Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Sep 23, 2024

Bumps github.com/aquasecurity/trivy from 0.55.1 to 0.55.2.

Release notes

Sourced from github.com/aquasecurity/trivy's releases.

v0.55.2

Changelog

  • 928c7c0f1a5c9432a2ba2daa5268dae53dc8eb7b release: v0.55.2 [release/v0.55] (#7523)
  • 14a058f608be403a53019775c8308f4f5718afd7 fix(java): use dependencyManagement from root/child pom's for dependencies from parents [backport: release/v0.55] (#7521)
  • 990bc4e8287889a18ebb59332b40db3e4586fed4 chore(deps): bump alpine from 3.20.0 to 3.20.3 [backport: release/v0.55] (#7516)
Changelog

Sourced from github.com/aquasecurity/trivy's changelog.

0.55.2 (2024-09-17)

Bug Fixes

  • java: use dependencyManagement from root/child pom's for dependencies from parents [backport: release/v0.55] (#7521) (14a058f)
Commits
  • 928c7c0 release: v0.55.2 [release/v0.55] (#7523)
  • 14a058f fix(java): use dependencyManagement from root/child pom's for dependencies ...
  • 990bc4e chore(deps): bump alpine from 3.20.0 to 3.20.3 [backport: release/v0.55] (#7516)
  • See full diff in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

@dependabot dependabot bot requested a review from jeremyrickard as a code owner September 23, 2024 12:15
@dependabot dependabot bot added the dependencies Pull requests that update a dependency file label Sep 23, 2024
@dependabot dependabot bot requested a review from sozercan as a code owner September 23, 2024 12:15
@dependabot dependabot bot added the go Pull requests that update Go code label Sep 23, 2024
@dependabot dependabot bot requested a review from ashnamehrotra as a code owner September 23, 2024 12:15
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/aquasecurity/trivy-0.55.2 branch 2 times, most recently from ac715b1 to 6240201 Compare September 30, 2024 21:16
@ashnamehrotra
Copy link
Contributor

@dependabot rebase

@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/aquasecurity/trivy-0.55.2 branch from 6240201 to cfd7bc9 Compare September 30, 2024 21:49
@ashnamehrotra
Copy link
Contributor

@dependabot rebase

Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy) from 0.55.1 to 0.55.2.
- [Release notes](https://github.com/aquasecurity/trivy/releases)
- [Changelog](https://github.com/aquasecurity/trivy/blob/v0.55.2/CHANGELOG.md)
- [Commits](aquasecurity/trivy@v0.55.1...v0.55.2)

---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/github.com/aquasecurity/trivy-0.55.2 branch from cfd7bc9 to d9147ad Compare September 30, 2024 22:43
@ashnamehrotra ashnamehrotra merged commit 1b18be6 into main Sep 30, 2024
20 checks passed
@ashnamehrotra ashnamehrotra deleted the dependabot/go_modules/github.com/aquasecurity/trivy-0.55.2 branch September 30, 2024 23:21
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

Status: Done

Development

Successfully merging this pull request may close these issues.

2 participants