Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

chore: bump github.com/aquasecurity/trivy from 0.32.1 to 0.43.1 #201

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jul 7, 2023

⚠️ Dependabot is rebasing this PR ⚠️

Rebasing might not happen immediately, so don't worry if this takes some time.

Note: if you make any changes to this PR yourself, they will take precedence over the rebase.


Bumps github.com/aquasecurity/trivy from 0.32.1 to 0.43.1.

Release notes

Sourced from github.com/aquasecurity/trivy's releases.

v0.43.1

Changelog

  • 5d76abadc chore(deps): Update defsec to v0.90.3 (#4793)
  • fed446c51 chore(deps): bump google.golang.org/protobuf from 1.30.0 to 1.31.0 (#4752)
  • df62927e5 chore(deps): bump alpine from 3.18.0 to 3.18.2 (#4748)
  • 1b9b9a84f chore(deps): bump github.com/alicebob/miniredis/v2 from 2.30.3 to 2.30.4 (#4758)
  • 3c16ca821 docs(image): fix the comment on the soft/hard link (#4740)
  • e5bee5ccc check Type when filling pkgs in vulns (#4776)
  • 4b9f310b9 feat: add support of linux/ppc64le and linux/s390x architectures for Install.sh script (#4770)
  • 8e7fb7cc8 chore(deps): bump modernc.org/sqlite from 1.20.3 to 1.23.1 (#4756)
  • a9badeaba fix(rocky): add architectures support for advisories (#4691)
  • f8ebccc68 chore(deps): bump github.com/opencontainers/image-spec (#4751)
  • 1c81948e0 chore(deps): bump github.com/package-url/packageurl-go (#4754)
  • 497cc10d8 chore(deps): bump golang.org/x/sync from 0.2.0 to 0.3.0 (#4750)
  • 065f0afa5 chore(deps): bump github.com/tetratelabs/wazero from 1.2.0 to 1.2.1 (#4755)
  • e2603056d chore(deps): bump github.com/testcontainers/testcontainers-go (#4759)
  • 0621402bf fix: documentation about reseting trivy image (#4733)
  • 798fdbc01 fix(suse): Add openSUSE Leap 15.5 eol date as well (#4744)
  • 34a89293d fix: update Amazon Linux 1 EOL (#4761)

v0.43.0

⚡Release highlights and summary⚡

👉 aquasecurity/trivy#4741

Changelog

  • 600819248 chore(deps): Update defsec to v0.90.1 (#4739)
  • 73734eab2 feat(nodejs): support yarn workspaces (#4664)
  • 22463abab feat(cli): add include-dev-deps flag (#4700)
  • 790c8054e fix(image): pass the secret scanner option to scan the img config (#4735)
  • 86fec9c4a fix: scan job pod it not found on k8s-1.27.x (#4729)
  • 26bc91160 feat(docker): add support for mTLS authentication when connecting to registry (#4649)
  • d699e8c10 chore(deps): Update defsec to v0.90.0 (#4723)
  • 1777878e8 fix: skip scanning the gpg-pubkey package (#4720)
  • 9be08253a Fix http registry oci pull (#4701)
  • 5d73b47db feat(misconf): Support skipping services (#4686)
  • 46e784c8a docs: fix supported modes for pubspec.lock files (#4713)
  • 0f61a8471 fix(misconf): disable the terraform plan analyzer for other scanners (#4714)
  • 8a1aa448a clarifying a dir path is required for custom policies (#4716)
  • fbab9eea3 chore: update alpine base images (#4715)
  • f84417bba fix last-history-created (#4697)
  • 85c681d44 feat: kbom and cyclonedx v1.5 spec support (#4708)
  • 46748ce6e docs: add information about Aqua (#4590)
  • c6741bddf fix: k8s escape resource filename on windows os (#4693)
  • a21acc7e0 ci: ignore merge queue branches (#4696)
  • 32a3a3311 chore(deps): bump actions/checkout from 2.4.0 to 3.5.3 (#4695)
  • cbb47dc7c chore(deps): bump aquaproj/aqua-installer from 2.1.1 to 2.1.2 (#4694)
  • e3d10d251 feat: cyclondx sbom custom property support (#4688)
  • e1770e046 ci: do not trigger tests in main (#4692)
  • 337c0b70d add SUSE Linux Enterprise Server 15 SP5 and update SP4 eol date (#4690)

... (truncated)

Commits
  • 5d76aba chore(deps): Update defsec to v0.90.3 (#4793)
  • fed446c chore(deps): bump google.golang.org/protobuf from 1.30.0 to 1.31.0 (#4752)
  • df62927 chore(deps): bump alpine from 3.18.0 to 3.18.2 (#4748)
  • 1b9b9a8 chore(deps): bump github.com/alicebob/miniredis/v2 from 2.30.3 to 2.30.4 (#4758)
  • 3c16ca8 docs(image): fix the comment on the soft/hard link (#4740)
  • e5bee5c check Type when filling pkgs in vulns (#4776)
  • 4b9f310 feat: add support of linux/ppc64le and linux/s390x architectures for Install....
  • 8e7fb7c chore(deps): bump modernc.org/sqlite from 1.20.3 to 1.23.1 (#4756)
  • a9badea fix(rocky): add architectures support for advisories (#4691)
  • f8ebccc chore(deps): bump github.com/opencontainers/image-spec (#4751)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot added dependencies Pull requests that update a dependency file go labels Jul 7, 2023
@codecov
Copy link

codecov bot commented Jul 7, 2023

Codecov Report

Patch and project coverage have no change.

Comparison is base (fda1668) 34.72% compared to head (819d029) 34.72%.
Report is 8 commits behind head on main.

Additional details and impacted files
@@           Coverage Diff           @@
##             main     #201   +/-   ##
=======================================
  Coverage   34.72%   34.72%           
=======================================
  Files          12       12           
  Lines        1146     1146           
=======================================
  Hits          398      398           
  Misses        727      727           
  Partials       21       21           

☔ View full report in Codecov by Sentry.
📢 Have feedback on the report? Share it here.

@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/aquasecurity/trivy-0.43.1 branch 5 times, most recently from 7bb382d to 83b4db9 Compare July 24, 2023 21:25
Copy link
Member

@sozercan sozercan left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

/hold, this is broken until spdx fix

Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy) from 0.32.1 to 0.43.1.
- [Release notes](https://github.com/aquasecurity/trivy/releases)
- [Changelog](https://github.com/aquasecurity/trivy/blob/main/goreleaser.yml)
- [Commits](aquasecurity/trivy@v0.32.1...v0.43.1)

---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/aquasecurity/trivy-0.43.1 branch from 83b4db9 to 819d029 Compare July 26, 2023 00:05
@sozercan
Copy link
Member

updated in #221

@sozercan sozercan closed this Jul 26, 2023
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Jul 26, 2023

OK, I won't notify you again about this release, but will get in touch when a new version is available. If you'd rather skip all updates until the next major or minor version, let me know by commenting @dependabot ignore this major version or @dependabot ignore this minor version. You can also ignore all major, minor, or patch releases for a dependency by adding an ignore condition with the desired update_types to your config file.

If you change your mind, just re-open this PR and I'll resolve any conflicts on it.

@dependabot dependabot bot deleted the dependabot/go_modules/github.com/aquasecurity/trivy-0.43.1 branch July 26, 2023 18:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant