Skip to content

Commit 22b19b8

Browse files
dependabot[bot]afsmeira
authored andcommitted
chore(deps): bump github.com/aquasecurity/trivy from 0.59.1 to 0.60.0
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy) from 0.59.1 to 0.60.0. - [Release notes](https://github.com/aquasecurity/trivy/releases) - [Changelog](https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md) - [Commits](aquasecurity/trivy@v0.59.1...v0.60.0) --- updated-dependencies: - dependency-name: github.com/aquasecurity/trivy dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <[email protected]>
1 parent c30bd87 commit 22b19b8

File tree

4 files changed

+169
-147
lines changed

4 files changed

+169
-147
lines changed

.circleci/config.yml

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -9,14 +9,14 @@ references:
99
persist_to_workspace: true
1010
# https://aquasecurity.github.io/trivy/v0.59/getting-started/installation/#install-script
1111
cmd: |
12-
curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b . v0.59.1
12+
curl -sfL https://raw.githubusercontent.com/aquasecurity/trivy/main/contrib/install.sh | sh -s -- -b . v0.60.0
1313
mkdir cache
1414
./trivy --cache-dir ./cache image --download-db-only
1515
1616
build_and_publish_docker: &build_and_publish_docker
1717
persist_to_workspace: true
1818
cmd: |
19-
docker build -t $CIRCLE_PROJECT_REPONAME:latest --build-arg TRIVY_VERSION=0.59.1 .
19+
docker build -t $CIRCLE_PROJECT_REPONAME:latest --build-arg TRIVY_VERSION=0.60.0 .
2020
docker save --output docker-image.tar $CIRCLE_PROJECT_REPONAME:latest
2121
2222
workflows:

Dockerfile

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,4 @@
1-
FROM golang:1.23-alpine as builder
1+
FROM golang:1.24-alpine as builder
22

33
ARG TRIVY_VERSION=dev
44
ENV TRIVY_VERSION=$TRIVY_VERSION

go.mod

Lines changed: 50 additions & 47 deletions
Original file line numberDiff line numberDiff line change
@@ -1,13 +1,13 @@
11
module github.com/codacy/codacy-trivy
22

3-
go 1.23.5
3+
go 1.24
44

5-
toolchain go1.23.6
5+
toolchain go1.24.1
66

77
require (
88
github.com/CycloneDX/cyclonedx-go v0.9.2
9-
github.com/aquasecurity/trivy v0.59.1 // Also update .config.yml
10-
github.com/aquasecurity/trivy-db v0.0.0-20241209111357-8c398f13db0e
9+
github.com/aquasecurity/trivy v0.60.0 // Also update .config.yml
10+
github.com/aquasecurity/trivy-db v0.0.0-20250227071930-8bd8a9b89e2d
1111
github.com/codacy/codacy-engine-golang-seed/v6 v6.3.0
1212
github.com/google/go-cmp v0.7.0
1313
github.com/package-url/packageurl-go v0.1.3
@@ -20,8 +20,8 @@ require (
2020
require (
2121
cel.dev/expr v0.19.0 // indirect
2222
cloud.google.com/go v0.116.0 // indirect
23-
cloud.google.com/go/auth v0.13.0 // indirect
24-
cloud.google.com/go/auth/oauth2adapt v0.2.6 // indirect
23+
cloud.google.com/go/auth v0.14.0 // indirect
24+
cloud.google.com/go/auth/oauth2adapt v0.2.7 // indirect
2525
cloud.google.com/go/compute/metadata v0.6.0 // indirect
2626
cloud.google.com/go/iam v1.2.2 // indirect
2727
cloud.google.com/go/monitoring v1.21.2 // indirect
@@ -31,7 +31,7 @@ require (
3131
github.com/AdamKorcz/go-118-fuzz-build v0.0.0-20231105174938-2b5cbb29f3e2 // indirect
3232
github.com/Azure/azure-sdk-for-go v68.0.0+incompatible // indirect
3333
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.17.0 // indirect
34-
github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.8.1 // indirect
34+
github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.8.2 // indirect
3535
github.com/Azure/azure-sdk-for-go/sdk/internal v1.10.0 // indirect
3636
github.com/Azure/go-ansiterm v0.0.0-20230124172434-306776ec8161 // indirect
3737
github.com/Azure/go-autorest v14.2.0+incompatible // indirect
@@ -40,7 +40,7 @@ require (
4040
github.com/Azure/go-autorest/autorest/date v0.3.0 // indirect
4141
github.com/Azure/go-autorest/logger v0.2.1 // indirect
4242
github.com/Azure/go-autorest/tracing v0.6.0 // indirect
43-
github.com/AzureAD/microsoft-authentication-library-for-go v1.3.2 // indirect
43+
github.com/AzureAD/microsoft-authentication-library-for-go v1.3.3 // indirect
4444
github.com/BurntSushi/toml v1.4.0 // indirect
4545
github.com/DataDog/zstd v1.5.5 // indirect
4646
github.com/GoogleCloudPlatform/docker-credential-gcr v2.0.5+incompatible // indirect
@@ -73,27 +73,27 @@ require (
7373
github.com/aquasecurity/jfather v0.0.8 // indirect
7474
github.com/aquasecurity/table v1.8.0 // indirect
7575
github.com/aquasecurity/tml v0.6.1 // indirect
76-
github.com/aquasecurity/trivy-checks v1.6.1 // indirect
76+
github.com/aquasecurity/trivy-checks v1.7.1 // indirect
7777
github.com/aquasecurity/trivy-java-db v0.0.0-20240109071736-184bd7481d48 // indirect
7878
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2 // indirect
7979
github.com/aws/aws-sdk-go v1.55.6 // indirect
80-
github.com/aws/aws-sdk-go-v2 v1.34.0 // indirect
81-
github.com/aws/aws-sdk-go-v2/config v1.29.2 // indirect
82-
github.com/aws/aws-sdk-go-v2/credentials v1.17.55 // indirect
83-
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.25 // indirect
84-
github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.29 // indirect
85-
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.29 // indirect
86-
github.com/aws/aws-sdk-go-v2/internal/ini v1.8.2 // indirect
80+
github.com/aws/aws-sdk-go-v2 v1.36.3 // indirect
81+
github.com/aws/aws-sdk-go-v2/config v1.29.8 // indirect
82+
github.com/aws/aws-sdk-go-v2/credentials v1.17.61 // indirect
83+
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.16.30 // indirect
84+
github.com/aws/aws-sdk-go-v2/internal/configsources v1.3.34 // indirect
85+
github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.6.34 // indirect
86+
github.com/aws/aws-sdk-go-v2/internal/ini v1.8.3 // indirect
8787
github.com/aws/aws-sdk-go-v2/service/ebs v1.22.1 // indirect
88-
github.com/aws/aws-sdk-go-v2/service/ec2 v1.201.1 // indirect
89-
github.com/aws/aws-sdk-go-v2/service/ecr v1.38.7 // indirect
90-
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.12.2 // indirect
91-
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.10 // indirect
92-
github.com/aws/aws-sdk-go-v2/service/s3 v1.74.1 // indirect
93-
github.com/aws/aws-sdk-go-v2/service/sso v1.24.12 // indirect
94-
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.28.11 // indirect
95-
github.com/aws/aws-sdk-go-v2/service/sts v1.33.10 // indirect
96-
github.com/aws/smithy-go v1.22.2 // indirect
88+
github.com/aws/aws-sdk-go-v2/service/ec2 v1.206.0 // indirect
89+
github.com/aws/aws-sdk-go-v2/service/ecr v1.42.0 // indirect
90+
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.12.3 // indirect
91+
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.12.15 // indirect
92+
github.com/aws/aws-sdk-go-v2/service/s3 v1.78.0 // indirect
93+
github.com/aws/aws-sdk-go-v2/service/sso v1.25.0 // indirect
94+
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.29.0 // indirect
95+
github.com/aws/aws-sdk-go-v2/service/sts v1.33.16 // indirect
96+
github.com/aws/smithy-go v1.22.3 // indirect
9797
github.com/beorn7/perks v1.0.1 // indirect
9898
github.com/bgentry/go-netrc v0.0.0-20140422174119-9fd32a8b3d3d // indirect
9999
github.com/bitnami/go-version v0.0.0-20231130084017-bb00604d650c // indirect
@@ -156,6 +156,7 @@ require (
156156
github.com/go-gorp/gorp/v3 v3.1.0 // indirect
157157
github.com/go-ini/ini v1.67.0 // indirect
158158
github.com/go-jose/go-jose/v4 v4.0.5 // indirect
159+
github.com/go-json-experiment/json v0.0.0-20250211171154-1ae217ad3535 // indirect
159160
github.com/go-logr/logr v1.4.2 // indirect
160161
github.com/go-logr/stdr v1.2.2 // indirect
161162
github.com/go-openapi/analysis v0.23.0 // indirect
@@ -185,7 +186,7 @@ require (
185186
github.com/google/go-querystring v1.1.0 // indirect
186187
github.com/google/gofuzz v1.2.0 // indirect
187188
github.com/google/licenseclassifier/v2 v2.0.0 // indirect
188-
github.com/google/s2a-go v0.1.8 // indirect
189+
github.com/google/s2a-go v0.1.9 // indirect
189190
github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 // indirect
190191
github.com/google/uuid v1.6.0 // indirect
191192
github.com/google/wire v0.6.0 // indirect
@@ -235,14 +236,13 @@ require (
235236
github.com/masahiro331/go-disk v0.0.0-20240625071113-56c933208fee // indirect
236237
github.com/masahiro331/go-ebs-file v0.0.0-20240917043618-e6d2bea5c32e // indirect
237238
github.com/masahiro331/go-ext4-filesystem v0.0.0-20240620024024-ca14e6327bbd // indirect
238-
github.com/masahiro331/go-mvn-version v0.0.0-20210429150710-d3157d602a08 // indirect
239+
github.com/masahiro331/go-mvn-version v0.0.0-20250131095131-f4974fa13b8a // indirect
239240
github.com/masahiro331/go-vmdk-parser v0.0.0-20221225061455-612096e4bbbd // indirect
240241
github.com/masahiro331/go-xfs-filesystem v0.0.0-20231205045356-1b22259a6c44 // indirect
241242
github.com/mattn/go-colorable v0.1.14 // indirect
242243
github.com/mattn/go-isatty v0.0.20 // indirect
243244
github.com/mattn/go-runewidth v0.0.16 // indirect
244245
github.com/mattn/go-shellwords v1.0.12 // indirect
245-
github.com/microsoft/go-rustaudit v0.0.0-20220808201409-204dfee52032 // indirect
246246
github.com/mitchellh/copystructure v1.2.0 // indirect
247247
github.com/mitchellh/go-homedir v1.1.0 // indirect
248248
github.com/mitchellh/go-testing-interface v1.14.1 // indirect
@@ -267,6 +267,7 @@ require (
267267
github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f // indirect
268268
github.com/nozzle/throttler v0.0.0-20180817012639-2ea982251481 // indirect
269269
github.com/oklog/ulid v1.3.1 // indirect
270+
github.com/oklog/ulid/v2 v2.1.0 // indirect
270271
github.com/open-policy-agent/opa v1.1.0 // indirect
271272
github.com/opencontainers/go-digest v1.0.0 // indirect
272273
github.com/opencontainers/image-spec v1.1.0 // indirect
@@ -277,7 +278,7 @@ require (
277278
github.com/openvex/discovery v0.1.1-0.20240802171711-7c54efc57553 // indirect
278279
github.com/openvex/go-vex v0.2.5 // indirect
279280
github.com/owenrumney/go-sarif/v2 v2.3.3 // indirect
280-
github.com/owenrumney/squealer v1.2.6 // indirect
281+
github.com/owenrumney/squealer v1.2.11 // indirect
281282
github.com/pelletier/go-toml/v2 v2.2.3 // indirect
282283
github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
283284
github.com/pjbgf/sha1cd v0.3.2 // indirect
@@ -293,8 +294,10 @@ require (
293294
github.com/rivo/uniseg v0.4.7 // indirect
294295
github.com/rubenv/sql-migrate v1.7.1 // indirect
295296
github.com/russross/blackfriday/v2 v2.1.0 // indirect
297+
github.com/rust-secure-code/go-rustaudit v0.0.0-20250226111315-e20ec32e963c // indirect
296298
github.com/sagikazarmark/locafero v0.6.0 // indirect
297299
github.com/sagikazarmark/slog-shim v0.1.0 // indirect
300+
github.com/samber/oops v1.15.0 // indirect
298301
github.com/santhosh-tekuri/jsonschema/v5 v5.3.1 // indirect
299302
github.com/sassoftware/go-rpmutils v0.4.0 // indirect
300303
github.com/sassoftware/relic v7.2.1+incompatible // indirect
@@ -303,7 +306,7 @@ require (
303306
github.com/shibumi/go-pathspec v1.3.0 // indirect
304307
github.com/shopspring/decimal v1.4.0 // indirect
305308
github.com/sigstore/cosign/v2 v2.2.4 // indirect
306-
github.com/sigstore/rekor v1.3.8 // indirect
309+
github.com/sigstore/rekor v1.3.9 // indirect
307310
github.com/sigstore/sigstore v1.8.12 // indirect
308311
github.com/sigstore/timestamp-authority v1.2.2 // indirect
309312
github.com/sirupsen/logrus v1.9.3 // indirect
@@ -312,15 +315,15 @@ require (
312315
github.com/spdx/tools-golang v0.5.5 // indirect
313316
github.com/spf13/afero v1.11.0 // indirect
314317
github.com/spf13/cast v1.7.1 // indirect
315-
github.com/spf13/cobra v1.8.1 // indirect
316-
github.com/spf13/pflag v1.0.5 // indirect
318+
github.com/spf13/cobra v1.9.1 // indirect
319+
github.com/spf13/pflag v1.0.6 // indirect
317320
github.com/spf13/viper v1.19.0 // indirect
318321
github.com/stretchr/objx v0.5.2 // indirect
319322
github.com/subosito/gotenv v1.6.0 // indirect
320323
github.com/syndtr/gocapability v0.0.0-20200815063812-42c35b437635 // indirect
321324
github.com/syndtr/goleveldb v1.0.1-0.20220721030215-126854af5e6d // indirect
322325
github.com/tchap/go-patricia/v2 v2.3.2 // indirect
323-
github.com/tetratelabs/wazero v1.8.2 // indirect
326+
github.com/tetratelabs/wazero v1.9.0 // indirect
324327
github.com/theupdateframework/go-tuf v0.7.0 // indirect
325328
github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399 // indirect
326329
github.com/tonistiigi/go-csvvalue v0.0.0-20240710180619-ddb21b71c0b4 // indirect
@@ -340,7 +343,7 @@ require (
340343
github.com/yashtewari/glob-intersection v0.2.0 // indirect
341344
github.com/zclconf/go-cty v1.16.2 // indirect
342345
github.com/zclconf/go-cty-yaml v1.1.0 // indirect
343-
go.etcd.io/bbolt v1.3.11 // indirect
346+
go.etcd.io/bbolt v1.4.0 // indirect
344347
go.mongodb.org/mongo-driver v1.14.0 // indirect
345348
go.opencensus.io v0.24.0 // indirect
346349
go.opentelemetry.io/auto/sdk v1.1.0 // indirect
@@ -354,35 +357,35 @@ require (
354357
go.opentelemetry.io/otel/trace v1.34.0 // indirect
355358
go.uber.org/multierr v1.11.0 // indirect
356359
go.uber.org/zap v1.27.0 // indirect
357-
golang.org/x/crypto v0.32.0 // indirect
360+
golang.org/x/crypto v0.33.0 // indirect
358361
golang.org/x/exp v0.0.0-20250106191152-7588d65b2ba8 // indirect
359-
golang.org/x/net v0.34.0 // indirect
362+
golang.org/x/net v0.35.0 // indirect
360363
golang.org/x/oauth2 v0.25.0 // indirect
361-
golang.org/x/sync v0.10.0 // indirect
362-
golang.org/x/sys v0.29.0 // indirect
363-
golang.org/x/term v0.28.0 // indirect
364-
golang.org/x/text v0.21.0 // indirect
364+
golang.org/x/sync v0.11.0 // indirect
365+
golang.org/x/sys v0.30.0 // indirect
366+
golang.org/x/term v0.29.0 // indirect
367+
golang.org/x/text v0.22.0 // indirect
365368
golang.org/x/time v0.9.0 // indirect
366369
golang.org/x/tools v0.29.0 // indirect
367370
golang.org/x/xerrors v0.0.0-20240716161551-93cc26a95ae9 // indirect
368-
google.golang.org/api v0.216.0 // indirect
371+
google.golang.org/api v0.218.0 // indirect
369372
google.golang.org/genproto v0.0.0-20241118233622-e639e219e697 // indirect
370373
google.golang.org/genproto/googleapis/api v0.0.0-20250115164207-1a7da9e5054f // indirect
371374
google.golang.org/genproto/googleapis/rpc v0.0.0-20250115164207-1a7da9e5054f // indirect
372375
google.golang.org/grpc v1.70.0 // indirect
373-
google.golang.org/protobuf v1.36.4 // indirect
376+
google.golang.org/protobuf v1.36.5 // indirect
374377
gopkg.in/cheggaaa/pb.v1 v1.0.28 // indirect
375378
gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
376379
gopkg.in/inf.v0 v0.9.1 // indirect
377380
gopkg.in/ini.v1 v1.67.0 // indirect
378381
gopkg.in/warnings.v0 v0.1.2 // indirect
379382
gopkg.in/yaml.v3 v3.0.1 // indirect
380383
gotest.tools/v3 v3.5.0 // indirect
381-
helm.sh/helm/v3 v3.17.0 // indirect
382-
k8s.io/api v0.32.1 // indirect
383-
k8s.io/apiextensions-apiserver v0.32.0 // indirect
384-
k8s.io/apimachinery v0.32.1 // indirect
385-
k8s.io/apiserver v0.32.0 // indirect
384+
helm.sh/helm/v3 v3.17.1 // indirect
385+
k8s.io/api v0.32.2 // indirect
386+
k8s.io/apiextensions-apiserver v0.32.1 // indirect
387+
k8s.io/apimachinery v0.32.2 // indirect
388+
k8s.io/apiserver v0.32.1 // indirect
386389
k8s.io/cli-runtime v0.32.1 // indirect
387390
k8s.io/client-go v0.32.1 // indirect
388391
k8s.io/component-base v0.32.1 // indirect

0 commit comments

Comments
 (0)