🌱 Update Builder Image group #169
Merged
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.51.3->0.59.17dba9a9->3c206a43.20.0->3.21.3a8712f2->c62751av1.58.2->v1.64.5Release Notes
aquasecurity/trivy (docker.io/aquasec/trivy)
v0.59.1Compare Source
Changelog
9aabfd2release: v0.59.1 [release/v0.59] (#8334)412c690fix(misconf): do not log scanners when misconfig scanning is disabled [backport: release/v0.59] (#8349)98f9ba2chore(deps): bump Go tov1.23.5[backport: release/v0.59] (#8343)1741fddfix(python): addpoetryv2 support [backport: release/v0.59] (#8335)3fd8e27fix(sbom): preserve OS packages from multiple SBOMs [backport: release/v0.59] (#8333)v0.59.0Compare Source
Features
--distroflag to manually specify OS distribution for vulnerability scanning (#8070) (da17dc7)Bug Fixes
dpkgpackages with different filePaths from different layers (#8298) (846498d)--generate-default-configcommand (#8046) (5e68bdc)BLOW_UNKNOWNerror to download DBs (#8060) (51f2123)project.*props (#8050) (9d9f80d)usr/share/buildinfo/dir to detect content sets (#8222) (f352f6b)unknowndependencies (if exists) (#8104) (7558df7)hasExtractedLicensingInfosfield for licenses that are not listed in the SPDX (#8077) (aec8885)Performance Improvements
v0.58.2Compare Source
Changelog
936f06arelease: v0.58.2 [release/v0.58] (#8216)f72d2bcfix(misconf): allow null values only for tf variables [backport: release/v0.58] (#8238)2896367fix(suse): SUSE - update OSType constants and references for compatility [backport: release/v0.58] (#8237)b733eccfix: CVE-2025-21613 and CVE-2025-21614 : go-git: argument injection via the URL field [backport: release/v0.58] (#8215)v0.58.1Compare Source
⚡Release highlights and summary⚡
👉 https://github.com/aquasecurity/trivy/discussions/8171
Changelog
https://github.com/aquasecurity/trivy/blob/release/v0.58/CHANGELOG.md#0581-2024-12-24
v0.58.0Compare Source
Features
workspaceRelationship(#7889) (d622ca2)go.modmain module in the parser (#7977) (5448ba2)flavorssupport (#7858) (b9b383e)Bug Fixes
UIDfor removed packages (#7887) (07915da)mirror.gcr.io(#7953) (9988147)root/buildinfo/content_manifests/contains files that are notcontentSetsfiles (#7912) (38775a5)[email protected]schema for misconfigs insarifreport (#7898) (19aea4b)v0.57.1Compare Source
⚡Release highlights and summary⚡
👉https://github.com/aquasecurity/trivy/discussions/7951
Changelog
https://github.com/aquasecurity/trivy/blob/release/v0.57/CHANGELOG.md#0571-2024-11-18
v0.57.0Compare Source
⚠ BREAKING CHANGES
Features
trivy auth(#7664) (27117f8)trivy authtotrivy registry(#7727) (633a7ab)CycloneDXreports (#7507) (c225883)Bug Fixes
clean --alldeletes only relevant dirs (#7704) (672e886)versionandscopefrom upper/rootdepManagementanddependenciesinto parents (#7541) (778df82)git cloneoutput to Stderr (#7561) (fdf203c)Annotationinstead ofAttributionTextsforSPDXformats (#7811) (f2bb9c6)v0.56.2Compare Source
Changelog
f2252c8release: v0.56.2 [release/v0.56] (#7694)f6700ecfix(redhat): include arch in PURL qualifiers [backport: release/v0.56] (#7702)25d2540fix(sbom): add options for DBs in private registries [backport: release/v0.56] (#7691)v0.56.1Compare Source
Changelog
95dbf11release: v0.56.1 [release/v0.56] (#7648)5dbdadffix(db): fix javadb downloading error handling [backport: release/v0.56] (#7646)v0.56.0Compare Source
Features
pom.xmldependency versions can't be detected (#7520) (b836232)--skip-*for all included modules (#7579) (c0e8da3)Bug Fixes
DownloadedAtfortrivy-java-db(#7592) (13ef3e7)dependencyManagementfrom root/child pom's for dependencies from parents (#7497) (5442949)ExperimentalModifiedFindings(#7463) (7ff9aff)frameworkaslibrarywhen unmarshallingCycloneDXfiles (#7527) (aeb7039)Performance Improvements
Reverts
testscope forpom.xmlfiles (#7488) (b0222fe)v0.55.2Compare Source
Changelog
928c7c0release: v0.55.2 [release/v0.55] (#7523)14a058ffix(java): usedependencyManagementfrom root/child pom's for dependencies from parents [backport: release/v0.55] (#7521)990bc4echore(deps): bump alpine from 3.20.0 to 3.20.3 [backport: release/v0.55] (#7516)v0.55.1Compare Source
⚡Release highlights and summary⚡
👉https://github.com/aquasecurity/trivy/discussions/7494
Changelog
https://github.com/aquasecurity/trivy/blob/release/v0.55/CHANGELOG.md#0551-2024-09-12
v0.55.0Compare Source
⚠ BREAKING CHANGES
Features
toolchainasstdlibversion forgo.modfiles (#7163) (2d80769)testscope support forpom.xmlfiles (#7414) (2d97700)--path-prefixflag for client/server mode (#7321) (24a4563)--detection-priorityflag for accuracy tuning (#7288) (fd8348d)Bug Fixes
--clear-cache(#7281) (2a0e529)kindandapiVersionofvolumeClaimTemplateelement (#7362) (da4ebfa)importersto detect dev deps from pnpm-lock.yaml file (#7387) (fd9ed3a)Messagefield inasff.tpltemplate (#7401) (dd9733e)NOASSERTIONfor licenses fields in SPDX formats (#7403) (c96dcdd).eyJkeyword for JWT secret (#7410) (bf64003)Performance Improvements
v0.54.1Compare Source
Changelog
854c61drelease: v0.54.1 [release/v0.54] (#7282)334a1c2fix(flag): incorrect behavior for deprected flag--clear-cache[backport: release/v0.54] (#7285)f61725cfix(java): Return error when trying to find a remote pom to avoid segfault [backport: release/v0.54] (#7283)a7b7117fix(plugin): do not call GitHub content API for releases and tags [backport: release/v0.54] (#7279)v0.54.0Compare Source
Features
log.FilePath()function for logger (#7080) (1f5f348)--vuln-typeflag to--pkg-typesflag (#7104) (7cbdb0a)SPDXandCycloneDXreports (#7257) (4a2f492)--pkg-relationships(#7237) (5c37361)Bug Fixes
*.deps.jsonfiles (#7039) (5bc662b)nuget package dir not foundlog only when checkingnugetpackages (#7194) (d76feba)pominitdir are not found (#7245) (4e54a7e)go-mvn-versionto removePackageduplicates (#7088) (a7a304d)latestversion for filesyarn.lock+package.json(#7110) (54bb8bd)Configuration
📅 Schedule: Branch creation - "on the first day of the month" in timezone Europe/Berlin, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.