What's Changed
- Fixes
docker scout watchfailing with401 Unauthorizedabout 15 minutes after it starts. The Docker token is now refreshed before it expires, and an image that fails to process no longer stops the watcher; it is retried on the next check. @aubm - Fixes
docker scout attest listanddocker scout attest getso they find attestations attached as OCI referrers on Docker Hub and other registries. Previously only attestations served by the Scout registry were listed. @benja-M-1 - Fixes
docker scout quickviewshowing VEX-suppressed CVEs in the Target row when VEX suppresses every CVE in the image. @whostolebenfrog - Fixes DHI base-image VEX statements not being applied to multistage builds that use a mirrored DHI base image (
<org>/dhi-<name>naming). @flyingmachine - Fixes CycloneDX SBOM output to keep the original creation timestamp and generator tool names and versions. @brianru
- Updates the embedded Trivy (0.72.0) and Syft (1.46.0) scanning engines. @brianru