github aquasecurity/trivy v0.37.0

latest releases: v0.57.0, v0.56.2, v0.56.1...
21 months ago

Changelog

  • e9d2af9 fix(image): close layers (#3517)
  • b169424 refactor: db client changed (#3515)
  • 7bf1e19 feat(java): use trivy-java-db to get GAV (#3484)
  • 023e45b docs: add note about the limitation in Rekor (#3494)
  • 0fe62a9 docs: aggregate targets (#3503)
  • 0373e08 deps: updates wazero to 1.0.0-pre.8 (#3510)
  • a2e21f9 docs: add alma 9 and rocky 9 to supported os (#3513)
  • 7d778b7 chore(deps): bump defsec to v0.82.9 (#3512)
  • 9e9dbea chore: add missing target labels (#3504)
  • d99a7b8 docs: add java vulnerability page (#3429)
  • cb5af0b feat(image): add support for Docker CIS Benchmark (#3496)
  • 6eec9ac feat(image): secret scanning on container image config (#3495)
  • 1eca973 chore(deps): Upgrade defsec to v0.82.8 (#3488)
  • fb0d8f3 feat(image): scan misconfigurations in image config (#3437)
  • 501d424 chore(helm): update Trivy from v0.30.4 to v0.36.1 (#3489)
  • 475dc17 feat(k8s): add node info resource (#3482)
  • ed173b8 perf(secret): optimize secret scanning memory usage (#3453)
  • 1b368be feat: support aliases in CLI flag, env and config (#3481)
  • 66a83d5 fix(k8s): migrate rbac k8s (#3459)
  • 81bee0f feat(java): add implementationVendor and specificationVendor fields to detect GroupID from MANIFEST.MF (#3480)
  • e107608 refactor: rename security-checks to scanners (#3467)
  • aaf845d chore: display the troubleshooting URL for the DB denial error (#3474)
  • ed5bb0b docs: yaml tabs to spaces, auto create namespace (#3469)
  • 3158bfe docs: adding show-and-tell template to GH discussions (#3391)
  • 85b6c4a fix: Fix a temporary file leak in case of error (#3465)
  • 60bddae fix(test): sort cyclonedx components (#3468)
  • e0bb04c docs: fixing spelling mistakes (#3462)
  • c25e826 ci: set paths triggering VM tests in PR (#3438)
  • 07ddc85 docs: typo in --skip-files (#3454)
  • e88507c feat(custom-forward): Extended advisory data (#3444)
  • e2dfee2 docs: fix spelling error (#3436)
  • c575d6f refactor(image): extend image config analyzer (#3434)
  • 036d5a8 fix(nodejs): add ignore protocols to yarn parser (#3433)
  • e6d7f15 fix(db): check proxy settings when using insecure flag (#3435)
  • a1d4427 feat(misconf): Fetch policies from OCI registry (#3015)
  • 682351a ci: downgrade Go to 1.18 and use stable and oldstable go versions for unit tests (#3413)
  • ff0c451 ci: store URLs to Github Releases in RPM repository (#3414)
  • ee12442 feat(server): add support of skip-db-update flag for hot db update (#3416)
  • 2033e05 chore(deps): bump github.com/moby/buildkit from v0.10.6 to v0.11.0 (#3411)
  • 6bc564e fix(image): handle wrong empty layer detection (#3375)
  • b3b8d4d test: fix integration tests for spdx and cycloneDX (#3412)
  • b88bcca feat(python): Include Conda packages in SBOMs (#3379)
  • fbd8a13 feat: add support pubspec.lock files for dart (#3344)
  • 0f545cf fix(image): parsePlatform is failing with UNAUTHORIZED error (#3326)
  • 76c883d fix(license): change normalize for GPL-3+-WITH-BISON-EXCEPTION (#3405)
  • a8b671b feat(server): log errors on server side (#3397)
  • a5919ca chore(deps): bump defsec to address helm vulnerabilities (#3399)
  • 89016da docs: rewrite installation docs and general improvements (#3368)
  • c3759c6 chore: update code owners (#3393)
  • 044fb97 chore: test docs separately from code (#3392)
  • ad2e648 docs: use the formula maintained by Homebrew (#3389)
  • ad25a77 docs: add Security Management section with SonarQube plugin

Don't miss a new trivy release

NewReleases is sending notifications on new releases.