57 Commits

Author SHA256 Message Date
9ac027b7ed [info=9bcf5b04b8e4b8e4ef33271ecf56c252063a907c]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:3/trivy?expand=0&rev=1
2023-12-06 10:22:52 +00:00
eddb096084 [info=e7076f0971c7963534b0ad701267258c921d4720]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:2/trivy?expand=0&rev=1
2023-11-08 16:32:09 +00:00
d7aa926f1c [info=fe5cccdebe8c3f80a50568289bbf4e65174e54d1]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:9/trivy?expand=0&rev=1
2023-08-16 16:34:28 +00:00
2b9122f8ac [info=3b8b301ce3e352f21ca0c2faef2ca1bc9b104ec7]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:5/trivy?expand=0&rev=1
2023-08-03 11:27:23 +00:00
901d7de560 [info=46b4e36452c73989d1e9f6536ae754cc7a61d32e]
OBS-URL: https://build.opensuse.org/package/show/devel:Factory:git-workflow:staging:dirkmueller:trivy:4/trivy?expand=0&rev=1
2023-07-13 09:18:42 +00:00
Dominique Leuenberger
076cb03c4a Accepting request 1096591 from devel:Factory:git-workflow:staging:SCM_STAGING:trivy:3
🤖: Submission of trivy via  by dirkmueller

OBS-URL: https://build.opensuse.org/request/show/1096591
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=55
2023-07-04 13:21:56 +00:00
3e2167aa9b - Update to version 0.42.1:
* ci: remove 32bit packages ()
  * fix(misconf): deduplicate misconf results ()
  * fix(vm): support sector size of 4096 ()
  * fix(misconf): terraform relative paths ()
  * fix(purl): skip unsupported library type ()
  * fix(terraform): recursively detect all Root Modules ()
  * fix(vm): support post analyzer for vm command ()
  * fix(nodejs): change the type of the devDependencies field ()
  * fix(sbom): export empty dependencies in CycloneDX ()
  * refactor: add composite fs for post-analyzers ()
  * chore(deps): bump golangci/golangci-lint-action from 3.4.0 to 3.5.0 ()
  * chore(deps): bump helm/kind-action from 1.5.0 to 1.7.0 ()
  * chore(deps): bump github.com/BurntSushi/toml from 1.2.1 to 1.3.0 ()
  * chore(deps): bump github.com/alicebob/miniredis/v2 from 2.30.2 to 2.30.3 ()
  * chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 ()
  * chore(deps): bump github.com/tetratelabs/wazero from 1.0.0 to 1.2.0 ()
  * chore(deps): bump github.com/spf13/cast from 1.5.0 to 1.5.1 ()
  * chore(deps): bump github.com/testcontainers/testcontainers-go ()
  * chore(deps): bump github.com/go-git/go-git/v5 from 5.6.1 to 5.7.0 ()
  * chore(deps): bump github.com/aws/aws-sdk-go-v2/config ()
  * chore(deps): bump github.com/sigstore/rekor from 1.2.0 to 1.2.1 ()
  * chore(deps): bump alpine from 3.17.3 to 3.18.0 ()
  * feat: add SBOM analyzer ()
  * fix(sbom): update logic for work with files in spdx format ()
  * feat: azure workload identity support ()
  * feat(ubuntu): add eol date for 18.04 ESM ()
  * fix(misconf): Update required extensions for terraformplan ()
  * refactor(cyclonedx): add intermediate representation ()
  * fix(misconf): Remove debug print while scanning ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=63
2023-06-12 08:17:18 +00:00
c266b89032 - Update to version 0.41.0:
* fix(spdx): add workaround for no src packages ()
  * test(golang): rename broken go.mod ()
  * feat(sbom): add supplier field ()
  * test(misconf): skip downloading of policies for tests 
  * refactor: use debug message for post-analyze errors ()
  * feat(sbom): add VEX support ()
  * feat(sbom): add primary package purpose field for SPDX ()
  * fix(k8s): fix quiet flag ()
  * fix(python): parse of pip extras ()
  * feat(java): use full path for nested jars ()
  * feat(license): add new flag for classifier confidence level ()
  * feat: config and fs compliance support ()
  * chore(deps): bump sigstore/cosign-installer from 2.8.1 to 3.0.1 ()
  * feat(spdx): add support for SPDX 2.3 ()
  * fix: k8s all-namespaces support ()
  * perf(misconf): replace with post-analyzers ()
  * fix(helm): update networking API version detection ()
  * feat(image): custom docker host option ()
  * style: debug flag is incorrect and needs extra - ()
  * docs(vuln): Document inline vulnerability filtering comments ()
  * feat(fs): customize error callback during fs walk ()
  * fix(ubuntu): skip copyright files from subfolders ()
  * docs: restructure scanners ()
  * fix: fix `file does not exist` error for post-analyzers ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=59
2023-04-28 07:52:09 +00:00
1c04f09b2d - Update to version 0.40.0:
* feat(flag): Support globstar for `--skip-files` and `--skip-directories` ()
  * chore(deps): bump actions/stale from 7 to 8 ()
  * fix: return insecure option to download javadb ()
  * fix(nodejs): don't stop parsing when unsupported yarn.lock protocols are found ()
  * ci: add gpg signing for RPM packages ()
  * fix(k8s): current context title ()
  * fix(k8s): quit support on k8s progress bar ()
  * chore: add a note about Dockerfile.canary ()
  * ci: fix path to canary binaries ()
  * fix(vuln): report architecture for debian packages ()
  * feat: add support for Chainguard's commercial distro ()
  * ci: bump goreleaser for Github Action from 1.4.1 to 1.16.2 ()
  * fix(vuln): fix error message for remote scanners ()
  * feat(report): add image metadata to SARIF ()
  * docs: fix broken cache link on Installation page ()
  * fix: lock downloading policies and database ()
  * fix: avoid concurrent access to the global map ()
  * feat(rust): add Cargo.lock v3 support ()
  * feat: auth support oci download server subcommand ()
  * chore(deps): bump github.com/docker/docker ()
  * chore: install.sh support for armv7 ()
  * chore(deps): bump github.com/Azure/go-autorest/autorest/adal ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=56
2023-04-16 18:11:29 +00:00
a9593f7bd8 - Update to version 0.39.1:
* fix(rust): fix panic when 'dependencies' field is not used in cargo.toml ()
  * fix(sbom): fix infinite loop for cyclonedx ()
  * chore(deps): bump helm/chart-testing-action from 2.3.1 to 2.4.0 ()
  * fix: use warning for errors from enrichment files for post-analyzers ()
  * chore(deps): bump github.com/docker/docker ()
  * fix(helm): added annotation to psp configurable from values ()
  * chore(deps): bump github.com/go-git/go-git/v5 from 5.5.2 to 5.6.1 ()
  * fix(secret): update built-in rule `tests`  ()
  * chore(deps): bump github.com/alicebob/miniredis/v2 from 2.23.0 to 2.30.1 ()
  * test: rewrite scripts in Go ()
  * docs(cli): Improve glob documentation ()
  * chore(deps): bump github.com/aws/aws-sdk-go-v2/service/sts ()
  * ci: check CLI references ()
  * chore(deps): bump alpine from 3.17.2 to 3.17.3 ()
  * chore(deps): bump github.com/aws/aws-sdk-go from 1.44.212 to 1.44.234 ()
  * chore(deps): bump github.com/moby/buildkit from 0.11.4 to 0.11.5 ()
  * chore(deps): bump actions/setup-go from 3 to 4 ()
  * chore(deps): bump actions/cache from 3.2.6 to 3.3.1 ()
  * chore(deps): bump github.com/containerd/containerd from 1.6.19 to 1.7.0 ()
  * chore(deps): bump github.com/sigstore/rekor from 1.0.1 to 1.1.0 ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=55
2023-04-13 09:17:33 +00:00
062c4c4519 - Update to version 0.39.0:
* docs(cli): added makefile and go file to create docs ()
  * chore: Revert "ci: add gpg signing for RPM packages ()" ()
  * chore: ignore gpg key ()
  * feat(cyclonedx): support dependency graph ()
  * chore(deps): Bump defsec to v0.85.0 ()
  * feat(rust): remove dev deps and find direct deps for Cargo.lock ()
  * feat(server): redis with public TLS certs support ()
  * feat(flag): Add glob support to `--skip-dirs` and `--skip-files`  ()
  * chore: replace make with mage ()
  * fix(sbom): add checksum to files ()
  * chore(deps): bump github.com/opencontainers/runc from 1.1.4 to 1.1.5 ()
  * chore: remove unused mount volumes ()
  * feat: add auth support for downloading OCI artifacts ()
  * refactor(purl): use epoch in qualifier ()
  * chore(deps): bump github.com/in-toto/in-toto-golang from 0.5.0 to 0.7.0 ()
  * feat(image): add registry options ()
  * feat(rust): dependency tree and line numbers support for cargo lock file ()
  * chore(deps): bump google.golang.org/protobuf from 1.29.0 to 1.29.1 ()
  * feat(php): add support for location, licenses and graph for composer.lock files ()
  * chore(deps): updates wazero to 1.0.0 ()
  * feat(image): discover SBOM in OCI referrers ()
  * docs: change cache-dir key in config file ()
  * fix(sbom): use release and epoch for SPDX package version ()
  * ci: add gpg signing for RPM packages ()
  * docs: Update incorrect comment for skip-update flag ()
  * refactor(misconf): simplify policy filesystem ()
  * feat(nodejs): parse package.json alongside yarn.lock ()
  * fix(spdx): add PkgDownloadLocation field ()
  * fix(report): try to guess direct deps for dependency tree ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=53
2023-04-03 12:32:29 +00:00
b319fb593e - Update to version 0.38.3:
* chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.86.1 to 1.89.1 ()
  * fix(java): skip empty files for jar post analyzer ()
  * fix(docker): build healthcheck command for line without /bin/sh prefix ()
  * refactor(license): use goyacc for license parser ()
  * chore(deps): bump github.com/docker/docker from 23.0.0-rc.1+incompatible to 23.0.1+incompatible ()
  * fix: populate timeout context to node-collector ()
  * fix: exclude node collector scanning ()
  * fix: display correct flag in error message when skipping java db update 
  * fix: disable jar analyzer for scanners other than vuln ()
  * fix(sbom): fix incompliant license format for spdx ()
  * fix(java): the project props take precedence over the parent's props ()
  * docs: add canary build info to README.md ()
  * docs: adding link to gh token generation ()
  * docs: changing docs in accordance with  ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=50
2023-03-14 09:57:08 +00:00
18a2b0893a - Update to version 0.38.2:
* chore(deps): bump github.com/moby/buildkit from 0.11.0 to 0.11.4 ()
  * chore(deps): bump actions/add-to-project from 0.4.0 to 0.4.1 ()
  * fix(license): disable jar analyzer for licence scan only ()
  * bump trivy-issue-action to v0.0.0; skip `pkg` dir ()
  * fix: skip checking dirs for required post-analyzers ()
  * docs: add information about plugin format ()
  * fix(sbom): add trivy version to spdx creators tool field ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=48
2023-03-08 11:07:56 +00:00
a65dfd33d7 - Update to version 0.38.1:
* feat(misconf): Add support to show policy bundle version ()
  * fix(python): fix error with optional dependencies in pyproject.toml ()
  * chore(deps): bump github.com/aws/aws-sdk-go from 1.44.210 to 1.44.212 ()
  * add id for package.json files ()
  * chore(deps): bump github.com/containerd/containerd from 1.6.18 to 1.6.19 ()
  * chore(deps): bump actions/cache from 3.2.4 to 3.2.6 ()
  * chore(deps): bump github.com/google/go-containerregistry ()
  * chore(deps): bump go.etcd.io/bbolt from 1.3.6 to 1.3.7 ()
  * chore(deps): bump alpine from 3.17.1 to 3.17.2 ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=46
2023-03-02 17:38:57 +00:00
4e5f1d07de - Update to version 0.38.0:
* fix(cli): pass integer to exit-on-eol ()
  * feat: add kubernetes pss compliance ()
  * feat: Adding --module-dir and --enable-modules ()
  * feat: add special IDs for filtering secrets ()
  * chore(deps): Update defsec ()
  * docs(misconf): Add guide on input schema ()
  * feat(go): support dependency graph and show only direct dependencies in the tree ()
  * feat: docker multi credential support ()
  * feat: summarize vulnerabilities in compliance reports ()
  * feat(python): parse pyproject.toml alongside poetry.lock ()
  * feat(python): add dependency tree for poetry lock file ()
  * fix(cyclonedx): incompliant affect ref ()
  * chore(helm): update skip-db-update environment variable ()
  * fix(spdx): change CreationInfo timestamp format RFC3336Nano to RFC3336 ()
  * fix(sbom): export empty dependencies in CycloneDX ()
  * docs: java-db air-gap doc tweaks ()
  * feat(go): license support ()
  * feat(ruby): add dependency tree/location support for Gemfile.lock ()
  * fix(k8s): k8s label size ()
  * fix(cyclondx): fix array empty value, null to [] ()
  * refactor: rewrite gomod analyzer as post-analyzer ()
  * feat: config outdated-api result filtered by k8s version ()
  * fix: Update to Alpine 3.17.2 ()
  * feat: add support for virtual files ()
  * feat: add post-analyzers ()
  * chore(deps): updates wazero to 1.0.0-pre.9 ()
  * chore(deps): bump github.com/go-openapi/runtime from 0.24.2 to 0.25.0 ()
  * chore(deps): bump github.com/containerd/containerd from 1.6.15 to 1.6.18 ()
  * feat(python): add dependency locations for Pipfile.lock ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=44
2023-03-01 10:45:59 +00:00
d2c9e8e17e - Update to version 0.37.3 (bsc#1208091, CVE-2023-25165):
* chore(helm): update Trivy from v0.36.1 to v0.37.2 ()
  * chore(deps): bump github.com/spf13/viper from 1.14.0 to 1.15.0 ()
  * chore(deps): bump golang/x/mod to v0.8.0 ()
  * chore(deps): bump golang.org/x/crypto from 0.3.0 to 0.5.0 ()
  * chore(deps): bump helm.sh/helm/v3 from 3.10.3 to 3.11.1 ()
  * ci: quote pros in c++ for semantic pr ()
  * fix(image): check proxy settings from env for remote images ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=42
2023-02-15 08:41:42 +00:00
2ec944171e Accepting request 1064149 from home:ojkastl_buildservice:Branch_Virtualization_containers
update to 0.37.2

OBS-URL: https://build.opensuse.org/request/show/1064149
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=40
2023-02-10 08:08:46 +00:00
d95d3d3fa3 - Update to version 0.37.1:
* fix(sbom): download the Java DB when generating SBOM ()
  * fix: use cgo free sqlite driver ()
  * ci: fix path to dist folder ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=38
2023-02-01 16:22:25 +00:00
672c04bdc6 - Update to version 0.37.0:
* fix(image): close layers ()
  * refactor: db client changed ()
  * feat(java): use trivy-java-db to get GAV ()
  * docs: add note about the limitation in Rekor ()
  * docs: aggregate targets ()
  * deps: updates wazero to 1.0.0-pre.8 ()
  * docs: add alma 9 and rocky 9 to supported os ()
  * chore(deps): bump defsec to v0.82.9 ()
  * chore: add missing target labels ()
  * docs: add java vulnerability page ()
  * feat(image): add support for Docker CIS Benchmark ()
  * feat(image): secret scanning on container image config ()
  * chore(deps): Upgrade defsec to v0.82.8 ()
  * feat(image): scan misconfigurations in image config ()
  * chore(helm): update Trivy from v0.30.4 to v0.36.1 ()
  * feat(k8s): add node info resource ()
  * perf(secret): optimize secret scanning memory usage ()
  * feat: support aliases in CLI flag, env and config ()
  * fix(k8s): migrate rbac k8s ()
  * feat(java): add implementationVendor and specificationVendor fields to detect GroupID from MANIFEST.MF ()
  * refactor: rename security-checks to scanners ()
  * chore: display the troubleshooting URL for the DB denial error ()
  * docs: yaml tabs to spaces, auto create namespace ()
  * docs: adding show-and-tell template to GH discussions ()
  * fix: Fix a temporary file leak in case of error ()
  * fix(test): sort cyclonedx components ()
  * docs: fixing spelling mistakes ()
  * ci: set paths triggering VM tests in PR ()
  * docs: typo in --skip-files ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=36
2023-02-01 12:11:50 +00:00
8feee24f2e - Update to version 0.36.1:
* fix(deps): fix errors on yarn.lock files that contain local file reference ()
  * feat(flag): early fail when the format is invalid ()
  * chore(deps): bump github.com/aws/aws-sdk-go from 1.44.136 to 1.44.171 ()
  * docs(aws): fix broken links ()
  * chore(deps): bump actions/stale from 6 to 7 ()
  * chore(deps): bump helm/kind-action from 1.4.0 to 1.5.0 ()
  * chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.6.0 to 0.7.0 ()
  * chore(deps): bump azure/setup-helm from 3.4 to 3.5 ()
  * chore(deps): bump github.com/moby/buildkit from 0.10.4 to 0.10.6 ()
  * chore(deps): bump goreleaser/goreleaser-action from 3 to 4 ()
  * chore(deps): bump github.com/containerd/containerd from 1.6.8 to 1.6.14 ()
  * chore(go): updates wazero to v1.0.0-pre.7 ()
  * chore(deps): bump golang.org/x/text from 0.4.0 to 0.5.0 ()
  * chore(deps): bump actions/cache from 3.0.11 to 3.2.2 ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=34
2023-01-05 12:15:28 +00:00
4e05e2e98d - Update to version 0.36.0:
* docs: improve compliance docs ()
  * feat(deps): add yarn lock dependency tree ()
  * fix: compliance change id and title naming ()
  * feat: add support for mix.lock files for elixir language ()
  * feat: add k8s cis bench ()
  * test: disable SearchLocalStoreByNameOrDigest test for non-amd64 arch ()
  * revert: cache merged layers ()
  * feat(cyclonedx): add recommendation ()
  * feat(ubuntu): added support ubuntu ESM versions ()
  * fix: change logic to build relative paths for skip-dirs and skip-files ()
  * chore(deps): bump github.com/hashicorp/golang-lru from 0.5.4 to 2.0.1 ()
  * feat: Adding support for Windows testing ()
  * feat: add support for Alpine 3.17 ()
  * docs: change PodFile.lock to Podfile.lock ()
  * fix(sbom): support for the detection of old CycloneDX predicate type ()
  * feat(secret): Use .trivyignore for filtering secret scanning result ()
  * chore(go): remove experimental FS API usage in Wasm ()
  * ci: add workflow to add issues to roadmap project ()
  * fix(vuln): include duplicate vulnerabilities with different package paths in the final report ()
  * chore(deps): bump github.com/spf13/viper from 1.13.0 to 1.14.0 ()
  * feat(sbom): better support for third-party SBOMs ()
  * docs: add information about languages with support for dependency locations ()
  * feat(vm): add `region` option to vm scan to be able to scan any region's ami and ebs snapshots ()
  * chore(deps): bump github.com/Azure/azure-sdk-for-go from 66.0.0+incompatible to 67.1.0+incompatible ()
  * fix(vuln): change severity vendor priority for ghsa-ids and vulns from govuln ()
  * docs: remove comparisons ()
  * feat: add support for Wolfi Linux ()
  * ci: add go.mod to canary workflow ()
  * feat(python): skip dev dependencies ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=32
2023-01-02 08:37:03 +00:00
83b7bc68d6 Accepting request 1038580 from home:ojkastl_buildservice:Branch_Virtualization_containers
update to 0.35.0

OBS-URL: https://build.opensuse.org/request/show/1038580
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=30
2022-11-28 08:09:58 +00:00
2f67d2596c Accepting request 1032484 from home:ojkastl_buildservice:Branch_Virtualization_containers
update to 0.34.0

OBS-URL: https://build.opensuse.org/request/show/1032484
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=28
2022-11-07 10:10:13 +00:00
1afcdaafd3 Accepting request 1031236 from home:ojkastl_buildservice:Branch_Virtualization_containers
update to 0.33.0

OBS-URL: https://build.opensuse.org/request/show/1031236
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=26
2022-10-26 06:33:34 +00:00
a79a01c42a - Update to version 0.32.1:
* fix(java): use fields of dependency from dependencyManagement from upper pom.xml to parse deps ()
  * chore: expat lib and go binary deps vulns ()
  * wasm: Removes accidentally exported memory ()
  * fix(sbom): fix package name separation for gradle ()
  * docs(readme.md): fix broken integrations link ()
  * fix(image): handle images with single layer in rescan mergedLayers cache ()
  * fix(cli): split env values with ',' for slice flags ()
  * fix(cli): config/helm: also take into account files with `.yml` ()
  * fix(flag): add file-patterns flag for config subcommand ()
  * chore(deps): bump github.com/open-policy-agent/opa from 0.43.0 to 0.43.1 ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=24
2022-09-28 14:07:00 +00:00
c7371b4a31 - Update to version 0.32.0:
* docs: add Rekor SBOM attestation scanning ()
  * chore: narrow the owner scope ()
  * fix: remove a patch number from the recommendation link ()
  * fix: enable parsing of UUID-only rekor entry ID ()
  * docs(sbom): add SPDX scanning ()
  * docs: restructure docs and add tutorials ()
  * feat(sbom): scan sbom attestation in the rekor record ()
  * feat(k8s): support outdated-api ()
  * chore(deps): bump github.com/moby/buildkit from 0.10.3 to 0.10.4 ()
  * fix(c): support revisions in Conan parser ()
  * feat: dynamic links support for scan results ()
  * chore(deps): bump go.uber.org/zap from 1.22.0 to 1.23.0 ()
  * docs: update archlinux commands ()
  * feat(secret): add line from dockerfile where secret was added to secret result ()
  * feat(sbom): Add unmarshal for spdx ()
  * chore(deps): bump github.com/aws/aws-sdk-go-v2/config ()
  * fix: revert asff arn and add documentation ()
  * docs: batch-import-findings limit ()
  * chore(deps): bump golang from 1.19.0 to 1.19.1 ()
  * feat(sbom): Add marshal for spdx ()
  * build: checkout before setting up Go ()
  * chore: bump Go to 1.19 ()
  * docs: azure doc and trivy ()
  * fix: Scan tarr'd dependencies ()
  * chore(helm): helm test with ingress ()
  * feat(report): add secrets to sarif format ()
  * chore(deps): bump azure/setup-helm from 1.1 to 3.3 ()
  * refactor: add a new interface for initializing analyzers ()
  * chore(deps): bump github.com/aws/aws-sdk-go from 1.44.77 to 1.44.92 ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=22
2022-09-19 07:30:12 +00:00
aede81fb2f - Update to version 0.31.3:
* fix: handle empty OS family ()
  * fix: fix k8s summary report ()
  * fix: don't skip packages that don't contain vulns, when using --list-all-pkgs flag ()
  * chore: bump trivy-kubernetes ()
  * fix(secret): Consider secrets in rpc calls ()
  * fix(java): check depManagement from upper pom's ()
  * fix(php): skip `composer.lock` inside `vendor` folder ()
  * fix: fix k8s rbac filter ()
  * feat(misconf): skipping misconfigurations by AVD ID ()
  * chore(deps): Upgrade Alpine to 3.16.2 to fix zlib issue ()
  * docs: add MacPorts install instructions ()
  * docs: typo ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=20
2022-09-05 12:17:06 +00:00
777f4f2773 - Update to version 0.31.2:
* fix: Correctly handle recoverable AWS scanning errors ()
  * docs: Remove reference to SecurityAudit policy for AWS scanning ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=18
2022-08-16 19:37:39 +00:00
481673a33f - Update to version 0.31.1:
* fix: upgrade defsec to v0.71.7 for elb scan panic ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=16
2022-08-16 13:34:38 +00:00
c72c54c5e4 - Update to version 0.31.0:
* fix(flag): add error when there are no supported security checks ()
  * fix(vuln): continue scanning when no vuln found in the first application ()
  * revert: add new classes for vulnerabilities ()
  * feat(secret): detect secrets removed or overwritten in upper layer ()
  * fix(cli): secret scanning perf link fix ()
  * chore(deps): bump github.com/spf13/viper from 1.8.1 to 1.12.0 ()
  * feat: Add AWS Cloud scanning ()
  * docs: specify the type when verifying an attestation ()
  * docs(sbom): improve SBOM docs by adding a description for scanning SBOM attestation ()
  * fix(rpc): scanResponse rpc conversion for custom resources ()
  * feat(rust): Add support for cargo-auditable ()
  * feat: Support passing value overrides for configuration checks ()
  * feat(sbom): add support for scanning a sbom attestation ()
  * chore(image): skip symlinks and hardlinks from tar scan ()
  * fix(report): Update junit.tpl ()
  * fix(cyclonedx): add nil check to metadata.component ()
  * docs(secret): fix missing and broken links ()
  * refactor(cyclonedx): implement json.Unmarshaler ()
  * chore(deps): bump github.com/aquasecurity/table from 1.6.0 to 1.7.2 ()
  * chore(deps): bump github.com/Azure/go-autorest/autorest ()
  * feat(kubernetes): add option to specify kubeconfig file path ()
  * docs:  follow Debian's "instructions to connect to a third-party repository" ()
  * chore(deps): bump github.com/google/licenseclassifier/v2 ()
  * chore(deps): bump github.com/samber/lo from 1.24.0 to 1.27.0 ()
  * chore(deps): bump github.com/Azure/go-autorest/autorest/adal ()
  * chore(deps): bump github.com/cheggaaa/pb/v3 from 3.0.8 to 3.1.0 ()
  * chore(deps): bump sigstore/cosign-installer from 2.4.1 to 2.5.0 ()
  * chore(deps): bump actions/cache from 3.0.4 to 3.0.5 ()
  * chore(deps): bump alpine from 3.16.0 to 3.16.1 ()

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=15
2022-08-16 12:09:06 +00:00
7a3aec4740 Accepting request 991366 from home:ojkastl_buildservice:Branch_Virtualization_containers
update to 0.30.4

OBS-URL: https://build.opensuse.org/request/show/991366
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=13
2022-07-27 13:15:36 +00:00
2625ca5f8f Accepting request 990661 from home:ojkastl_buildservice:Branch_Virtualization_containers
update to 0.30.2

OBS-URL: https://build.opensuse.org/request/show/990661
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=11
2022-07-22 11:25:22 +00:00
12697e9c2a Accepting request 990399 from home:ojkastl_buildservice:Branch_Virtualization_containers
update to 0.30.1

OBS-URL: https://build.opensuse.org/request/show/990399
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=10
2022-07-21 09:48:49 +00:00
499dfbf363 Accepting request 989624 from home:ojkastl_buildservice:Branch_Virtualization_containers
update to 0.30.0

OBS-URL: https://build.opensuse.org/request/show/989624
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=8
2022-07-18 14:08:59 +00:00
0391b2d8e4 - Update to version 0.29.2:
* chore: skip Visual Studio Code project folder ()
  * fix(helm): handle charts with templated names ()
  * docs: redirect operator docs to trivy-operator repo ()
  * fix(secret): use secret result when determining Failed status ()
  * try removing libdb-dev
  * run integration tests in fanal
  * use same testing images in fanal
  * feat(helm): add support for trivy dbRepository ()
  * fix: Fix failing test due to deref lint issue
  * test: Fix broken test
  * fix: Fix makefile when no previous named ref is visible in a shallow clone
  * chore: Fix linting issues in fanal
  * refactor: Fix fanal import paths and remove dotfiles
  * chore: bump defsec version v0.68.1

OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=6
2022-07-08 07:39:10 +00:00
a0ae104f70 Accepting request 984475 from home:ojkastl_buildservice:Branch_Virtualization_containers
update to 0.29.1

OBS-URL: https://build.opensuse.org/request/show/984475
OBS-URL: https://build.opensuse.org/package/show/Virtualization:containers/trivy?expand=0&rev=4
2022-06-23 06:02:26 +00:00
Dominique Leuenberger
7d9d718b33 Accepting request 978633 from Virtualization:containers
- Update to version 0.28.0 (bsc#1199760, CVE-2022-28946):
  * fix: remove Highlighted from json output ()
  * fix: remove trivy-kubernetes replace ()
  * docs: Add Operator docs under Kubernetes section ()
  * fix(k8s): security-checks panic ()
  * ci: added k8s scope ()
  * docs: Update misconfig output in examples ()
  * fix(misconf): Fix coloured output in Goland terminal ()
  * docs(secret): Fix default value of --security-checks in docs ()
  * refactor(report): move colorize function from trivy-db ()
  * feat: k8s resource scanning ()
  * chore: add CODEOWNERS ()
  * feat(image): add `--server` option for remote scans ()
  * refactor: k8s ()
  * refactor: export useful APIs ()
  * docs: fix k8s doc ()
  * feat(kubernetes): Add report flag for summary ()
  * fix: Remove problematic advanced rego policies ()
  * feat(misconf): Add special output format for misconfigurations ()
  * feat:  add k8s subcommand ()
  * chore: fix make lint version ()
  * fix(java): handle relative pom modules ()
  * fix(misconf): Add missing links for non-rego misconfig results ()
  * feat(misconf): Added fs.FS based scanning via latest defsec ()
  * chore(deps): bump trivy-issue-action to v0.0.4 ()
  * chore(deps): bump github.com/twitchtv/twirp ()
  * chore(deps): bump github.com/urfave/cli/v2 from 2.4.0 to 2.5.1 ()
  * chore(os): updated fanal version and alpine distroless test ()
  * chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.5.1 to 0.5.2 ()
  * chore(deps): bump github.com/samber/lo from 1.16.0 to 1.19.0 ()

OBS-URL: https://build.opensuse.org/request/show/978633
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=25
2022-05-23 13:51:56 +00:00
Dominique Leuenberger
538b73ffc5 Accepting request 973909 from devel:kubic
OBS-URL: https://build.opensuse.org/request/show/973909
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=24
2022-04-29 22:46:07 +00:00
Dominique Leuenberger
7ebb134dc1 Accepting request 972935 from devel:kubic
OBS-URL: https://build.opensuse.org/request/show/972935
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=23
2022-04-26 18:16:18 +00:00
Dominique Leuenberger
3d611306a8 Accepting request 970622 from devel:kubic
OBS-URL: https://build.opensuse.org/request/show/970622
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=22
2022-04-19 07:58:28 +00:00
Dominique Leuenberger
12c2451802 Accepting request 967695 from devel:kubic
OBS-URL: https://build.opensuse.org/request/show/967695
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=21
2022-04-08 20:45:39 +00:00
Dominique Leuenberger
05f6bff4d4 Accepting request 966387 from devel:kubic
OBS-URL: https://build.opensuse.org/request/show/966387
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=20
2022-04-01 19:36:12 +00:00
Dominique Leuenberger
5743b6ba0b Accepting request 963467 from devel:kubic
OBS-URL: https://build.opensuse.org/request/show/963467
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=18
2022-03-21 19:11:35 +00:00
Dominique Leuenberger
f6ba84dfa9 Accepting request 962469 from devel:kubic
OBS-URL: https://build.opensuse.org/request/show/962469
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=17
2022-03-17 16:01:51 +00:00
Dominique Leuenberger
d13d78fbdd Accepting request 959290 from devel:kubic
OBS-URL: https://build.opensuse.org/request/show/959290
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=16
2022-03-03 23:19:34 +00:00
Dominique Leuenberger
f2e4016652 Accepting request 950418 from devel:kubic
OBS-URL: https://build.opensuse.org/request/show/950418
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=15
2022-02-01 15:59:47 +00:00
Dominique Leuenberger
af76884223 Accepting request 942895 from devel:kubic
Update to version 0.22.0:
  * fix(java/pom): ignore unsupported requirements ()
  * feat(cli): warning for root command ()
  * BREAKING: disable JAR detection in fs/repo scanning ()
  * feat(scan): support --offline-scan option ()
  * fix: improve memory usage ()
  * feat(java): support pom.xml ()
  * docs: fixing rust link to security advisory ()
  * Add missing IacMetdata ()
  * feat(jar): add file path ()
  * feat(rpm): support NDB ()
  * feat: added misconfiguration field for html.tpl ()

OBS-URL: https://build.opensuse.org/request/show/942895
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=13
2021-12-28 12:17:07 +00:00
Dominique Leuenberger
3fc0b65644 Accepting request 941786 from devel:kubic
- Update to version 0.21.3:
  * fix(docs): typo ()
  * feat(plugin): Add option to update plugin ()
  * fix: fixed skipFiles/skipDirs flags for relative path ()
  * feat (plugin): add list and info command for plugin ()
  * fix: set up a vulnerability severity ()
  * chore: add arm64 deb package ()
  * Link to trivy tutorial on Semaphore ()
  * refactor(helm): externalize env vars to configMap ()
  * docs: provide more information on scanning Google's GCR ()
  * docs(misconfiguration): added instruction for misconfiguration detection ()
  * Update git-repository.md ()
  * fix(hooks): exclude unrelated lib types from system files filtering ()
  * chore: run `go fmt` ()
  * fix(sarif): change `help` field in the sarif template. ()
  * Update fanal with cfsec version update ()
  * Replace deprecated option in goreleaser ()
  * feat(alpine): support 3.15 ()
  * chore: test the helm chart in the PR and used the commit hash ()
  * chore(deps): bump alpine from 3.14 to 3.15.0 ()
  * chore(release): add ubuntu older versions to deploy script ()

OBS-URL: https://build.opensuse.org/request/show/941786
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=12
2021-12-21 17:40:41 +00:00
Dominique Leuenberger
fd2035c8f7 Accepting request 935778 from devel:kubic
- Update to version 0.21.1:
  * chore(mod): tidy ()
  * fix(rpc): fix nil layer transmit ()
  * Lang advisory order ()
  * chore: add support for s390x arch ()
  * fix(chart): ingress helm manifest-update trivy image ()
  * docs: Add comparison for cfsec ()
  * remove: delete unused functions in utils package ()
  * fix(sarif): fix validation errors ()
  * docs: add Bitbucket Pipelines ()
  * docs: add community integrations ()
  * Use a stable SARIF identifier ()
  * fix(python): fix parsing of requirements.txt with hash checking mode available in pip since version 8.0
  * feat(iac): Add line information ()
  * feat(cloudformation): Adding support for cfsec IaC scanning ()
  * chore: send debug and info logs to stdout in install.sh, not stderr. ()
  * Update containerd to v1.5.7 and docker-cli to v20.10.9 ()
  * chore: update SBOM generation ()

OBS-URL: https://build.opensuse.org/request/show/935778
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=11
2021-12-05 21:46:20 +00:00
Dominique Leuenberger
637d09bb64 Accepting request 930653 from devel:kubic
- Update to version 0.20.2:
  * docs: update builtin.md ()
  * chore: fix issues with Homebrew formula ()
  * chore: bump GoReleaser to v0.183.0 ()
  * docs: update iac.md for a typo ()
  * docs: typo fix ()
  * Add new networking API features to Ingress ()
  * chore(release): bump up GoReleaser to v0.182.1 ()
  * fix(yarn): support quoted version ()
  * feat(custom-forward): Forward the extended advisory data ()
  * feat(javascript) : Initialize npm driver for javascript packages ()
  * fix(cli): fix incorrect comparision of DB metadata type. ()
  * docs: add footer to readme ()
  * feat(report): add package path ()
  * feat(command): add rootfs command ()
  * fix: update fanal ()
  * feat(commands): remove deprecated options ()
  * Aggregate jar result for table ()
  * BREAKING(report): migrate to new json schema ()
  * feat: improve --skip-dirs and --skip-files ()
  * fix(gobinary): skip large files ()
  * Disable library analyzer for OS only scan type ()
  * chore: update trivy version ()
  * refactor: move from io/ioutil to io and os package ()
  * fix: brew test command ()
  * fix:added layer info in packages ()
  * fix(go/binary): improve debug messages ()
  * Update db.go ()
  * fix(deps): fix CVE-2021-32760 for github.com/containerd/containerd ()
  * feat(debian): support the versions that reached EOL ()

OBS-URL: https://build.opensuse.org/request/show/930653
OBS-URL: https://build.opensuse.org/package/show/openSUSE:Factory/trivy?expand=0&rev=10
2021-11-10 20:46:48 +00:00