Skip to content
This repository has been archived by the owner on Oct 14, 2024. It is now read-only.

chore(deps): update docker.io/aquasec/trivy docker tag to v0.49.1 #1215

Merged
merged 2 commits into from
Feb 9, 2024

Conversation

renovate[bot]
Copy link
Contributor

@renovate renovate bot commented Feb 8, 2024

Mend Renovate

This PR contains the following updates:

Package Update Change
docker.io/aquasec/trivy (source) minor 0.41.0 -> 0.49.1

Release Notes

aquasecurity/trivy (docker.io/aquasec/trivy)

v0.49.1

Compare Source

Changelog

  • 6ccc0a5 fix: check unescaped BomRef when matching PkgIdentifier (#​6025)
  • 458c5d9 docs: Fix broken link to "pronunciation" (#​6057)
  • 5c0ff6d chore(deps): bump actions/upload-artifact from 3 to 4 (#​6047)
  • e2bd7f7 chore(deps): bump github.com/spf13/viper from 1.16.0 to 1.18.2 (#​6042)
  • f95fbcb chore(deps): bump k8s.io/api from 0.29.0 to 0.29.1 (#​6043)
  • 7651bf5 ci: reduce root-reserve-mb size for maximize-build-space (#​6064)
  • fc20dfd chore(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.48.0 to 1.48.1 (#​6041)
  • 3bd80e7 chore(deps): bump github.com/open-policy-agent/opa from 0.60.0 to 0.61.0 (#​6039)
  • 2900a21 fix: fix cursor usage in Redis Clear function (#​6056)
  • 85cb9a7 chore(deps): bump github.com/go-openapi/runtime from 0.26.0 to 0.27.1 (#​6037)
  • 4e962c0 fix(nodejs): add local packages support for pnpm-lock.yaml files (#​6034)
  • aa48a7b chore(deps): bump sigstore/cosign-installer from 3.3.0 to 3.4.0 (#​6046)
  • 8aabbea chore(deps): bump github.com/go-openapi/strfmt from 0.21.7 to 0.22.0 (#​6044)
  • ec02a65 chore(deps): bump actions/cache from 3.3.2 to 4.0.0 (#​6048)
  • 27d35ba test: fix flaky TestDockerEngine (#​6054)
  • c3a66da chore(deps): bump github.com/google/go-containerregistry from 0.17.0 to 0.19.0 (#​6040)
  • 2000fe2 chore(deps): bump easimon/maximize-build-space from 9 to 10 (#​6049)
  • 2be6421 chore(deps): bump alpine from 3.19.0 to 3.19.1 (#​6051)
  • 41c0ef6 chore(deps): bump github.com/moby/buildkit from 0.11.6 to 0.12.5 (#​6028)

v0.49.0

Compare Source

⚡Release highlights and summary⚡

👉 https://github.com/aquasecurity/trivy/discussions/6033

Changelog

  • 729a051 fix(java): recursive check all nested depManagements with import scope for pom.xml files (#​5982)
  • 884745b chore(deps): bump github.com/opencontainers/runc from 1.1.5 to 1.1.12 (#​6029)
  • 59e5433 fix(cli): inconsistent behavior across CLI flags, environment variables, and config files (#​5843)
  • 5924c02 feat(rust): Support workspace.members parsing for Cargo.toml analysis (#​5285)
  • 4df9363 docs: add note about Bun (#​6001)
  • 70dd572 fix(report): use AWS_REGION env for secrets in asff template (#​6011)
  • 13f797f fix: check returned error before deferring f.Close() (#​6007)
  • adfde63 feat(misconf): add support of buildkit instructions when building dockerfile from image config (#​5990)
  • e2eb70e feat(vuln): enable --vex for all targets (#​5992)
  • f9da021 docs: update link to data sources (#​6000)
  • b4b90cf feat(java): add support for line numbers for pom.xml files (#​5991)
  • fb36c4e refactor(sbom): use new metadata.tools struct for CycloneDX (#​5981)
  • f6be42b docs: Update troubleshooting guide with image not found error (#​5983)
  • bb6caea style: update band logos (#​5968)
  • 189a46a chore(deps): Update misconfig deps (#​5956)
  • 91a2547 docs: update cosign tutorial and commands, update kyverno policy (#​5929)
  • a96f66f docs: update command to scan go binary (#​5969)
  • 2212d14 fix: handle non-parsable images names (#​5965)
  • 7cad04b chore(deps): bump aquaproj/aqua-installer from 2.1.2 to 2.2.0 (#​5693)
  • fbc1a83 fix(amazon): save system files for pkgs containing amzn in src (#​5951)
  • 260aa28 fix(alpine): Add EOL support for alpine 3.19. (#​5938)
  • 2c9d7c6 feat: allow end-users to adjust K8S client QPS and burst (#​5910)
  • ffe2ca7 chore(deps): bump go-ebs-file (#​5934)
  • f90d4ee fix(nodejs): find licenses for packages with slash (#​5836)
  • c75143f fix(sbom): use group field for pom.xml and nodejs files for CycloneDX reports (#​5922)
  • a3fac90 fix: ignore no init containers (#​5939)
  • b1b4734 docs: Fix documentation of ecosystem (#​5940)
  • a2b6549 docs(misconf): multiple ignores in comment (#​5926)
  • ae134a9 fix(secret): find aws secrets ending with a comma or dot (#​5921)
  • c8c55fe chore(deps): bump github.com/aws/aws-sdk-go-v2/feature/s3/manager from 1.11.90 to 1.15.11 (#​5885)
  • 4d2e785 docs: ✨ Updated ecosystem docs with reference to new community app (#​5918)
  • 7895657 fix(java): don't remove excluded deps from upper pom's (#​5838)
  • 37e7e3e fix(java): check if a version exists when determining GAV by file name for jar files (#​5630)
  • d0c81e2 feat(vex): add PURL matching for CSAF VEX (#​5890)
  • 958e1f1 fix(secret): AWS Secret Access Key must include only secrets with aws text. (#​5901)
  • 56c4e24 revert(report): don't escape new line characters for sarif format (#​5897)
  • 92d9b3d docs: improve filter by rego (#​5402)
  • a626cdf chore(deps): bump github.com/cloudflare/circl from 1.3.6 to 1.3.7 (#​5892)
  • 47b6c28 docs: add_scan2html_to_trivy_ecosystem (#​5875)
  • 0ebb6c4 fix(vm): update ext4-filesystem fix reading groupdescriptor in 32bit mode (#​5888)
  • c47ed0d feat(vex): Add support for CSAF format (#​5535)
  • 2cdd65d chore(deps): bump github.com/aws/aws-sdk-go-v2/service/sts from 1.26.2 to 1.26.7 (#​5880)
  • cba67d1 chore(deps): bump actions/setup-go from 4 to 5 (#​5845)
  • d990e70 chore(deps): bump actions/stale from 8 to 9 (#​5846)
  • c72dfbf chore(deps): bump github.com/open-policy-agent/opa from 0.58.0 to 0.60.0 (#​5853)
  • 1218984 chore(deps): bump sigstore/cosign-installer from 3.2.0 to 3.3.0 (#​5847)
  • 682210a chore(deps): bump modernc.org/sqlite from 1.23.1 to 1.28.0 (#​5854)
  • e1a60cc chore(deps): bump alpine from 3.18.5 to 3.19.0 (#​5849)
  • b508414 chore(deps): bump actions/setup-python from 4 to 5 (#​5848)
  • df3e90a feat(python): parse licenses from dist-info folder (#​4724)
  • fa2e883 chore(deps): bump github.com/secure-systems-lab/go-securesystemslib from 0.7.0 to 0.8.0 (#​5852)
  • 30eff9c feat(nodejs): add yarn alias support (#​5818)
  • 013df4c chore(deps): bump github.com/samber/lo from 1.38.1 to 1.39.0 (#​5850)
  • b1489f3 chore(deps): bump github.com/hashicorp/go-getter from 1.7.2 to 1.7.3 (#​5856)
  • 7f2e422 chore(deps): bump google.golang.org/protobuf from 1.31.0 to 1.32.0 (#​5855)
  • da597c4 refactor: propagate time through context values (#​5858)
  • 1607eee refactor: move PkgRef under PkgIdentifier (#​5831)
  • b3d516e fix(cyclonedx): fix unmarshal for licenses (#​5828)
  • c17b660 chore(deps): bump github.com/go-git/go-git/v5 from 5.10.1 to 5.11.0 (#​5830)
  • 1f0d629 feat(vuln): include pkg identifier on detected vulnerabilities (#​5439)

v0.48.3

Compare Source

Changelog

  • eac7513 chore(deps): bump github.com/cloudflare/circl from 1.3.6 to 1.3.7 (#​5892)
  • d866b71 chore(deps): bump google.golang.org/protobuf from 1.31.0 to 1.32.0 (#​5855)
  • 34ba96e chore(deps): bump github.com/go-git/go-git/v5 from 5.10.1 to 5.11.0 (#​5830)

v0.48.2

Compare Source

Changelog

  • 4cdff0e chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from v1.116.0 to v1.134.0 (#​5822)
  • be969d4 chore(deps): bump github.com/containerd/containerd from 1.7.7 to 1.7.11 (#​5809)
  • 81748f5 chore(deps): bump golang.org/x/crypto from 0.15.0 to 0.17.0 (#​5805)

v0.48.1

Compare Source

Changelog

  • ba825b2 chore(deps): bump trivy-iac to v0.7.1 (#​5797)
  • abf227e fix(bitnami): use a different comparer for detecting vulnerabilities (#​5633)
  • df49ea4 refactor(sbom): disable html escaping for CycloneDX (#​5764)
  • f25e2df refactor(purl): use pub from package-url (#​5784)
  • b5e3b77 docs(python): add note to using pip freeze for compatible releases (#​5760)
  • 6cc00c2 fix(report): use OS information for OS packages purl in github template (#​5783)
  • c317fe8 fix(report): fix error if miconfigs are empty (#​5782)
  • 9b4bced refactor(vuln): don't remove VendorSeverity in JSON report (#​5761)
  • be5a550 fix(report): don't mark misconfig passed tests as failed in junit.tpl (#​5767)
  • 01edbda docs(k8s): replace --scanners config with --scanners misconfig in docs (#​5746)
  • eb97419 fix(report): update Gitlab template (#​5721)
  • be1c554 feat(secret): add support of GitHub fine-grained tokens (#​5740)
  • a5342da fix(misconf): add an image misconf to result (#​5731)
  • 108a5b0 feat(secret): added support of Docker registry credentials (#​5720)
  • 6080e24 chore(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.18.45 to 1.25.11 (#​5717)
  • e27ec32 chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ecr from 1.21.0 to 1.24.1 (#​5701)

v0.48.0

Compare Source

⚡Release highlights and summary⚡

👉 https://github.com/aquasecurity/trivy/discussions/5724

Changelog

v0.47.0

Compare Source

⚡Release highlights and summary⚡

👉 https://github.com/aquasecurity/trivy/discussions/5520

Changelog

  • d6df5fb docs: add info that license scanning supports file-patterns flag (#​5484)
  • 156d4cc docs: add Zora integration into Ecosystem session (#​5490)
  • 772d1d0 fix(sbom): Use UUID as BomRef for packages with empty purl (#​5448)
  • df47073 ci: use maximize build space for K8s tests (#​5387)
  • fed4710 fix: correct error mismatch causing race in fast walks (#​5516)
  • 46f1b9e docs: k8s vulnerability scanning (#​5515)
  • fdb3a15 chore(deps): bump github.com/aws/aws-sdk-go-v2/service/sts from 1.23.2 to 1.25.0 (#​5506)
  • d0d956f chore(deps): bump github.com/owenrumney/go-sarif/v2 from 2.2.2 to 2.3.0 (#​5493)
  • 68b0797 docs: remove glad for java datasources (#​5508)
  • 474167c chore(deps): bump github.com/testcontainers/testcontainers-go/modules/localstack from 0.21.0 to 0.26.0 (#​5475)
  • 7299867 chore: remove unused logger attribute in amazon detector (#​5476)
  • 8656bd9 fix: correct error mismatch causing race in fast walks (#​5482)
  • 2e10cd2 chore(deps): bump goreleaser/goreleaser-action from 4 to 5 (#​5502)
  • 13df746 chore(deps): bump docker/build-push-action from 4 to 5 (#​5500)
  • b0141cf chore(deps): bump github.com/package-url/packageurl-go from 0.1.2-0.20230812223828-f8bb31c1f10b to 0.1.2 (#​5491)
  • 520830b fix(server): add licenses to BlobInfo message (#​5382)
  • 9a6e125 chore(deps): bump actions/checkout from 4.1.0 to 4.1.1 (#​5501)
  • 6e59272 chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ecr from 1.17.18 to 1.21.0 (#​5497)
  • f3de7bc feat: scan vulns on k8s core component apps (#​5418)
  • e2fb3dd fix(java): fix infinite loop when relativePath field points to pom.xml being scanned (#​5470)
  • 3e833be chore(deps): bump github.com/docker/docker from 24.0.5+incompatible to 24.0.7+incompatible (#​5472)
  • ca50b77 fix(sbom): save digests for package/application when scanning SBOM files (#​5432)
  • 048150d docs: fix the broken link (#​5454)
  • 013d901 docs: fix error when installing PyYAML for gh pages (#​5462)
  • 26b4959 fix(java): download java-db once (#​5442)
  • 57fa701 chore(deps): bump google.golang.org/grpc from 1.57.0 to 1.57.1 (#​5447)
  • 53c9a7d docs(misconf): Update --tf-exclude-downloaded-modules description (#​5419)
  • 01c98d1 feat(misconf): Support --ignore-policy in config scans (#​5359)
  • 05b3c86 docs(misconf): fix broken table for Use container image section (#​5425)
  • 1a15a3a feat(dart): add graph support (#​5374)
  • f2a12f5 refactor: define a new struct for scan targets (#​5397)
  • 6040d9f fix(sbom): add missed primaryURL and source severity for CycloneDX (#​5399)
  • e5317c7 fix: correct invalid MD5 hashes for rpms ending with one or more zero bytes (#​5393)
  • 9fba79f chore(deps): move to aws-sdk-go-v2 (#​5381)
  • 00f2059 docs: remove --scanners none (#​5384)
  • 57a1022 docs: Update container_image.md #​5182 (#​5193)
  • 5b2b4ea feat(report): Add InstalledFiles field to Package (#​4706)

v0.46.1

Compare Source

Changelog

v0.46.0

Compare Source

⚡Release highlights and summary⚡

👉 https://github.com/aquasecurity/trivy/discussions/5377

Changelog

v0.45.1

Compare Source

Changelog

v0.45.0

Compare Source

⚡Release highlights and summary⚡

👉 https://github.com/aquasecurity/trivy/discussions/5082

Changelog


Configuration

📅 Schedule: Branch creation - "after 6am every weekday,before 12pm every weekday" in timezone Etc/UTC, Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate. View repository job log here.

@renovate renovate bot requested a review from a team as a code owner February 8, 2024 23:26
@renovate renovate bot added dependencies Pull requests that update a dependency file kubernetes labels Feb 8, 2024
chrisgacsal
chrisgacsal previously approved these changes Feb 8, 2024
@renovate renovate bot force-pushed the renovate/docker.io-aquasec-trivy-0.x branch from 551a767 to d4f24d0 Compare February 8, 2024 23:29

This comment has been minimized.

@renovate renovate bot force-pushed the renovate/docker.io-aquasec-trivy-0.x branch from d4f24d0 to 9964d1a Compare February 9, 2024 00:21

This comment has been minimized.

@renovate renovate bot force-pushed the renovate/docker.io-aquasec-trivy-0.x branch from 9964d1a to 8bd2da2 Compare February 9, 2024 07:28

This comment has been minimized.

@renovate renovate bot force-pushed the renovate/docker.io-aquasec-trivy-0.x branch 2 times, most recently from c96cfd8 to 0d68c06 Compare February 9, 2024 08:34
@chrisgacsal chrisgacsal self-assigned this Feb 9, 2024
Copy link
Contributor Author

renovate bot commented Feb 9, 2024

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

Warning: custom changes will be lost.

This comment has been minimized.

@chrisgacsal chrisgacsal force-pushed the renovate/docker.io-aquasec-trivy-0.x branch from 25a468e to 092216a Compare February 9, 2024 09:33
@chrisgacsal chrisgacsal enabled auto-merge February 9, 2024 09:34
Copy link

github-actions bot commented Feb 9, 2024

Hey!

Your images are ready:

  • ghcr.io/openclarity/vmclarity-apiserver-dev:pr1215-719e73163e47ee4114ef279047309f6c951189bf
  • ghcr.io/openclarity/vmclarity-orchestrator-dev:pr1215-719e73163e47ee4114ef279047309f6c951189bf
  • ghcr.io/openclarity/vmclarity-ui-backend-dev:pr1215-719e73163e47ee4114ef279047309f6c951189bf
  • ghcr.io/openclarity/vmclarity-ui-dev:pr1215-719e73163e47ee4114ef279047309f6c951189bf
  • ghcr.io/openclarity/vmclarity-cli-dev:pr1215-719e73163e47ee4114ef279047309f6c951189bf
  • ghcr.io/openclarity/vmclarity-cr-discovery-server-dev:pr1215-719e73163e47ee4114ef279047309f6c951189bf

@chrisgacsal chrisgacsal disabled auto-merge February 9, 2024 09:53
@chrisgacsal chrisgacsal added this pull request to the merge queue Feb 9, 2024
Merged via the queue into main with commit 279ebe7 Feb 9, 2024
37 checks passed
@chrisgacsal chrisgacsal deleted the renovate/docker.io-aquasec-trivy-0.x branch February 9, 2024 11:49
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file kubernetes
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

1 participant