84 Commits

Author SHA256 Message Date
d8a2a02ec0 Accepting request 1324695 from Virtualization:containers
- Update to version 0.68.2:
  * release: v0.68.2 [release/v0.68] (#9950)
  * fix(deps): bump alpine from `3.22.1` to `3.23.0` [backport: release/v0.68] (#9949)
  * ci: enable `check-latest` for `setup-go` [backport: release/v0.68] (#9946)

- Update to version 0.68.1 (bsc#1251363, CVE-2025-47911,
  bsc#1251547, CVE-2025-58190, bsc#1253512, CVE-2025-47913,
  bsc#1253512, CVE-2025-47913, bsc#1253786, CVE-2025-58181,
  bsc#1253977, CVE-2025-47914):

OBS-URL: https://build.opensuse.org/request/show/1324695
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=84
2025-12-29 14:17:35 +00:00
c1a1f46352 Accepting request 1320965 from Virtualization:containers
- Update to version 0.68.1:
  * release: v0.68.1 [main] (#9867)
  * fix: update cosing settings for GoReleaser after bumping cosing to v3 (#9863)
  * chore(deps): bump the testcontainers group with 2 updates (#9506)
  * release: v0.68.0 [main] (#9549)
  * feat(aws): Add support for dualstack ECR endpoints (#9862)
  * fix(vex): use a separate `visited` set for each DFS path (#9760)
  * docs: catch some missed docs -> guide (#9850)
  * refactor(misconf): parse azure_policy_enabled to addonprofile.azurepolicy.enabled (#9851)
  * chore(cli): Remove Trivy Cloud (#9847)
  * fix(misconf): ensure value used as ignore marker is non-null and known (#9835)
  * fix(misconf): map healthcheck start period flag to --start-period instead of --startPeriod (#9837)
  * chore(deps): bump the docker group with 3 updates (#9776)
  * chore(deps): bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#9827)
  * chore(deps): bump the common group across 1 directory with 20 updates (#9840)
  * feat(image): add Sigstore bundle SBOM support (#9516)
  * chore(deps): bump the aws group with 7 updates (#9691)
  * test(k8s): update k8s integrtion test (#9725)
  * chore(deps): bump github.com/containerd/containerd from 1.7.28 to 1.7.29 (#9764)
  * feat(sbom): add support for SPDX attestations (#9829)
  * docs(misconf): Remove duplicate sections (#9819)
  * feat(misconf): Update Azure network schema for new checks (#9791)
  * feat(misconf): Update AppService schema (#9792)
  * fix(misconf): ensure boolean metadata values are correctly interpreted (#9770)
  * feat(misconf): support https_traffic_only_enabled in Az storage account (#9784)
  * docs: restructure docs for new hosting (#9799)
  * docs(server): fix info about scanning licenses on the client side. (#9805)
  * ci: remove unused preinstalled software/images for build tests to free up disk space. (#9814)
  * feat(report): add fingerprint generation for vulnerabilities (#9794)
  * chore: trigger the trivy-www workflow (#9737)

OBS-URL: https://build.opensuse.org/request/show/1320965
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=83
2025-12-03 13:13:46 +00:00
1fa0f4e999 Accepting request 1316946 from Virtualization:containers
- Update to version 0.67.2 (bsc#1250625, CVE-2025-11065,
  bsc#1248897, CVE-2025-58058):
  * release: v0.67.2 [release/v0.67] (#9639)
  * fix: Use `fetch-level: 1` to check out trivy-repo in the release workflow [backport: release/v0.67] (#9638)
  * release: v0.67.1 [release/v0.67] (#9614)
  * fix: restore compatibility for google.protobuf.Value [backport: release/v0.67] (#9631)
  * fix: using SrcVersion instead of Version for echo detector [backport: release/v0.67] (#9629)
  * fix: add `buildInfo` for `BlobInfo` in `rpc` package [backport: release/v0.67] (#9615)
  * fix(vex): don't use reused BOM [backport: release/v0.67] (#9612)
  * release: v0.67.0 [main] (#9432)
  * fix(vex): don't  suppress vulns for packages with infinity loop (#9465)
  * fix(aws): use `BuildableClient` insead of `xhttp.Client` (#9436)
  * refactor(misconf): replace github.com/liamg/memoryfs with internal mapfs and testing/fstest (#9282)
  * docs: clarify inline ignore limitations for resource-less checks (#9537)
  * fix(k8s): disable parallel traversal with fs cache for k8s images (#9534)
  * fix(misconf): handle tofu files in module detection (#9486)
  * feat(seal): add seal support (#9370)
  * docs: fix modules path and update code example (#9539)
  * fix: close file descriptors and pipes on error paths (#9536)
  * feat: add documentation URL for database lock errors (#9531)
  * fix(db): Dowload database when missing but metadata still exists (#9393)
  * feat(cloudformation): support default values and list results in Fn::FindInMap (#9515)
  * fix(misconf): unmark cty values before access (#9495)
  * feat(cli): change --list-all-pkgs default to true (#9510)
  * fix(nodejs): parse workspaces as objects for package-lock.json files (#9518)
  * refactor(fs): use underlyingPath to determine virtual files more reliably (#9302)
  * refactor: remove google/wire dependency and implement manual DI (#9509)
  * chore(deps): bump the aws group with 6 updates (#9481)
  * chore(deps): bump the common group across 1 directory with 24 updates (#9507)
  * fix(misconf): wrap legacy ENV values in quotes to preserve spaces (#9497)

OBS-URL: https://build.opensuse.org/request/show/1316946
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=82
2025-11-10 18:21:00 +00:00
02ea4752ef Accepting request 1303631 from Virtualization:containers
- Update to version 0.66.0 (bsc#1248937, CVE-2025-58058):
  * release: v0.66.0 [main] (#9289)
  * chore(deps): bump the aws group with 7 updates (#9419)
  * refactor(secret): clarify secret scanner messages (#9409)
  * fix(cyclonedx): handle multiple license types (#9378)
  * fix(repo): sanitize git repo URL before inserting into report metadata (#9391)
  * test: add HTTP basic authentication to git test server (#9407)
  * fix(sbom): add support for `file` component type of `CycloneDX` (#9372)
  * fix(misconf): ensure module source is known (#9404)
  * ci: migrate GitHub Actions from version tags to SHA pinning (#9405)
  * fix: create temp file under composite fs dir (#9387)
  * chore(deps): bump github.com/ulikunitz/xz from 0.5.12 to 0.5.14 (#9403)
  * refactor: switch to stable azcontainerregistry SDK package (#9319)
  * chore(deps): bump the common group with 7 updates (#9382)
  * refactor(misconf): migrate from custom Azure JSON parser (#9222)
  * fix(repo): preserve RepoMetadata on FS cache hit (#9389)
  * refactor(misconf): use atomic.Int32 (#9385)
  * chore(deps): bump the aws group with 6 updates (#9383)
  * docs: Fix broken link to "Built-in Checks" (#9375)
  * fix(plugin): don't remove plugins when updating index.yaml file (#9358)
  * fix: persistent flag option typo (#9374)
  * chore(deps): bump the common group across 1 directory with 26 updates (#9347)
  * fix(image): use standardized HTTP client for ECR authentication (#9322)
  * refactor: export `systemFileFiltering` Post Handler (#9359)
  * docs: update links to Semaphore pages (#9352)
  * fix(conda): memory leak by adding closure method for `package.json` file (#9349)
  * feat: add timeout handling for cache database operations (#9307)
  * fix(misconf): use correct field log_bucket instead of target_bucket in gcp bucket (#9296)
  * fix(misconf): ensure ignore rules respect subdirectory chart paths (#9324)
  * chore(deps): bump alpine from 3.21.4 to 3.22.1 (#9301)

OBS-URL: https://build.opensuse.org/request/show/1303631
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=81
2025-09-10 18:22:52 +00:00
8bae2675e0 Accepting request 1302751 from Virtualization:containers
- Update to version 0.64.1 (bsc#1243633, CVE-2025-47291,
                           (bsc#1246730, CVE-2025-46569):

OBS-URL: https://build.opensuse.org/request/show/1302751
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=80
2025-09-05 19:42:45 +00:00
f4012ffb18 Accepting request 1299810 from devel:Factory:git-workflow:staging:dirkmueller:trivy:21
update to 0.65.0. add missing CVE references to changes file



(🤖: Submission of trivy via #21 by dirkmueller)

OBS-URL: https://build.opensuse.org/request/show/1299810
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=79
2025-08-15 19:52:38 +00:00
d932041a37 Accepting request 1295289 from devel:Factory:git-workflow:staging:dirkmueller:trivy:20
remove rpm dependency



(🤖: Submission of trivy via #20 by dirkmueller)

OBS-URL: https://build.opensuse.org/request/show/1295289
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=78
2025-07-25 15:04:35 +00:00
6fa56db217 Accepting request 1292195 from devel:Factory:git-workflow:staging:dirkmueller:trivy:19
Update to 0.64.1

Includes a changes file update to mention a already previously
dropped patch file

(🤖: Submission of trivy via #19 by dirkmueller)

OBS-URL: https://build.opensuse.org/request/show/1292195
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=77
2025-07-11 19:31:30 +00:00
3bd2a05abf Accepting request 1275332 from devel:Factory:git-workflow:staging:dirkmueller:trivy:16
Update to 0.62.1



(🤖: Submission of trivy via #16 by dirkmueller)

OBS-URL: https://build.opensuse.org/request/show/1275332
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=76
2025-05-08 16:22:19 +00:00
c27646747a Accepting request 1272461 from devel:Factory:git-workflow:staging:dirkmueller:trivy:15
Update to 0.61.1



(🤖: Submission of trivy via #15 by dirkmueller)

OBS-URL: https://build.opensuse.org/request/show/1272461
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=75
2025-04-25 20:18:51 +00:00
Git SCM Staging
017475a00c [info=7ca63ef7514307238c0f1d8d92767cb7822b6c03c75c6bed34f60798fce83caa]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:13/trivy?expand=0&rev=3
2025-02-26 10:19:50 +00:00
Git SCM Staging
d416a67278 [info=f0646f271b638d4cf53f86e463a222a46366598e326af4f4e15e6c9baf11061b]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:13/trivy?expand=0&rev=2
2025-02-26 09:03:35 +00:00
Git SCM Staging
a7e51b499a [info=242c86594fd512f06334f1349c8ca593d62cb1faf79fce26d64e85d1d728d702]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:13/trivy?expand=0&rev=1
2025-02-25 14:51:07 +00:00
Git SCM Staging
98a1df8994 [info=d51993176293f0a7c9544df9656c098cdb779883bec3fe549396628001b9bd61]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:12/trivy?expand=0&rev=2
2025-02-07 13:38:23 +00:00
Git SCM Staging
f95624c9b8 [info=ff71303c939446de604aaee6e7d4bc0e74165810f05fd70559970eeac9277971]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:12/trivy?expand=0&rev=1
2025-02-06 16:12:40 +00:00
Git SCM Staging
50791c140e [info=757447aee927fa8446de045d0c1b532e9a3787977a6cd9b2e6282a170bd4b0a5]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:11/trivy?expand=0&rev=2
2025-01-29 12:07:58 +00:00
Git SCM Staging
8b004bf8b1 [info=74c123e46715b11e134b8a9f80135e77b43d64ba19903284a20b303dde3dc240]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:11/trivy?expand=0&rev=1
2025-01-29 12:01:48 +00:00
Git SCM Staging
a47274f501 [info=7b167d9c3b42696274d8b3dffebce782481d162e1c1407e3c3db6c328a8e3422]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:10/trivy?expand=0&rev=1
2024-12-03 08:56:09 +00:00
Git SCM Staging
568fa1ca6b [info=4c05bd9c33e94651288d974fbdef1c2b871663758cd3912a5f1d2e77c19756c6]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:8/trivy?expand=0&rev=1
2024-10-23 13:28:39 +00:00
Git SCM Staging
4700211994 [info=9b5c03e298c4c058d6eee3ae4d434f5c728c5981a97a5a134a50523eec2234dc]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:7/trivy?expand=0&rev=2
2024-10-08 16:53:36 +00:00
Git SCM Staging
2409d72527 [info=579ede4865fcf5783c98eab0446e1c095dd85e84]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:7/trivy?expand=0&rev=1
2024-06-06 13:32:53 +00:00
Git SCM Staging
3aa0363cbf [info=9db9048f8fcda9228fdaecd994a195b439617cc7]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:6/trivy?expand=0&rev=1
2024-05-17 20:27:28 +00:00
ce290678ab [info=2104123c72636f1cd80a006a15bd8b68af402960]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:5/trivy?expand=0&rev=2
2024-02-09 16:26:31 +00:00
2b9122f8ac [info=3b8b301ce3e352f21ca0c2faef2ca1bc9b104ec7]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:5/trivy?expand=0&rev=1
2023-08-03 11:27:23 +00:00
b25074f6e0 [info=6fda4ae520211599a57cefcb305a98c83f616b89]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:4/trivy?expand=0&rev=3
2023-07-20 11:20:15 +00:00
901d7de560 [info=46b4e36452c73989d1e9f6536ae754cc7a61d32e]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:4/trivy?expand=0&rev=1
2023-07-13 09:18:42 +00:00
076cb03c4a Accepting request 1096591 from devel:Factory:git-workflow:staging:SCM_STAGING:trivy:3
🤖: Submission of trivy via #3 by dirkmueller

OBS-URL: https://build.opensuse.org/request/show/1096591
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=55
2023-07-04 13:21:56 +00:00
1443f0bae4 Accepting request 1095924 from devel:Factory:git-workflow:staging:SCM_STAGING:trivy:1
🤖: Submission of trivy via #1 by dirkmueller

OBS-URL: https://build.opensuse.org/request/show/1095924
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=54
2023-06-29 15:29:13 +00:00
3e2167aa9b - Update to version 0.42.1:
* ci: remove 32bit packages (#4585)
  * fix(misconf): deduplicate misconf results (#4588)
  * fix(vm): support sector size of 4096 (#4564)
  * fix(misconf): terraform relative paths (#4571)
  * fix(purl): skip unsupported library type (#4577)
  * fix(terraform): recursively detect all Root Modules (#4457)
  * fix(vm): support post analyzer for vm command (#4544)
  * fix(nodejs): change the type of the devDependencies field (#4560)
  * fix(sbom): export empty dependencies in CycloneDX (#4568)
  * refactor: add composite fs for post-analyzers (#4556)
  * chore(deps): bump golangci/golangci-lint-action from 3.4.0 to 3.5.0 (#4554)
  * chore(deps): bump helm/kind-action from 1.5.0 to 1.7.0 (#4526)
  * chore(deps): bump github.com/BurntSushi/toml from 1.2.1 to 1.3.0 (#4528)
  * chore(deps): bump github.com/alicebob/miniredis/v2 from 2.30.2 to 2.30.3 (#4529)
  * chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 (#4536)
  * chore(deps): bump github.com/tetratelabs/wazero from 1.0.0 to 1.2.0 (#4549)
  * chore(deps): bump github.com/spf13/cast from 1.5.0 to 1.5.1 (#4532)
  * chore(deps): bump github.com/testcontainers/testcontainers-go (#4537)
  * chore(deps): bump github.com/go-git/go-git/v5 from 5.6.1 to 5.7.0 (#4530)
  * chore(deps): bump github.com/aws/aws-sdk-go-v2/config (#4534)
  * chore(deps): bump github.com/sigstore/rekor from 1.2.0 to 1.2.1 (#4533)
  * chore(deps): bump alpine from 3.17.3 to 3.18.0 (#4525)
  * feat: add SBOM analyzer (#4210)
  * fix(sbom): update logic for work with files in spdx format (#4513)
  * feat: azure workload identity support (#4489)
  * feat(ubuntu): add eol date for 18.04 ESM (#4524)
  * fix(misconf): Update required extensions for terraformplan (#4523)
  * refactor(cyclonedx): add intermediate representation (#4490)
  * fix(misconf): Remove debug print while scanning (#4521)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=63
2023-06-12 08:17:18 +00:00
fa6666214b - actually create a PIE binary
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=61
2023-05-11 17:05:19 +00:00
c266b89032 - Update to version 0.41.0:
* fix(spdx): add workaround for no src packages (#4118)
  * test(golang): rename broken go.mod (#4129)
  * feat(sbom): add supplier field (#4122)
  * test(misconf): skip downloading of policies for tests #4126
  * refactor: use debug message for post-analyze errors (#4037)
  * feat(sbom): add VEX support (#4053)
  * feat(sbom): add primary package purpose field for SPDX (#4119)
  * fix(k8s): fix quiet flag (#4120)
  * fix(python): parse of pip extras (#4103)
  * feat(java): use full path for nested jars (#3992)
  * feat(license): add new flag for classifier confidence level (#4073)
  * feat: config and fs compliance support (#4097)
  * chore(deps): bump sigstore/cosign-installer from 2.8.1 to 3.0.1 (#3952)
  * feat(spdx): add support for SPDX 2.3 (#4058)
  * fix: k8s all-namespaces support (#4096)
  * perf(misconf): replace with post-analyzers (#4090)
  * fix(helm): update networking API version detection (#4106)
  * feat(image): custom docker host option (#3599)
  * style: debug flag is incorrect and needs extra - (#4087)
  * docs(vuln): Document inline vulnerability filtering comments (#4024)
  * feat(fs): customize error callback during fs walk (#4038)
  * fix(ubuntu): skip copyright files from subfolders (#4076)
  * docs: restructure scanners (#3977)
  * fix: fix `file does not exist` error for post-analyzers (#4061)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=59
2023-04-28 07:52:09 +00:00
1c04f09b2d - Update to version 0.40.0:
* feat(flag): Support globstar for `--skip-files` and `--skip-directories` (#4026)
  * chore(deps): bump actions/stale from 7 to 8 (#3955)
  * fix: return insecure option to download javadb (#4064)
  * fix(nodejs): don't stop parsing when unsupported yarn.lock protocols are found (#4052)
  * ci: add gpg signing for RPM packages (#4056)
  * fix(k8s): current context title (#4055)
  * fix(k8s): quit support on k8s progress bar (#4021)
  * chore: add a note about Dockerfile.canary (#4050)
  * ci: fix path to canary binaries (#4045)
  * fix(vuln): report architecture for debian packages (#4032)
  * feat: add support for Chainguard's commercial distro (#3641)
  * ci: bump goreleaser for Github Action from 1.4.1 to 1.16.2 (#3979)
  * fix(vuln): fix error message for remote scanners (#4031)
  * feat(report): add image metadata to SARIF (#4020)
  * docs: fix broken cache link on Installation page (#3999)
  * fix: lock downloading policies and database (#4017)
  * fix: avoid concurrent access to the global map (#4014)
  * feat(rust): add Cargo.lock v3 support (#4012)
  * feat: auth support oci download server subcommand (#4008)
  * chore(deps): bump github.com/docker/docker (#4009)
  * chore: install.sh support for armv7 (#3985)
  * chore(deps): bump github.com/Azure/go-autorest/autorest/adal (#3961)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=56
2023-04-16 18:11:29 +00:00
a9593f7bd8 - Update to version 0.39.1:
* fix(rust): fix panic when 'dependencies' field is not used in cargo.toml (#3997)
  * fix(sbom): fix infinite loop for cyclonedx (#3998)
  * chore(deps): bump helm/chart-testing-action from 2.3.1 to 2.4.0 (#3954)
  * fix: use warning for errors from enrichment files for post-analyzers (#3972)
  * chore(deps): bump github.com/docker/docker (#3963)
  * fix(helm): added annotation to psp configurable from values (#3893)
  * chore(deps): bump github.com/go-git/go-git/v5 from 5.5.2 to 5.6.1 (#3962)
  * fix(secret): update built-in rule `tests`  (#3855)
  * chore(deps): bump github.com/alicebob/miniredis/v2 from 2.23.0 to 2.30.1 (#3957)
  * test: rewrite scripts in Go (#3968)
  * docs(cli): Improve glob documentation (#3945)
  * chore(deps): bump github.com/aws/aws-sdk-go-v2/service/sts (#3959)
  * ci: check CLI references (#3967)
  * chore(deps): bump alpine from 3.17.2 to 3.17.3 (#3951)
  * chore(deps): bump github.com/aws/aws-sdk-go from 1.44.212 to 1.44.234 (#3956)
  * chore(deps): bump github.com/moby/buildkit from 0.11.4 to 0.11.5 (#3958)
  * chore(deps): bump actions/setup-go from 3 to 4 (#3953)
  * chore(deps): bump actions/cache from 3.2.6 to 3.3.1 (#3950)
  * chore(deps): bump github.com/containerd/containerd from 1.6.19 to 1.7.0 (#3965)
  * chore(deps): bump github.com/sigstore/rekor from 1.0.1 to 1.1.0 (#3964)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=55
2023-04-13 09:17:33 +00:00
062c4c4519 - Update to version 0.39.0:
* docs(cli): added makefile and go file to create docs (#3930)
  * chore: Revert "ci: add gpg signing for RPM packages (#3612)" (#3946)
  * chore: ignore gpg key (#3943)
  * feat(cyclonedx): support dependency graph (#3177)
  * chore(deps): Bump defsec to v0.85.0 (#3940)
  * feat(rust): remove dev deps and find direct deps for Cargo.lock (#3919)
  * feat(server): redis with public TLS certs support (#3783)
  * feat(flag): Add glob support to `--skip-dirs` and `--skip-files`  (#3866)
  * chore: replace make with mage (#3932)
  * fix(sbom): add checksum to files (#3888)
  * chore(deps): bump github.com/opencontainers/runc from 1.1.4 to 1.1.5 (#3928)
  * chore: remove unused mount volumes (#3927)
  * feat: add auth support for downloading OCI artifacts (#3915)
  * refactor(purl): use epoch in qualifier (#3913)
  * chore(deps): bump github.com/in-toto/in-toto-golang from 0.5.0 to 0.7.0 (#3727)
  * feat(image): add registry options (#3906)
  * feat(rust): dependency tree and line numbers support for cargo lock file (#3746)
  * chore(deps): bump google.golang.org/protobuf from 1.29.0 to 1.29.1 (#3905)
  * feat(php): add support for location, licenses and graph for composer.lock files (#3873)
  * chore(deps): updates wazero to 1.0.0 (#3904)
  * feat(image): discover SBOM in OCI referrers (#3768)
  * docs: change cache-dir key in config file (#3897)
  * fix(sbom): use release and epoch for SPDX package version (#3896)
  * ci: add gpg signing for RPM packages (#3612)
  * docs: Update incorrect comment for skip-update flag (#3878)
  * refactor(misconf): simplify policy filesystem (#3875)
  * feat(nodejs): parse package.json alongside yarn.lock (#3757)
  * fix(spdx): add PkgDownloadLocation field (#3879)
  * fix(report): try to guess direct deps for dependency tree (#3852)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=53
2023-04-03 12:32:29 +00:00
b319fb593e - Update to version 0.38.3:
* chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.86.1 to 1.89.1 (#3827)
  * fix(java): skip empty files for jar post analyzer (#3832)
  * fix(docker): build healthcheck command for line without /bin/sh prefix (#3831)
  * refactor(license): use goyacc for license parser (#3824)
  * chore(deps): bump github.com/docker/docker from 23.0.0-rc.1+incompatible to 23.0.1+incompatible (#3586)
  * fix: populate timeout context to node-collector (#3766)
  * fix: exclude node collector scanning (#3771)
  * fix: display correct flag in error message when skipping java db update #3808
  * fix: disable jar analyzer for scanners other than vuln (#3810)
  * fix(sbom): fix incompliant license format for spdx (#3335)
  * fix(java): the project props take precedence over the parent's props (#3320)
  * docs: add canary build info to README.md (#3799)
  * docs: adding link to gh token generation (#3784)
  * docs: changing docs in accordance with #3460 (#3787)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=50
2023-03-14 09:57:08 +00:00
18a2b0893a - Update to version 0.38.2:
* chore(deps): bump github.com/moby/buildkit from 0.11.0 to 0.11.4 (#3789)
  * chore(deps): bump actions/add-to-project from 0.4.0 to 0.4.1 (#3724)
  * fix(license): disable jar analyzer for licence scan only (#3780)
  * bump trivy-issue-action to v0.0.0; skip `pkg` dir (#3781)
  * fix: skip checking dirs for required post-analyzers (#3773)
  * docs: add information about plugin format (#3749)
  * fix(sbom): add trivy version to spdx creators tool field (#3756)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=48
2023-03-08 11:07:56 +00:00
a65dfd33d7 - Update to version 0.38.1:
* feat(misconf): Add support to show policy bundle version (#3743)
  * fix(python): fix error with optional dependencies in pyproject.toml (#3741)
  * chore(deps): bump github.com/aws/aws-sdk-go from 1.44.210 to 1.44.212 (#3740)
  * add id for package.json files (#3750)
  * chore(deps): bump github.com/containerd/containerd from 1.6.18 to 1.6.19 (#3738)
  * chore(deps): bump actions/cache from 3.2.4 to 3.2.6 (#3725)
  * chore(deps): bump github.com/google/go-containerregistry (#3731)
  * chore(deps): bump go.etcd.io/bbolt from 1.3.6 to 1.3.7 (#3732)
  * chore(deps): bump alpine from 3.17.1 to 3.17.2 (#3723)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=46
2023-03-02 17:38:57 +00:00
4e5f1d07de - Update to version 0.38.0:
* fix(cli): pass integer to exit-on-eol (#3716)
  * feat: add kubernetes pss compliance (#3498)
  * feat: Adding --module-dir and --enable-modules (#3677)
  * feat: add special IDs for filtering secrets (#3702)
  * chore(deps): Update defsec (#3713)
  * docs(misconf): Add guide on input schema (#3692)
  * feat(go): support dependency graph and show only direct dependencies in the tree (#3691)
  * feat: docker multi credential support (#3631)
  * feat: summarize vulnerabilities in compliance reports (#3651)
  * feat(python): parse pyproject.toml alongside poetry.lock (#3695)
  * feat(python): add dependency tree for poetry lock file (#3665)
  * fix(cyclonedx): incompliant affect ref (#3679)
  * chore(helm): update skip-db-update environment variable (#3657)
  * fix(spdx): change CreationInfo timestamp format RFC3336Nano to RFC3336 (#3675)
  * fix(sbom): export empty dependencies in CycloneDX (#3664)
  * docs: java-db air-gap doc tweaks (#3561)
  * feat(go): license support (#3683)
  * feat(ruby): add dependency tree/location support for Gemfile.lock (#3669)
  * fix(k8s): k8s label size (#3678)
  * fix(cyclondx): fix array empty value, null to [] (#3676)
  * refactor: rewrite gomod analyzer as post-analyzer (#3674)
  * feat: config outdated-api result filtered by k8s version (#3578)
  * fix: Update to Alpine 3.17.2 (#3655)
  * feat: add support for virtual files (#3654)
  * feat: add post-analyzers (#3640)
  * chore(deps): updates wazero to 1.0.0-pre.9 (#3653)
  * chore(deps): bump github.com/go-openapi/runtime from 0.24.2 to 0.25.0 (#3528)
  * chore(deps): bump github.com/containerd/containerd from 1.6.15 to 1.6.18 (#3633)
  * feat(python): add dependency locations for Pipfile.lock (#3614)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=44
2023-03-01 10:45:59 +00:00
d2c9e8e17e - Update to version 0.37.3 (bsc#1208091, CVE-2023-25165):
* chore(helm): update Trivy from v0.36.1 to v0.37.2 (#3574)
  * chore(deps): bump github.com/spf13/viper from 1.14.0 to 1.15.0 (#3536)
  * chore(deps): bump golang/x/mod to v0.8.0 (#3606)
  * chore(deps): bump golang.org/x/crypto from 0.3.0 to 0.5.0 (#3529)
  * chore(deps): bump helm.sh/helm/v3 from 3.10.3 to 3.11.1 (#3580)
  * ci: quote pros in c++ for semantic pr (#3605)
  * fix(image): check proxy settings from env for remote images (#3604)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=42
2023-02-15 08:41:42 +00:00
2ec944171e Accepting request 1064149 from home:ojkastl_buildservice:Branch_Virtualization_containers
update to 0.37.2

OBS-URL: https://build.opensuse.org/request/show/1064149
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=40
2023-02-10 08:08:46 +00:00
d95d3d3fa3 - Update to version 0.37.1:
* fix(sbom): download the Java DB when generating SBOM (#3539)
  * fix: use cgo free sqlite driver (#3521)
  * ci: fix path to dist folder (#3527)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=38
2023-02-01 16:22:25 +00:00
672c04bdc6 - Update to version 0.37.0:
* fix(image): close layers (#3517)
  * refactor: db client changed (#3515)
  * feat(java): use trivy-java-db to get GAV (#3484)
  * docs: add note about the limitation in Rekor (#3494)
  * docs: aggregate targets (#3503)
  * deps: updates wazero to 1.0.0-pre.8 (#3510)
  * docs: add alma 9 and rocky 9 to supported os (#3513)
  * chore(deps): bump defsec to v0.82.9 (#3512)
  * chore: add missing target labels (#3504)
  * docs: add java vulnerability page (#3429)
  * feat(image): add support for Docker CIS Benchmark (#3496)
  * feat(image): secret scanning on container image config (#3495)
  * chore(deps): Upgrade defsec to v0.82.8 (#3488)
  * feat(image): scan misconfigurations in image config (#3437)
  * chore(helm): update Trivy from v0.30.4 to v0.36.1 (#3489)
  * feat(k8s): add node info resource (#3482)
  * perf(secret): optimize secret scanning memory usage (#3453)
  * feat: support aliases in CLI flag, env and config (#3481)
  * fix(k8s): migrate rbac k8s (#3459)
  * feat(java): add implementationVendor and specificationVendor fields to detect GroupID from MANIFEST.MF (#3480)
  * refactor: rename security-checks to scanners (#3467)
  * chore: display the troubleshooting URL for the DB denial error (#3474)
  * docs: yaml tabs to spaces, auto create namespace (#3469)
  * docs: adding show-and-tell template to GH discussions (#3391)
  * fix: Fix a temporary file leak in case of error (#3465)
  * fix(test): sort cyclonedx components (#3468)
  * docs: fixing spelling mistakes (#3462)
  * ci: set paths triggering VM tests in PR (#3438)
  * docs: typo in --skip-files (#3454)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=36
2023-02-01 12:11:50 +00:00
8feee24f2e - Update to version 0.36.1:
* fix(deps): fix errors on yarn.lock files that contain local file reference (#3384)
  * feat(flag): early fail when the format is invalid (#3370)
  * chore(deps): bump github.com/aws/aws-sdk-go from 1.44.136 to 1.44.171 (#3366)
  * docs(aws): fix broken links (#3374)
  * chore(deps): bump actions/stale from 6 to 7 (#3360)
  * chore(deps): bump helm/kind-action from 1.4.0 to 1.5.0 (#3359)
  * chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.6.0 to 0.7.0 (#2974)
  * chore(deps): bump azure/setup-helm from 3.4 to 3.5 (#3358)
  * chore(deps): bump github.com/moby/buildkit from 0.10.4 to 0.10.6 (#3173)
  * chore(deps): bump goreleaser/goreleaser-action from 3 to 4 (#3357)
  * chore(deps): bump github.com/containerd/containerd from 1.6.8 to 1.6.14 (#3367)
  * chore(go): updates wazero to v1.0.0-pre.7 (#3355)
  * chore(deps): bump golang.org/x/text from 0.4.0 to 0.5.0 (#3362)
  * chore(deps): bump actions/cache from 3.0.11 to 3.2.2 (#3356)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=34
2023-01-05 12:15:28 +00:00
4e05e2e98d - Update to version 0.36.0:
* docs: improve compliance docs (#3340)
  * feat(deps): add yarn lock dependency tree (#3348)
  * fix: compliance change id and title naming (#3349)
  * feat: add support for mix.lock files for elixir language (#3328)
  * feat: add k8s cis bench (#3315)
  * test: disable SearchLocalStoreByNameOrDigest test for non-amd64 arch (#3322)
  * revert: cache merged layers (#3334)
  * feat(cyclonedx): add recommendation (#3336)
  * feat(ubuntu): added support ubuntu ESM versions (#1893)
  * fix: change logic to build relative paths for skip-dirs and skip-files (#3331)
  * chore(deps): bump github.com/hashicorp/golang-lru from 0.5.4 to 2.0.1 (#3265)
  * feat: Adding support for Windows testing (#3037)
  * feat: add support for Alpine 3.17 (#3319)
  * docs: change PodFile.lock to Podfile.lock (#3318)
  * fix(sbom): support for the detection of old CycloneDX predicate type (#3316)
  * feat(secret): Use .trivyignore for filtering secret scanning result (#3312)
  * chore(go): remove experimental FS API usage in Wasm (#3299)
  * ci: add workflow to add issues to roadmap project (#3292)
  * fix(vuln): include duplicate vulnerabilities with different package paths in the final report (#3275)
  * chore(deps): bump github.com/spf13/viper from 1.13.0 to 1.14.0 (#3250)
  * feat(sbom): better support for third-party SBOMs (#3262)
  * docs: add information about languages with support for dependency locations (#3306)
  * feat(vm): add `region` option to vm scan to be able to scan any region's ami and ebs snapshots (#3284)
  * chore(deps): bump github.com/Azure/azure-sdk-for-go from 66.0.0+incompatible to 67.1.0+incompatible (#3251)
  * fix(vuln): change severity vendor priority for ghsa-ids and vulns from govuln (#3255)
  * docs: remove comparisons (#3289)
  * feat: add support for Wolfi Linux (#3215)
  * ci: add go.mod to canary workflow (#3288)
  * feat(python): skip dev dependencies (#3282)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=32
2023-01-02 08:37:03 +00:00
83b7bc68d6 Accepting request 1038580 from home:ojkastl_buildservice:Branch_Virtualization_containers
update to 0.35.0

OBS-URL: https://build.opensuse.org/request/show/1038580
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=30
2022-11-28 08:09:58 +00:00
2f67d2596c Accepting request 1032484 from home:ojkastl_buildservice:Branch_Virtualization_containers
update to 0.34.0

OBS-URL: https://build.opensuse.org/request/show/1032484
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=28
2022-11-07 10:10:13 +00:00
1afcdaafd3 Accepting request 1031236 from home:ojkastl_buildservice:Branch_Virtualization_containers
update to 0.33.0

OBS-URL: https://build.opensuse.org/request/show/1031236
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=26
2022-10-26 06:33:34 +00:00
a79a01c42a - Update to version 0.32.1:
* fix(java): use fields of dependency from dependencyManagement from upper pom.xml to parse deps (#2943)
  * chore: expat lib and go binary deps vulns (#2940)
  * wasm: Removes accidentally exported memory (#2950)
  * fix(sbom): fix package name separation for gradle (#2906)
  * docs(readme.md): fix broken integrations link (#2931)
  * fix(image): handle images with single layer in rescan mergedLayers cache (#2927)
  * fix(cli): split env values with ',' for slice flags (#2926)
  * fix(cli): config/helm: also take into account files with `.yml` (#2928)
  * fix(flag): add file-patterns flag for config subcommand (#2925)
  * chore(deps): bump github.com/open-policy-agent/opa from 0.43.0 to 0.43.1 (#2902)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=24
2022-09-28 14:07:00 +00:00
c7371b4a31 - Update to version 0.32.0:
* docs: add Rekor SBOM attestation scanning (#2893)
  * chore: narrow the owner scope (#2894)
  * fix: remove a patch number from the recommendation link (#2891)
  * fix: enable parsing of UUID-only rekor entry ID (#2887)
  * docs(sbom): add SPDX scanning (#2885)
  * docs: restructure docs and add tutorials (#2883)
  * feat(sbom): scan sbom attestation in the rekor record (#2699)
  * feat(k8s): support outdated-api (#2877)
  * chore(deps): bump github.com/moby/buildkit from 0.10.3 to 0.10.4 (#2815)
  * fix(c): support revisions in Conan parser (#2878)
  * feat: dynamic links support for scan results (#2838)
  * chore(deps): bump go.uber.org/zap from 1.22.0 to 1.23.0 (#2818)
  * docs: update archlinux commands (#2876)
  * feat(secret): add line from dockerfile where secret was added to secret result (#2780)
  * feat(sbom): Add unmarshal for spdx (#2868)
  * chore(deps): bump github.com/aws/aws-sdk-go-v2/config (#2827)
  * fix: revert asff arn and add documentation (#2852)
  * docs: batch-import-findings limit (#2851)
  * chore(deps): bump golang from 1.19.0 to 1.19.1 (#2872)
  * feat(sbom): Add marshal for spdx (#2867)
  * build: checkout before setting up Go (#2873)
  * chore: bump Go to 1.19 (#2861)
  * docs: azure doc and trivy (#2869)
  * fix: Scan tarr'd dependencies (#2857)
  * chore(helm): helm test with ingress (#2630)
  * feat(report): add secrets to sarif format (#2820)
  * chore(deps): bump azure/setup-helm from 1.1 to 3.3 (#2807)
  * refactor: add a new interface for initializing analyzers (#2835)
  * chore(deps): bump github.com/aws/aws-sdk-go from 1.44.77 to 1.44.92 (#2840)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=22
2022-09-19 07:30:12 +00:00
aede81fb2f - Update to version 0.31.3:
* fix: handle empty OS family (#2768)
  * fix: fix k8s summary report (#2777)
  * fix: don't skip packages that don't contain vulns, when using --list-all-pkgs flag (#2767)
  * chore: bump trivy-kubernetes (#2770)
  * fix(secret): Consider secrets in rpc calls (#2753)
  * fix(java): check depManagement from upper pom's (#2747)
  * fix(php): skip `composer.lock` inside `vendor` folder (#2718)
  * fix: fix k8s rbac filter (#2765)
  * feat(misconf): skipping misconfigurations by AVD ID (#2743)
  * chore(deps): Upgrade Alpine to 3.16.2 to fix zlib issue (#2741)
  * docs: add MacPorts install instructions (#2727)
  * docs: typo (#2730)

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=20
2022-09-05 12:17:06 +00:00