Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

trivy 0.53.0 #176068

Merged
merged 2 commits into from
Jul 1, 2024
Merged

trivy 0.53.0 #176068

merged 2 commits into from
Jul 1, 2024

Conversation

BrewTestBot
Copy link
Member

Created by brew bump


Created with brew bump-formula-pr.

release notes
## Changelog
* c55b0e6ca release: v0.53.0 [main] (#6855)
* 654217a65 feat(conda): add licenses support for `environment.yml` files (#6953)
* 3d4ae8b5b fix(sbom): fix panic when scanning SBOM file without root component into SBOM format (#7051)
* 55ccd06df feat: add memory cache backend (#7048)
* 14d71ba63 fix(sbom): use package UIDs for uniqueness (#7042)
* edc556b85 feat(php): add installed.json file support (#4865)
* 4f8b3996e docs: ✨ Updated ecosystem docs with reference to new community app (#7041)
* 137c91642 fix: use embedded when command path not found (#7037)
* 9e4927ee1 chore(deps): bump trivy-kubernetes version (#7012)
* 4be02bab8 refactor: use google/wire for cache (#7024)
* e9fc3e339 fix(cli): show info message only when --scanners is available (#7032)
* 0ccdbfbb6 chore: enable float-compare rule from testifylint (#6967)
* 9045f2445 docs: Add sudo on commands, chmod before mv on install docs (#7009)
* 3d02a31b4 fix(plugin): respect `--insecure` (#7022)
* 8d618e48a feat(k8s)!: node-collector dynamic commands support (#6861)
* a76e3286c fix(sbom): take pkg name from `purl` for maven pkgs (#7008)
* eb636c1b3 chore(deps): bump github.com/hashicorp/go-getter from 1.7.4 to 1.7.5 (#7018)
* 8d0ae1f5d feat!: add clean subcommand (#6993)
* de201dc77 chore: use `!` for breaking changes (#6994)
* 979e118a9 feat(aws)!: Remove aws subcommand (#6995)
* 648ead955 refactor: replace global cache directory with parameter passing (#6986)
* 7eabb92ec fix(sbom): use `purl` for `bitnami` pkg names (#6982)
* 333087c9e chore: bump Go toolchain version (#6984)
* 6dff4223e refactor: unify cache implementations (#6977)
* 9dc8a2ba6 docs: non-packaged and sbom clarifications (#6975)
* b58d42dc9 BREAKING(aws): Deprecate `trivy aws` as subcmd in favour of a plugin (#6819)
* 6469d37cc docs: delete unknown URL (#6972)
* 30bcb9535 refactor: use version-specific URLs for documentation references (#6966)
* e493fc931 refactor: delete db mock (#6940)
* 983ac15f2 ci: add depguard (#6963)
* dfe757e37 refactor: add warning if severity not from vendor (or NVD or GH) is used (#6726)
* f144e912d feat: Add local ImageID to SARIF metadata (#6522)
* 5ee4e9d30 fix(suse): Add SLES 15.6 and Leap 15.6 (#6964)
* f18d035ae feat(java): add support for sbt projects using sbt-dependency-lock (#6882)
* 1f8fca1fc feat(java): add support for `maven-metadata.xml` files for remote snapshot repositories. (#6950)
* 2d85a003b fix(purl): add missed os types (#6955)
* 417212e09 fix(cyclonedx): trim non-URL info for `advisory.url` (#6952)
* 38b35dd3c fix(c): don't skip conan files from `file-patterns` and scan `.conan2` cache dir (#6949)
* eb6d0d977 ci: correctly handle categories (#6943)
* 0af5730cb fix(image): parse `image.inspect.Created` field only for non-empty values (#6948)
* c3192f061 fix(misconf): handle source prefix to ignore (#6945)
* ec68c9ab4 fix(misconf): fix parsing of engine links and frameworks (#6937)
* bc3741ae2 feat(misconf): support of selectors for all providers for Rego (#6905)
* 735aadf2d ci: don't run `tests` for `release-please` PRs (#6936)
* 52f7aa54b fix(license): return license separation using separators  `,`, `or`, etc. (#6916)
* d77d9ce38 ci: use `ubuntu-latest-m` runner (#6918)
* 55fa6109c feat(misconf): add support for AWS::EC2::SecurityGroupIngress/Egress (#6755)
* cd360dde2 BREAKING(misconf): flatten recursive types (#6862)
* 08a428a08 ci: move triage workflow yaml under .github/workflows (#6895)
* 04ed5edba ci: add `trivy` group for `dependabot` (#6908)
* fdf799e6a chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azidentity from 1.5.2 to 1.6.0 (#6910)
* baa121689 test: bump docker API to 1.45  (#6914)
* 09e50ce6a feat(sbom): migrate to `CycloneDX v1.6` (#6903)
* 6e7f62d2d chore(deps): bump the aws group with 8 updates (#6898)
* 1bdc135fe ci: bump `github.com/goreleaser/goreleaser` to `v2.0.0` (#6887)
* 9b3169727 feat(image): Set User-Agent header for Trivy container registry requests (#6868)
* 089b95346 fix(debian): take installed files from the origin layer (#6849)
* cf5aa336e fix(nodejs): fix infinite loop when package link from `package-lock.json` file is broken (#6858)
* 8491469f0 feat(misconf): API Gateway V1 support for CloudFormation (#6874)
* bb8893736 ci: add created release branch to `rulesets` to enable merge queue (#6880)
* 622c67b76 feat(plugin): add support for nested archives (#6845)
* 04af59c29 fix(sbom): don't overwrite `srcEpoch` when decoding SBOM files (#6866)
* bb26445e3 fix(secret): `Asymmetric Private Key` shouldn't start with space (#6867)
* 72e20d765 ci: use author permission check instead of `author_association` field for backport workflow (#6870)
* e8d8af450 chore: auto label discussions (#5259)
* 63eb85a06 docs: explain how VEX is applied (#6864)
* 1e2db83e4 ci: automate backporting process (#6781)
* d4aea2788 ci: create release branch (#6859)
* faa9d92cf fix(python): compare pkg names from `poetry.lock` and `pyproject.toml` in lowercase (#6852)
* 7d083bc89 fix(nodejs): fix infinity loops for `pnpm` with cyclic imports (#6857)
* 042d6b08c feat(dart): use first version of constraint for dependencies using SDK version (#6239)
* 8141a137b fix(misconf): parsing numbers without fraction as int (#6834)
* 0bcfedbca fix(misconf): fix caching of modules in subdirectories (#6814)
* 02d540478 feat(misconf): add metadata to Cloud schema (#6831)
* 8dd076a76 chore(deps): bump the aws group across 1 directory with 7 updates (#6837)
* bab16b88a chore(deps): bump the common group with 5 updates (#6842)
* b7b8cdc9e test: replace embedded Git repository with dynamically created repository (#6824)

@github-actions github-actions bot added go Go use is a significant feature of the PR or issue bump-formula-pr PR was created using `brew bump-formula-pr` labels Jul 1, 2024
@chenrui333
Copy link
Member

    Minitest::Assertion: Expected /0\.53\.0/ to match "Version: dev\nVulnerability DB:\n  Version: 2\n  UpdatedAt: 2024-07-01 12:12:32.062374929 +0000 UTC\n  NextUpdate: 2024-07-01 18:12:32.062374518 +0000 UTC\n  DownloadedAt: 2024-07-01 13:01:35.358307 +0000 UTC\n".

trivy: update build

Signed-off-by: Rui Chen <[email protected]>
@chenrui333 chenrui333 added the ready to merge PR can be merged once CI is green label Jul 1, 2024
Copy link
Contributor

github-actions bot commented Jul 1, 2024

🤖 An automated task has requested bottles to be published to this PR.

@github-actions github-actions bot added the CI-published-bottle-commits The commits for the built bottles have been pushed to the PR branch. label Jul 1, 2024
@BrewTestBot BrewTestBot added this pull request to the merge queue Jul 1, 2024
Merged via the queue into master with commit dd5e37b Jul 1, 2024
14 checks passed
@BrewTestBot BrewTestBot deleted the bump-trivy-0.53.0 branch July 1, 2024 14:58
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
bump-formula-pr PR was created using `brew bump-formula-pr` CI-published-bottle-commits The commits for the built bottles have been pushed to the PR branch. go Go use is a significant feature of the PR or issue ready to merge PR can be merged once CI is green
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

3 participants