Skip to content

chore(deps): bump github.com/aquasecurity/trivy from 0.61.0 to 0.62.1 in the trivy group #2221

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Merged
merged 1 commit into from
May 29, 2025

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github May 27, 2025

Bumps the trivy group with 1 update: github.com/aquasecurity/trivy.

Updates github.com/aquasecurity/trivy from 0.61.0 to 0.62.1

Release notes

Sourced from github.com/aquasecurity/trivy's releases.

v0.62.1

Changelog

  • c75ed2156c8fa801d6998016f46f6b953e8a9556 release: v0.62.1 [release/v0.62] (#8825)
  • aafebeb53aecbc9ed1ea44f8601183b4c25c49e3 chore(deps): bump the common group across 1 directory with 10 updates [backport: release/v0.62] (#8831)
  • 99485cfea2de53570342901eac860afdaacce86f fix(misconf): check if for-each is known when expanding dyn block [backport: release/v0.62] (#8826)
  • b4fc9e8ca1ff77a2795ffa47d0fc53cecd0e1bbd fix(redhat): trim invalid suffix from content_sets in manifest parsing [backport: release/v0.62] (#8824)

v0.62.0

⚡Release highlights and summary⚡

👉 aquasecurity/trivy#8801

Changelog

https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md#0620-2025-04-30

v0.61.1

Changelog

  • 7d3b4ffdd6b22ae80215f3a04421606b1f78de6a release: v0.61.1 [release/v0.61] (#8704)
  • 80d120fa0f96695e09eb97f43fb7413e5c773e50 fix(k8s): skip passed misconfigs for the summary report [backport: release/v0.61] (#8748)
  • 9d6290b31977b1bd4ab47349cd26498bc3b079c3 fix(k8s): correct compare artifact versions [backport: release/v0.61] (#8699)
  • 3799ebbb5a9bc78041492d1f191fb94ce1aa389b test: use aquasecurity repository for test images [backport: release/v0.61] (#8698)
Changelog

Sourced from github.com/aquasecurity/trivy's changelog.

0.62.1 (2025-05-06)

Bug Fixes

  • misconf: check if for-each is known when expanding dyn block [backport: release/v0.62] (#8826) (99485cf)
  • redhat: trim invalid suffix from content_sets in manifest parsing [backport: release/v0.62] (#8824) (b4fc9e8)

0.62.0 (2025-04-30)

Features

  • image: save layers metadata into report (#8394) (a95cab0)
  • misconf: add option to pass Rego scanner to IaC scanner (#8369) (890a360)
  • misconf: convert AWS managed policy to document (#8757) (7abf5f0)
  • misconf: support auto_provisioning_defaults in google_container_cluster (#8705) (9792611)
  • nodejs: add root and workspace for yarn packages (#8535) (bf4cd4f)
  • rust: add root and workspace relationships/package for cargo lock files (#8676) (93efe07)

Bug Fixes

  • early-return, indent-error-flow and superfluous-else rules from revive (#8796) (43350dd)
  • k8s: correct compare artifact versions (#8682) (cc47711)
  • k8s: remove using last-applied-configuration (#8791) (7a58ccb)
  • k8s: skip passed misconfigs for the summary report (#8684) (bff0e9b)
  • misconf: add missing variable as unknown (#8683) (9dcd06f)
  • misconf: check if metadata is not nil (#8647) (b7dfd64)
  • misconf: filter null nodes when parsing json manifest (#8785) (e10929a)
  • misconf: perform operations on attribute safely (#8774) (3ce7d59)
  • misconf: populate context correctly for module instances (#8656) (efd177b)
  • report: clean buffer after flushing (#8725) (9a5383e)
  • secret: ignore .dist-info directories during secret scanning (#8646) (a032ad6)
  • server: fix redis key when trying to delete blob (#8649) (36f8d0f)
  • terraform: evaluateStep to correctly set EvalContext for multiple instances of blocks (#8555) (e25de25)
  • terraform: hcl object expressions to return references (#8271) (0d3efa5)
  • testifylint last issues (#8768) (ee4f7dc)
  • unused-parameter rule from revive (#8794) (6562082)
Commits
  • c75ed21 release: v0.62.1 [release/v0.62] (#8825)
  • aafebeb chore(deps): bump the common group across 1 directory with 10 updates [backpo...
  • 99485cf fix(misconf): check if for-each is known when expanding dyn block [backport: ...
  • b4fc9e8 fix(redhat): trim invalid suffix from content_sets in manifest parsing [backp...
  • 6e6af01 release: v0.62.0 [main] (#8669)
  • bf4cd4f feat(nodejs): add root and workspace for yarn packages (#8535)
  • 6562082 fix: unused-parameter rule from revive (#8794)
  • 573f35c chore(deps): Update trivy-checks (#8798)
  • 43350dd fix: early-return, indent-error-flow and superfluous-else rules from revive ...
  • 7a58ccb fix(k8s): remove using last-applied-configuration (#8791)
  • Additional commits viewable in compare view

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
github.com/aquasecurity/trivy [>= 0.50.2.a, < 0.50.3]
github.com/aquasecurity/trivy [< 0.51, > 0.50.1]

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels May 27, 2025
@dependabot dependabot bot requested a review from shino May 27, 2025 05:55
Bumps the trivy group with 1 update: [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy).


Updates `github.com/aquasecurity/trivy` from 0.61.0 to 0.62.1
- [Release notes](https://github.com/aquasecurity/trivy/releases)
- [Changelog](https://github.com/aquasecurity/trivy/blob/v0.62.1/CHANGELOG.md)
- [Commits](aquasecurity/trivy@v0.61.0...v0.62.1)

---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
  dependency-version: 0.62.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: trivy
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/master/trivy-7180abae0d branch from fc7e052 to f63202d Compare May 28, 2025 05:13
@shino shino self-assigned this May 29, 2025
@shino shino merged commit e58a0e8 into master May 29, 2025
7 checks passed
@shino shino deleted the dependabot/go_modules/master/trivy-7180abae0d branch May 29, 2025 02:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
dependencies Pull requests that update a dependency file go Pull requests that update Go code
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant