Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
0.56.2
->0.59.1
3.20.3
->3.21.3
v1.61.0
->v1.64.5
Release Notes
aquasecurity/trivy (docker.io/aquasec/trivy)
v0.59.1
Compare Source
Changelog
9aabfd2
release: v0.59.1 [release/v0.59] (#8334)412c690
fix(misconf): do not log scanners when misconfig scanning is disabled [backport: release/v0.59] (#8349)98f9ba2
chore(deps): bump Go tov1.23.5
[backport: release/v0.59] (#8343)1741fdd
fix(python): addpoetry
v2 support [backport: release/v0.59] (#8335)3fd8e27
fix(sbom): preserve OS packages from multiple SBOMs [backport: release/v0.59] (#8333)v0.59.0
Compare Source
Features
--distro
flag to manually specify OS distribution for vulnerability scanning (#8070) (da17dc7)Bug Fixes
dpkg
packages with different filePaths from different layers (#8298) (846498d)--generate-default-config
command (#8046) (5e68bdc)BLOW_UNKNOWN
error to download DBs (#8060) (51f2123)project.*
props (#8050) (9d9f80d)usr/share/buildinfo/
dir to detect content sets (#8222) (f352f6b)unknown
dependencies (if exists) (#8104) (7558df7)hasExtractedLicensingInfos
field for licenses that are not listed in the SPDX (#8077) (aec8885)Performance Improvements
v0.58.2
Compare Source
Changelog
936f06a
release: v0.58.2 [release/v0.58] (#8216)f72d2bc
fix(misconf): allow null values only for tf variables [backport: release/v0.58] (#8238)2896367
fix(suse): SUSE - update OSType constants and references for compatility [backport: release/v0.58] (#8237)b733ecc
fix: CVE-2025-21613 and CVE-2025-21614 : go-git: argument injection via the URL field [backport: release/v0.58] (#8215)v0.58.1
Compare Source
⚡Release highlights and summary⚡
👉 https://github.com/aquasecurity/trivy/discussions/8171
Changelog
https://github.com/aquasecurity/trivy/blob/release/v0.58/CHANGELOG.md#0581-2024-12-24
v0.58.0
Compare Source
Features
workspaceRelationship
(#7889) (d622ca2)go.mod
main module in the parser (#7977) (5448ba2)flavors
support (#7858) (b9b383e)Bug Fixes
UID
for removed packages (#7887) (07915da)mirror.gcr.io
(#7953) (9988147)root/buildinfo/content_manifests/
contains files that are notcontentSets
files (#7912) (38775a5)[email protected]
schema for misconfigs insarif
report (#7898) (19aea4b)v0.57.1
Compare Source
⚡Release highlights and summary⚡
👉https://github.com/aquasecurity/trivy/discussions/7951
Changelog
https://github.com/aquasecurity/trivy/blob/release/v0.57/CHANGELOG.md#0571-2024-11-18
v0.57.0
Compare Source
⚠ BREAKING CHANGES
Features
trivy auth
(#7664) (27117f8)trivy auth
totrivy registry
(#7727) (633a7ab)CycloneDX
reports (#7507) (c225883)Bug Fixes
clean --all
deletes only relevant dirs (#7704) (672e886)version
andscope
from upper/rootdepManagement
anddependencies
into parents (#7541) (778df82)git clone
output to Stderr (#7561) (fdf203c)Annotation
instead ofAttributionTexts
forSPDX
formats (#7811) (f2bb9c6)golangci/golangci-lint (golangci/golangci-lint)
v1.64.5
Compare Source
new-from-merge-base-flag
asciicheck
: from 0.3.0 to 0.4.0forcetypeassert
: from 0.1.0 to 0.2.0gosec
: from 2.22.0 to 2.22.1v1.64.4
Compare Source
gci
: fix standard packages list for go1.24v1.64.3
Compare Source
ginkgolinter
: from 0.18.4 to 0.19.0go-critic
: from 0.11.5 to 0.12.0revive
: from 1.6.0 to 1.6.1gci
: fix standard packages list for go1.24v1.64.2
Compare Source
This is the last minor release of golangci-lint v1.
The next release will be golangci-lint v2.
issues.new-from-merge-base
optionrun.relative-path-mode
optioncopyloopvar
: from 1.1.0 to 1.2.1 (support suggested fixes)exptostd
: from 0.3.1 to 0.4.1 (handlesgolang.org/x/exp/constraints.Ordered
)fatcontext
: from 0.5.3 to 0.7.1 (new option:check-struct-pointers
)perfsprint
: from 0.7.1 to 0.8.1 (new options:integer-format
,error-format
,string-format
,bool-format
, andhex-format
)revive
: from 1.5.1 to 1.6.0 (new rules:redundant-build-tag
,use-errors-new
. New optionearly-return.early-return
)go-errorlint
: from 1.7.0 to 1.7.1gochecknoglobals
: from 0.2.1 to 0.2.2godox
: from006bad1
to 1.1.0gosec
: from 2.21.4 to 2.22.0iface
: from 1.3.0 to 1.3.1nilnesserr
: from 0.1.1 to 0.1.2protogetter
: from 0.3.8 to 0.3.9sloglint
: from 0.7.2 to 0.9.0spancheck
: fix defaultStartSpanMatchersSlice
valuesstaticcheck
: from 0.5.1 to 0.6.0tenv
is deprecated and replaced byusetesting.os-setenv: true
.depguard
configurationv1.64.1
Compare Source
Cancelled due to CI failure.
v1.64.0
Compare Source
Cancelled due to CI failure.
v1.63.4
Compare Source
dupl
,gomodguard
,revive
: keep only Go-files.v1.63.3
Compare Source
gofmt
,gofumpt
,goimports
,gci
: panic with several trailing EOLgoheader
: skip issues with invalid positionsv1.63.2
Compare Source
gofmt
,gofumpt
,goimports
,gci
: panic with missing trailing EOLv1.63.1
Compare Source
cgi
: invalid reports with cgogofumpt
: panic with autofix and cgov1.63.0
Compare Source
gofmt
,goimports
,gofumpt
,gci
) are applied after the suggested fixes.exptostd
linter https://github.com/ldez/exptostdnilnesserr
linter https://github.com/alingse/nilnesserrusetesting
linter https://github.com/ldez/usetestinggci
: new options:no-inline-comments
,no-prefix-comments
gomoddirectives
: from 0.2.4 to 0.6.0 (new options:go-version-pattern
,toolchain-pattern
,toolchain-forbidden
,tool-forbidden
,go-debug-forbidden
)govet
: newstdversion
,waitgroup
analyzersimportas
: allow multiple empty aliasesloggercheck
: newslog
optionrecvcheck
: from 0.1.2 to 0.2.0 (new options:disable-builtin
,exclusions
)tagliatelle
: from 0.5.0 to 0.7.1 (new options:ignored-fields
,extended-rules
,overrides
,pkg
,ignore
)usestdlibvars
: from 1.27.0 to 1.28.0 (autofix)wrapcheck
: from 2.9.0 to 2.10.0 (new option:extra-ignore-sigs
)asciicheck
: from 0.2.0 to 0.3.0bodyclose
: from5742072
toed6a65f
funlen
: from 0.1.0 to 0.2.0ginkgolinter
: from 0.18.3 to 0.18.4gochecksumtype
: from 0.2.0 to 0.3.1gocognit
: from 1.1.3 to 1.2.0godot
: from 1.4.18 to 1.4.20goheader
: report position improvementgosec
: handling of global nosec option when it is falseiface
: from 1.2.1 to 1.3.0importas
: from 0.1.0 to 0.2.0intrange
: from 0.2.1 to 0.3.0makezero
: from 1.1.1 to 1.2.0mirror
: from 1.2.0 to 1.3.0nilnil
: from 1.0.0 to 1.0.1nosprintfhostport
: from 0.1.1 to 0.2.0reassign
: from 0.2.0 to 0.3.0spancheck
: from 0.6.2 to 0.6.4tagalign
: from 1.3.4 to 1.4.1wastedassign
: from 2.0.7 to 2.1.0whitespace
: from 0.1.1 to 0.2.0wsl
: from 4.4.1 to 4.5.0output.uniq-by-line
is deprecated and replaced byissues.uniq-by-line
.decoder
,sloglint
,tagalign
fromformat
preset.run.timeout
<= 0.v1.62.2
Compare Source
fatcontext
: from 0.5.2 to 0.5.3ginkgolinter
: from 0.18.0 to 0.18.3errorlint
: from 1.6.0 to 1.7.0iface
: from 1.2.0 to 1.2.1revive
: from 1.5.0 to 1.5.1testifylint
: from 1.5.0 to 1.5.2v1.62.1
Compare Source
Cancelled due to CI failure.
v1.62.0
Compare Source
recvcheck
linter https://github.com/raeperd/recvcheckiface
linter https://github.com/uudashr/ifaceginkgolinter
: from 0.17.0 to 0.18.0 (new option:force-succeed
)gochecksumtype
: from 0.1.4 to 0.2.0 (new option:default-signifies-exhaustive
)loggercheck
: from 0.9.4 to 0.10.1 (log/slog
support)nilnil
: from 0.1.9 to 1.0.0 (new option:detect-opposite
)revive
: from 1.3.9 to 1.5.0 (new rules:filename-format
, andfile-length-limit
)tenv
: from 1.10.0 to 1.12.1 (handle dot import)testifylint
: from 1.4.3 to 1.5.0 (new checkers:contains
,encoded-compare
,regexp
)bidichk
: from 0.2.7 to 0.3.2 (important performance improvement)canonicalheader
: from 1.1.1 to 1.1.2cyclop
: from 1.2.1 to 1.2.3dupword
: from 0.1.1 to 0.1.3errcheck
: from 1.7.0 to 1.8.0errchkjson
: from 0.3.6 to 0.4.0errname
: from 0.1.13 to 1.0.0gocritic
: from 0.11.4 to 0.11.5goprintffuncname
: from7558a9e
to v0.1.0godot
: from 1.4.17 to 1.4.18gosec
: from 2.21.2 to 2.21.4intrange
: from 0.2.0 to 0.2.1musttag
: from 0.12.2 to 0.13.0nakedret
: from 2.0.4 to 2.0.5noctx
: from 0.0.2 to 0.1.0protogetter
: from 0.3.6 to 0.3.8execinquery
: deprecation step 2gomnd
: deprecation step 2 (replaced bymnd
)exclude-dirs-use-default
forbidigo
pattern examples for built-in functionsConfiguration
📅 Schedule: Branch creation - "on the first day of the month" in timezone Europe/Berlin, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.