)1e171afdocs: added note about default template path when Trivy installed using rpm (#1551)e65274eBREAKING: Trivy DB from GHCR (#1539)db35450feat(cli): Do not set default commands when a plugin is being run (#1549)24254d1fix: add fingerprint field to codequality template (#1541)2ee0745fix(image): correct handling of uncompressed layers (#1544)0aef82cchore: helm chart app version 0.22.0 (#1535)8b2a799test(integration): use fixtures (#1532)Docker images
docker pull aquasec/trivy:0.23.0docker pull ghcr.io/aquasecurity/trivy:0.23.0docker pull public.ecr.aws/aquasecurity/trivy:0.23.0v0.22.0Changelog
42f795ffix(java/pom): ignore unsupported requirements (#1514)8f737ccfeat(cli): warning for root command (#1516)76249bdBREAKING: disable JAR detection in fs/repo scanning (#1512)59957d4feat(scan): support --offline-scan option (#1511)da8b72dfix: improve memory usage (#1509)b713ad0feat(java): support pom.xml (#1501)56115e9docs: fixing rust link to security advisory (#1504)7f859afAdd missing IacMetdata (#1505)628a796feat(jar): add file path (#1498)82fba77feat(rpm): support NDB (#1497)d5269dafeat: added misconfiguration field for html.tpl (#1444)Docker images
docker pull aquasec/trivy:0.22.0docker pull ghcr.io/aquasecurity/trivy:0.22.0docker pull public.ecr.aws/aquasecurity/trivy:0.22.0v0.21.2Changelog
7beed30docs: provide more information on scanning Google's GCR (#1426)f50e1f4docs(misconfiguration): added instruction for misconfiguration detection (#1428)3ae4de5Update git-repository.md (#1430)6e35b8ffix(hooks): exclude unrelated lib types from system files filtering (#1431)beb60b0chore: rungo fmt(#1429)582e7fdfix(sarif): changehelpfield in the sarif template. (#1423)11bc290Update fanal with cfsec version update (#1425)392f689Replace deprecated option in goreleaser (#1406)101d576feat(alpine): support 3.15 (#1422)bd3ba68chore: test the helm chart in the PR and used the commit hash (#1414)3860d6echore(deps): bump alpine from 3.14 to 3.15.0 (#1417)4f82673chore(release): add ubuntu older versions to deploy script (#1416)Docker images
docker pull aquasec/trivy:0.21.2docker pull ghcr.io/aquasecurity/trivy:0.21.2docker pull public.ecr.aws/aquasecurity/trivy:0.21.2v0.21.1Changelog
b9a51dechore(mod): tidy (#1415)7f24834fix(rpc): fix nil layer transmit (#1410)af3eaefLang advisory order (#1409)07c9200chore: add support for s390x arch (#1304)8bc8a4afix(chart): ingress helm manifest-update trivy image (#1323)9076a49docs: Add comparison for cfsec (#1388)bb316d9remove: delete unused functions in utils package (#1379)Docker images
docker pull aquasec/trivy:0.21.1docker pull ghcr.io/aquasecurity/trivy:0.21.1docker pull public.ecr.aws/aquasecurity/trivy:0.21.1v0.21.0Changelog
efdb29dfix(sarif): fix validation errors (#1376)9bcf9e7docs: add Bitbucket Pipelines (#1374)3147097docs: add community integrations (#1361)33f74b3Use a stable SARIF identifier (#1230)5915ffbfix(python): fix parsing of requirements.txt with hash checking mode available in pip since version 8.0ae4c42bfeat(iac): Add line information (#1366)19747d0feat(cloudformation): Adding support for cfsec IaC scanning (#1360)da45061chore: send debug and info logs to stdout in install.sh, not stderr. (#1264)cb1a4edUpdate containerd to v1.5.7 and docker-cli to v20.10.9 (#1356)69dae54chore: update SBOM generation (#1349)Docker images
docker pull aquasec/trivy:0.21.0docker pull ghcr.io/aquasecurity/trivy:0.21.0docker pull public.ecr.aws/aquasecurity/trivy:0.21.0v0.20.2Changelog
5dc8cfedocs: update builtin.md (#1335)798b564chore: fix issues with Homebrew formula (#1329)21bf5e5chore: bump GoReleaser to v0.183.0 (#1328)e0f4ebddocs: update iac.md for a typo (#1326)23a9a5edocs: typo fix (#1308)1f5d17fAdd new networking API features to Ingress (#1262)Docker images
docker pull aquasec/trivy:0.20.2docker pull ghcr.io/aquasecurity/trivy:0.20.2docker pull public.ecr.aws/aquasecurity/trivy:0.20.2v0.19.2Changelog
f3f3029Updated the Alpine Image to 3.14 (latest) (#1130)0e52fdeAdded EOL for Ubuntu 21.10 (#1131)9b3fba0fix(image): disabled scanning of config files within container images (#1133)1101634docs: fixed typo (#1124)499b7a6update cyclonedx github action to v0.3.0 (#1127)Docker images
docker pull aquasec/trivy:0.19.2docker pull ghcr.io/aquasecurity/trivy:0.19.2docker pull public.ecr.aws/aquasecurity/trivy:0.19.2docker pull aquasec/trivy:latestdocker pull ghcr.io/aquasecurity/trivy:latestdocker pull public.ecr.aws/aquasecurity/trivy:latestv0.19.1Changelog
cea9b0bfix(policy): fix panic on the first run (#1116)Docker images
docker pull aquasec/trivy:0.19.1docker pull ghcr.io/aquasecurity/trivy:0.19.1docker pull public.ecr.aws/aquasecurity/trivy:0.19.1docker pull aquasec/trivy:latestdocker pull ghcr.io/aquasecurity/trivy:latestdocker pull public.ecr.aws/aquasecurity/trivy:latestv0.18.3Changelog
85e45cachore(ci): change to more granular tokens (#1014)9fa512achore(ci): add Go scanning and update dependencies (#1001)349371bdocs: Add HIGH severity to Trivy command in GitLab CI example to match comment (#1013)Docker images
docker pull aquasec/trivy:0.18.3docker pull ghcr.io/aquasecurity/trivy:0.18.3docker pull public.ecr.aws/aquasecurity/trivy:0.18.3docker pull aquasec/trivy:latestdocker pull ghcr.io/aquasecurity/trivy:latestdocker pull public.ecr.aws/aquasecurity/trivy:latestv0.18.2Changelog
4446961fix(image): disable go.sum scanning (#1007)04473adfix(gomod): handle go.sum with an empty line (#1006)1b66b77feat: prepare for config scanning (#1005)8fc6ea6Clarify that dev dependencies are excluded (#986)Docker images
docker pull aquasec/trivy:0.18.2docker pull ghcr.io/aquasecurity/trivy:0.18.2docker pull public.ecr.aws/aquasecurity/trivy:0.18.2docker pull aquasec/trivy:latestdocker pull ghcr.io/aquasecurity/trivy:latestdocker pull public.ecr.aws/aquasecurity/trivy:latestv0.18.1Changelog
eaf2da2Include target value in Sarif template ruleID (#991)083c157chore(mkdocs): allow workflow_dispatch (#989)Docker images
docker pull aquasec/trivy:0.18.1docker pull ghcr.io/aquasecurity/trivy:0.18.1docker pull public.ecr.aws/aquasecurity/trivy:0.18.1docker pull aquasec/trivy:latestdocker pull ghcr.io/aquasecurity/trivy:latestdocker pull public.ecr.aws/aquasecurity/trivy:latestv0.18.0Release Note
https://github.com/aquasecurity/trivy/discussions/990
Changelog
e26e39afix(vuln) unique vulnerabilities from different data sources (#984)04e7ccafeat(go): added support of gomod analyzer (#978)Docker images
docker pull aquasec/trivy:0.18.0docker pull ghcr.io/aquasecurity/trivy:0.18.0docker pull public.ecr.aws/aquasecurity/trivy:0.18.0docker pull aquasec/trivy:latestdocker pull ghcr.io/aquasecurity/trivy:latestdocker pull public.ecr.aws/aquasecurity/trivy:latestv0.17.2Changelog
415e1d8fix: scan only regular files (#976)3bb8852docs: mention upx binaries (#974)c0fddd9chore: upgrade alpine to fix git and libcurl vulnerabilities in trivy docker image scan (#971)Docker images
docker pull aquasec/trivy:0.17.2docker pull ghcr.io/aquasecurity/trivy:0.17.2docker pull public.ecr.aws/aquasecurity/trivy:0.17.2docker pull aquasec/trivy:latestdocker pull ghcr.io/aquasecurity/trivy:latestdocker pull public.ecr.aws/aquasecurity/trivy:latestv0.17.1Changelog
41c066dfix(fs): skip dirs (#969)Docker images
docker pull aquasec/trivy:0.17.1docker pull ghcr.io/aquasecurity/trivy:0.17.1docker pull public.ecr.aws/aquasecurity/trivy:0.17.1docker pull aquasec/trivy:latestdocker pull ghcr.io/aquasecurity/trivy:latestdocker pull public.ecr.aws/aquasecurity/trivy:latestv0.16.0Features
Support Podman (#825)
[EXPERIMENTAL] This feature might change without preserving backwards compatibility.
Scan your image in Podman (>=2.0) running locally. The remote Podman is not supported. Before performing Trivy commands, you must enable the podman.sock systemd service on your machine. For more details, see here
Then, you can scan your image in Podman.
Support modular packages in RHEL 8/CentOS 8 (#790)
Trivy is able to scan RHEL 8/CentOS 8 more accurately now.
Add redis cache backend configuration options in the Helm chart (#784)
Trivy can be deployed to Kubernetes with Redis cache.
Thanks, @czunker!
Support PEP 440 (#816)
Trivy is able to scan Python vulnerabilities more accurately now.
Support alpine 3.13 (#819)
Trivy is able to scan Alpine Linux 3.13 now.
Fixes
Changelog
cdabe7fFix compatibility for Jenkins xunit plugin (#820)b0fe439README: add Gitlab job that uses a container with trivy (#823)6685cd4feat: support Podman (#825)7a683bdfix(eol): update EOL dates (#824)6ed03a8fix(python): follow PEP 440 (#816)182cb80Support alpine 3.13 (#819)2acd1caChanged the output string to "Using your github token". (#814)dd35bfdAlign comment with code (#812)1f17e71Parse redis backend url (#804)0954f6bUpdate README.md (#810)6b29bf1Added nodeSelector, affinity and tolerations to helm chart (#803)f6afdf0Fix readme typo in policy flag (#805)412847dFix errors in SARIF format (#801)5b27862Fix env variable for github token (#796)6ed25c1fix(vulnerability): set unknown severity for empty values (#793)e2c483fRemove global flags from filesystem command (#772)5c5e0cbAdd imagePullSecrets to helm Chart (#789)b9b84cdAdd redis cache backend configuration options (#784)e517bccUpdate README.md (#735)7f5a6d4feat(redhat): support modular packages (#790)8de09ddFix formatting of log message (#785)e08ae8dchore(ci): migrate unit tests to GitHub Actions (#779)a00d719shifted: brews.github to brews.tap (#780)Docker images
docker pull docker.io/aquasec/trivy:0.16.0docker pull docker.io/aquasec/trivy:latestdocker pull ghcr.io/aquasecurity/trivy:0.16.0docker pull ghcr.io/aquasecurity/trivy:latestv0.15.0Features
NuGet Scanner (#686)
Trivy now supports a lock file
packages.lock.jsonof NuGet.Thanks to @Johannestegner
Redis support as the cache backend (#770)
For the detail, see here
HTML template (#567)
Thanks to @irrandon
Helm chart (#751, #769)
For the detail, see here
Thanks to @czunker
Fixes
redhat: skip modular packages (#776)
Close #771 and #741
Thanks to @masahiro331
Make the table output less wide. (#763)
Changelog
08ca1b0Feat: NuGet Scanner (#686)7b86f81feat(cache): support Redis (#770)8cd4afefix(redhat): skip module packages (#776)b606b62chore: migrate from master to main (#778)5c2b14bchore(circleci): remove gofmt (#777)a19a023chore(README): remove experimental (#775)e6cef75NVD: Add timestamps. (#761)1371f72(fix): Make the table output less wide. (#763)8ecaa2fAdd gitHubToken to prevent rate limit problems (#769)8132174Add helm chart to install trivy in server mode. (#751)bcc2850chore(docs): add nix install (#762)cb36972HTML template (#567)Docker images
docker pull docker.io/aquasec/trivy:0.15.0docker pull docker.io/aquasec/trivy:latestdocker pull ghcr.io/aquasecurity/trivy:0.15.0docker pull ghcr.io/aquasecurity/trivy:latestv0.14.0Features
Add primary URLs (#752)
Trivy shows a primary URL in the result as follows.
In these cases, you can see
https://avd.aquasec.com/nvd/cve-2020-28928as a primary URL.Remove rpm dependency (#753)
Trivy no longer requires the
rpmcommand on the host. You can scan a RHEL-based image without rpm.Bug fixes
--light shows less results (#755)
There was a bug where vulnerabilities with unknown severity do not appear in the result when using the
--lightoption.Changelog
9bdbeabfeat: remove rpm dependency (#753)d85cb77fix(vulnerability): make an empty severity UNKNOWN (#759)1bee83cchore(README): add TRIVY_INSECURE (#760)4d18943feat(vulnerability): add primary URLs (#752)Docker images
docker pull docker.io/aquasec/trivy:0.14.0docker pull docker.io/aquasec/trivy:latestdocker pull ghcr.io/aquasecurity/trivy:0.14.0docker pull ghcr.io/aquasecurity/trivy:latestv0.13.0Important change
Support npm and RubyGems versioning semantics (#740)
npm and RubyGems have different versioning/constraint semantics from other languages, so we developed libraries for them. In the future, we will probably develop libraries for other languages such as Python.
New features
Skip downloading DB if a remote DB is not updated (#717)
Once the vulnerability DB is downloaded, it will not be updated within one hour so that Trivy will not download the same DB many times by mistake.
Support
Add back support for FreeBSD & OpenBSD (#728)
Provide binaries for FreeBSD & OpenBSD
Add support for ppc64le architecture (#724)
Provide binaries for the ppc64le (Power) architecture.
Bug fixes
Handle ksplice advisories of Oracle Linux(#745)
Skip ksplice advisories when the installed package is not a ksplice package during Oracle Linux scanning. Also, if the package is a ksplice one, we should not use the normal advisories.
Skip packages from unsupported repository (remi) (#695)
Skip scanning RPM packages installed from the remi repository
Changelog
1391b3bfix(oracle): handle ksplice advisories (#745)b6d5b82fix: version comparison (#740)9dfb0feupdated Readme.md (#737)4555469Add suse sles 15.2 to the EOL list as well (#734)c189aa6Update README.md (#731)8442528Warn when a user attempts to use trivy without a detectable lockfile (#729)d09787eAdd back support for FreeBSD & OpenBSD (#728)0285a89Add support for ppc64le architecture (#724)7d7784fSkip packages from unsupported repository (remi) (#695)ca6f196Skip downloading DB if a remote DB is not updated (#717)e621cf2Sunsetting VendorVectors (#718)906ab54Add GitHub Container Registry to README (#712)1549c25update BUG_REPORT.md using H2 instead of bold formatting (#714)fe1d07efix(ci/deb): do not remove old packages for EOL versions (#706)793a1aaAdd linter check support (#679)4a94477Optimize images (#696)9bc2b19Update triage.md (#701)Docker images
docker pull docker.io/aquasec/trivy:0.13.0docker pull docker.io/aquasec/trivy:latestdocker pull ghcr.io/aquasecurity/trivy:0.13.0docker pull ghcr.io/aquasecurity/trivy:latestConfiguration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR has been generated by Mend Renovate CLI.
21d6c9e67e73d09bf735View command line instructions
Checkout
From your project repository, check out a new branch and test the changes.Merge
Merge the changes and update on Forgejo.Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.