github docker/scout-action v1.26.0

one hour ago

What's Changed

  • Fixes docker scout watch failing with 401 Unauthorized about 15 minutes after it starts. The Docker token is now refreshed before it expires, and an image that fails to process no longer stops the watcher; it is retried on the next check. @aubm
  • Fixes docker scout attest list and docker scout attest get so they find attestations attached as OCI referrers on Docker Hub and other registries. Previously only attestations served by the Scout registry were listed. @benja-M-1
  • Fixes docker scout quickview showing VEX-suppressed CVEs in the Target row when VEX suppresses every CVE in the image. @whostolebenfrog
  • Fixes DHI base-image VEX statements not being applied to multistage builds that use a mirrored DHI base image (<org>/dhi-<name> naming). @flyingmachine
  • Fixes CycloneDX SBOM output to keep the original creation timestamp and generator tool names and versions. @brianru
  • Updates the embedded Trivy (0.72.0) and Syft (1.46.0) scanning engines. @brianru

Don't miss a new scout-action release

NewReleases is sending notifications on new releases.