Update aquasec/trivy Docker tag to v0.50.0
This MR contains the following updates:
| Package | Type | Update | Change |
|---|---|---|---|
| aquasec/trivy | minor |
0.49.1 -> 0.50.0
|
|
| aquasec/trivy | ironbank-docker | minor |
0.49.1 -> 0.50.0
|
| aquasec/trivy | stage | minor |
0.49.1 -> 0.50.0
|
Release Notes
aquasecurity/trivy (aquasec/trivy)
v0.50.0
Changelog
-
8ec3938chore(deps): bump google.golang.org/protobuf from 1.32.0 to 1.33.0 (#6321) -
f6c5d58feat(java): add support licenses and graph for gradle lock files (#6140) -
c4022d6feat(vex): consider root component for relationships (#6313) -
3177924fix: increase the default buffer size for scanning dpkg status files by 2 times (#6298) -
dd9620echore: updates wazero to v1.7.0 (#6301) -
eb3ceb3feat(sbom): Support license detection for SBOM scan (#6072) -
ab74caarefactor(sbom): use intermediate representation for SPDX (#6310) -
71da44fdocs(terraform): improve documentation for filtering by inline comments (#6284) -
102b6dffix(terraform): fix policy document retrieval (#6276) -
aa19aafrefactor(terraform): remove unused custom error (#6303) -
8fcef35refactor(sbom): add intermediate representation for BOM (#6240) -
fb8c516fix(amazon): check only major version of AL to find advisories (#6295) -
96bd7acfix(db): use schema version as tag only fortrivy-dbandtrivy-java-dbregistries by default (#6219) -
12c5bf0fix(nodejs): add name validation for package name frompackage.json(#6268) -
d6c40cedocs: Added install instructions for FreeBSD (#6293) -
9d2057afeat(image): customer podman host or socket option (#6256) -
2a9d9bdchore(deps): bump wazero from 1.2.1 to 1.6.0 (#6290) -
617c3e3feat(java): mark dependencies frommaven-invoker-pluginintegration tests pom.xml files asDev(#6213) -
56cedc0fix(license): reorder logic of how python package licenses are acquired (#6220) -
d7d7265test(terraform): skip cached modules (#6281) -
6639911feat(secret): Support for detecting Hugging Face Access Tokens (#6236) -
337cb75fix(cloudformation): support of all SSE algorithms for s3 (#6270) -
9361cdbfeat(terraform): Terraform Plan snapshot scanning support (#6176) -
ee01e6echore(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.26.6 to 1.27.4 (#6249) -
3d2f583fix: typo function name and comment optimization (#6200) -
c4b5ab7fix(java): don't ignore runtime scope for pom.xml files (#6223) -
355c1b5chore(deps): bump helm/kind-action from 1.8.0 to 1.9.0 (#6242) -
7244ecechore(deps): bump golangci/golangci-lint-action from 3.7.0 to 4.0.0 (#6243) -
5cd0566chore(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.48.1 to 1.51.1 (#6251) -
ebb74a5chore(deps): bump github.com/hashicorp/go-uuid from 1.0.1 to 1.0.3 (#6253) -
24a8d6achore(deps): bump github.com/open-policy-agent/opa from 0.61.0 to 0.62.0 (#6250) -
9d0d7adchore(deps): bump github.com/containerd/containerd from 1.7.12 to 1.7.13 (#6247) -
e8230e1chore(deps): bump go.uber.org/zap from 1.26.0 to 1.27.0 (#6246) -
04535b5fix(license): add FilePath to results to allow for license path filtering via trivyignore file (#6215) -
939e34echore(deps): Upgrade iac deps (#6255) -
7cb6c02feat: add info log message about dev deps suppression (#6211) -
c1d26ectest(k8s): use test-db for k8s integration tests (#6222) -
4f70468ci: add maximize-build-space forTestjob (#6221) -
1dfece8fix(terraform): fix root module search (#6160) -
e1ea02ctest(parser): squash test data for yarn (#6203) -
64926d8fix(terraform): do not re-expand dynamic blocks (#6151) -
eb54bb5docs: update ecosystem page reporting with db app (#6201) -
dc76c6efix: k8s summary separate infra and user finding results (#6120) -
1b7e474fix: add context to target finding on k8s table view (#6099) -
876ab84fix: Printf format err (#6198) -
eef7c4frefactor: better integration of the parser into Trivy (#6183) -
069aae5chore(deps): bump helm.sh/helm/v3 from 3.14.1 to 3.14.2 (#6189) -
4a9ac6dfeat(terraform): Add hyphen and non-ASCII support for domain names in credential extraction (#6108) -
9c5e5a0fix(vex): CSAF filtering should consider relationships (#5923) -
388f476refactor(report): Replacingsource_locationingithubreport when scanning an image (#5999) -
cd3e4bcfeat(vuln): ignore vulnerabilities by PURL (#6178) -
ce81c05feat(java): add support for fetching packages from repos mentioned in pom.xml (#6171) -
cf0f0d0feat(k8s): rancher rke2 version support (#5988) -
8a3a113docs: update kbom distribution for scanning (#6019) -
19495bachore: update CODEOWNERS (#6173) -
e787e1afix(swift): try to use branch to resolve version (#6168) -
327cf88fix(terraform): ensure consistent path handling across OS (#6161) -
8221473fix(java): add only valid libs frompom.propertiesfiles fromjars(#6164) -
7694df1fix(sbom): skip executable file analysis if Rekor isn't a specified SBOM source (#6163) -
74dc5b6chore(deps): merge go-dep-parser into Trivy (#6094) -
32a02a9docs(report): add remark aboutpathto filter licenses using.trivyignore.yamlfile (#6145) -
fb79ea7docs: update template path for gitlab-ci tutorial (#6144) -
c6844a7feat(report): support for filtering licenses and secrets via rego policy files (#6004) -
a813506fix(cyclonedx): move root component from scanned cyclonedx file to output cyclonedx file (#6113) -
14adbb4refactor(deps): Merge defsec into trivy (#6109) -
efe0e0fchore(deps): bump helm.sh/helm/v3 from 3.14.0 to 3.14.1 (#6142) -
73dde32docs: add SecObserve in CI/CD and reporting (#6139) -
aadbad1fix(alpine): exclude empty licenses for apk packages (#6130) -
14a0981docs: add docs tutorial on custom policies with rego (#6104) -
3ac6388fix(nodejs): use project dir when searching for workspaces for Yarn.lock files (#6102) -
3c1601bfeat(vuln): show suppressed vulnerabilities in table (#6084) -
c107e1adocs: rename governance to principles (#6107) -
b26f217docs: add governance (#6090) -
7bd3b63refactor(deps): Merge trivy-iac into Trivy (#6005) -
535b5a9feat(java): add dependency location support forgradlefiles (#6083) -
428420echore(deps): bump github.com/aws/aws-sdk-go-v2/feature/s3/manager from 1.15.11 to 1.15.15 (#6038) -
7fec991fix(misconf): getuserfromConfig.User(#6070)
Configuration
-
If you want to rebase/retry this MR, check this box
This MR has been generated by Renovate Bot.