Описание
Security update for trivy
This update for trivy fixes the following issues:
Update to version 0.68.2:
Security fixes:
- CVE-2024-3817: hashicorp/go-getter: argument injection when fetching remote default git branches (bsc#1227010).
- CVE-2024-45337: golang.org/x/crypto/ssh: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass in golang.org/x/crypto (bsc#1234512).
- CVE-2024-45338: golang.org/x/net/html: denial of service due to non-linear parsing of case-insensitive content (bsc#1235265).
- CVE-2024-51744: github.com/golang-jwt/jwt/v4: Bad documentation of error handling in ParseWithClaims can lead to potentially dangerous situations in golang-jwt (bsc#1232948).
- CVE-2025-11065: github.com/go-viper/mapstructure/v2: sensitive Information leak in logs (bsc#1250625).
- CVE-2025-22868: golang.org/x/oauth2/jws: Unexpected memory consumption during token parsing in golang.org/x/oauth2 (bsc#1239225).
- CVE-2025-22869: golang.org/x/crypto/ssh: Denial of Service in the Key Exchange of golang.org/x/crypto/ssh (bsc#1239385).
- CVE-2025-22872: golang.org/x/net/html: incorrectly interpreted tags can cause content to be placed wrong scope during DOM construction (bsc#1241724).
- CVE-2025-27144: gopkg.in/go-jose/go-jose.v2: Go JOSE's Parsing Vulnerable to Denial of Service (bsc#1237618).
- CVE-2025-30204: github.com/golang-jwt/jwt/v4,github.com/golang-jwt/jwt/v5: jwt-go allows excessive memory allocation during header parsing (bsc#1240466).
- CVE-2025-46569: github.com/open-policy-agent/opa: HTTP request path can be crafted to inject Rego code into a constructed query when a virtual document is requested through the Data API (bsc#1246730).
- CVE-2025-47291: github.com/containerd/containerd/v2: Incorrect cgroup hierarchy assignment for containers running in usernamespaced Kubernetes pods. (bsc#1243633).
- CVE-2025-47911: golang.org/x/net/html: various algorithms with quadratic complexity when parsing HTML documents (bsc#1251363).
- CVE-2025-47913: golang.org/x/crypto/ssh/agent: client process termination when receiving an unexpected message type in response to a key listing or signing request (bsc#1253512).
- CVE-2025-47914: golang.org/x/crypto/ssh/agent: non validated message size can cause a panic due to an out of bounds read (bsc#1253977).
- CVE-2025-53547: helm.sh/helm/v3: Helm Chart Code Execution (bsc#1246151).
- CVE-2025-58058: github.com/ulikunitz/xz: github.com/ulikunitz/xz leaks memory (bsc#1248937, bsc#1248897).
- CVE-2025-58181: golang.org/x/crypto/ssh: invalidated number of mechanisms can cause unbounded memory consumption (bsc#1253786).
- CVE-2025-58190: golang.org/x/net/html: excessive memory consumption by
html.ParseFragmentwhen processing specially crafted input (bsc#1251547).
Other fixes:
- Update installation.md (#8979)
- chore(alpine): add EOL date for Alpine 3.21 (#8221)
- chore(alpine): add EOL date for Alpine 3.22 (#8992)
- chore(cli): Remove Trivy Cloud (#9847)
- chore(deps): Bump trivy-checks (#7819)
- chore(deps): Bump trivy-checks (#8310)
- chore(deps): Bump trivy-checks (#8619)
- chore(deps): Bump trivy-checks (#8934)
- chore(deps): Bump trivy-checks to v1.7.1 (#8467)
- chore(deps): Bump up trivy-checks to v1.3.0 (#7959)
- chore(deps): Switch to go-viper/mapstructure (#9579)
- chore(deps): Update trivy-checks (#8798)
- chore(deps): Upgrade trivy-checks (#8018)
- chore(deps): bump Go to
v1.23.5(#8341) - chore(deps): bump Go to
v1.23.5[backport: release/v0.59] (#8343) - chore(deps): bump
github.com/CycloneDX/cyclonedx-gofromv0.9.1tov0.9.2(#8105) - chore(deps): bump
github.com/CycloneDX/cyclonedx-gofromv0.9.1tov0.9.2[backport: release/v0.58] (#8136) - chore(deps): bump
golang.org/x/netfromv0.32.0tov0.33.0(#8140) - chore(deps): bump
golang.org/x/netfromv0.32.0tov0.33.0[backport: release/v0.58] (#8142) - chore(deps): bump alpine from 3.20.0 to 3.21.0 in the docker group across 1 directory (#8196)
- chore(deps): bump alpine from 3.21.0 to 3.21.3 in the docker group across 1 directory (#8490)
- chore(deps): bump alpine from 3.21.4 to 3.22.1 (#9301)
- chore(deps): bump github.com/containerd/containerd from 1.7.28 to 1.7.29 (#9764)
- chore(deps): bump github.com/containerd/containerd/v2 from 2.1.0 to 2.1.1 (#8901)
- chore(deps): bump github.com/containerd/containerd/v2 from 2.1.4 to 2.1.5 (#9763)
- chore(deps): bump github.com/docker/docker from 28.3.2+incompatible to 28.3.3+incompatible (#9274)
- chore(deps): bump github.com/go-jose/go-jose/v4 from 4.0.4 to 4.0.5 (#8443)
- chore(deps): bump github.com/go-viper/mapstructure/v2 from 2.2.1 to 2.3.0 (#9088)
- chore(deps): bump github.com/golang-jwt/jwt/v4 from 4.5.0 to 4.5.1 (#7868)
- chore(deps): bump github.com/golang-jwt/jwt/v4 from 4.5.1 to 4.5.2 (#8597)
- chore(deps): bump github.com/moby/buildkit from 0.17.0 to 0.17.2 in the docker group across 1 directory (#7990)
- chore(deps): bump github.com/moby/buildkit from 0.17.2 to 0.18.0 in the docker group (#8029)
- chore(deps): bump github.com/opencontainers/selinux from 1.12.0 to 1.13.0 (#9778)
- chore(deps): bump github.com/quic-go/quic-go from 0.52.0 to 0.54.1 (#9694)
- chore(deps): bump github.com/ulikunitz/xz from 0.5.12 to 0.5.14 (#9403)
- chore(deps): bump golang.org/x/crypto from 0.30.0 to 0.31.0 (#8103)
- chore(deps): bump golang.org/x/crypto from 0.30.0 to 0.31.0 [backport: release/v0.58] (#8122)
- chore(deps): bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#9827)
- chore(deps): bump golang.org/x/sync from 0.13.0 to 0.14.0 in the common group (#8822)
- chore(deps): bump golangci-lint to v2.1.2 (#8766)
- chore(deps): bump helm.sh/helm/v3 from 3.18.3 to 3.18.4 (#9164)
- chore(deps): bump the aws group across 1 directory with 5 updates (#8652)
- chore(deps): bump the aws group across 1 directory with 6 updates (#8074)
- chore(deps): bump the aws group across 1 directory with 6 updates (#8163)
- chore(deps): bump the aws group across 1 directory with 7 updates (#7991)
- chore(deps): bump the aws group across 1 directory with 7 updates (#8468)
- chore(deps): bump the aws group with 6 updates (#7902)
- chore(deps): bump the aws group with 6 updates (#9383)
- chore(deps): bump the aws group with 6 updates (#9481)
- chore(deps): bump the aws group with 6 updates (#9547)
- chore(deps): bump the aws group with 7 updates (#8299)
- chore(deps): bump the aws group with 7 updates (#9311)
- chore(deps): bump the aws group with 7 updates (#9419)
- chore(deps): bump the aws group with 7 updates (#9691)
- chore(deps): bump the common group across 1 directory with 10 updates (#8566)
- chore(deps): bump the common group across 1 directory with 10 updates (#8817)
- chore(deps): bump the common group across 1 directory with 10 updates [backport: release/v0.62] (#8831)
- chore(deps): bump the common group across 1 directory with 11 updates (#8381)
- chore(deps): bump the common group across 1 directory with 13 updates (#8491)
- chore(deps): bump the common group across 1 directory with 14 updates (#8126)
- chore(deps): bump the common group across 1 directory with 20 updates (#7876)
- chore(deps): bump the common group across 1 directory with 20 updates (#9840)
- chore(deps): bump the common group across 1 directory with 23 updates (#8733)
- chore(deps): bump the common group across 1 directory with 24 updates (#9228)
- chore(deps): bump the common group across 1 directory with 24 updates (#9507)
- chore(deps): bump the common group across 1 directory with 26 updates (#9063)
- chore(deps): bump the common group across 1 directory with 26 updates (#9347)
- chore(deps): bump the common group across 1 directory with 29 updates (#8261)
- chore(deps): bump the common group across 1 directory with 7 updates (#9590)
- chore(deps): bump the common group across 1 directory with 9 updates (#8887)
- chore(deps): bump the common group across 1 directory with 9 updates (#9153)
- chore(deps): bump the common group with 12 updates (#8301)
- chore(deps): bump the common group with 4 updates (#7949)
- chore(deps): bump the common group with 6 updates (#7904)
- chore(deps): bump the common group with 6 updates (#8162)
- chore(deps): bump the common group with 6 updates (#8411)
- chore(deps): bump the common group with 7 updates (#9382)
- chore(deps): bump the docker group across 1 directory with 3 updates (#8127)
- chore(deps): bump the docker group across 1 directory with 3 updates (#8762)
- chore(deps): bump the docker group with 3 updates (#9545)
- chore(deps): bump the docker group with 3 updates (#9776)
- chore(deps): bump the github-actions group across 1 directory with 2 updates (#7854)
- chore(deps): bump the github-actions group across 1 directory with 2 updates (#8962)
- chore(deps): bump the github-actions group across 1 directory with 4 updates (#8331)
- chore(deps): bump the github-actions group across 1 directory with 9 updates (#9563)
- chore(deps): bump the github-actions group with 3 updates (#8473)
- chore(deps): bump the github-actions group with 4 updates (#9739)
- chore(deps): bump the testcontainers group with 2 updates (#8650)
- chore(deps): bump the testcontainers group with 2 updates (#9506)
- chore(deps): bump to alpine from
3.21.3to3.21.4(#9283) - chore(deps): bump up Trivy-kubernetes to v0.9.1 (#9214)
- chore(deps): remove missed replace of
trivy-db(#8492) - chore(deps): update Docker to v28.2.2 and fix compatibility issues (#9037)
- chore(deps): update Go to 1.24 and switch to go-version-file (#8388)
- chore(deps): update csaf module dependency from csaf-poc to gocsaf (#7992)
- chore(deps): update go-rustaudit location (#8450)
- chore(deps): update to module-compatible docker-credential-gcr/v2 (#9591)
- chore(deps): use aqua forks for
github.com/liamg/jfatherandgithub.com/liamg/iamgo(#8289) - chore(k8s): enhance k8s scan log (#6997)
- chore(k8s): update comments with deprecated command format (#8964)
- chore(license): add missed spdx exceptions: (#9147)
- chore(secret): add reported issues related to secrets in junit template (#8193)
- chore(terraform): add accessors to underlying raw hcl values (#8306)
- chore(terraform): assign *terraform.Module 'parent' field (#8444)
- chore(terraform): export module path on terraform modules (#8374)
- chore(terraform): option to pass in instanced logger (#8738)
- chore(terraform): remove os.OpenPath call from terraform file functions (#8737)
- chore(vex): suppress CVE-2024-45337 (#8101)
- chore(vex): suppress CVE-2024-45338 (#8137)
- chore: Update release flow to include chocolatey (#9460)
- chore: Update release workflow to trigger version updates (#9162)
- chore: add an issue template for maintainers (#8838)
- chore: add context to the cache interface (#9565)
- chore: add debug log to show image source location (#9163)
- chore: add modernize tool integration for code modernization (#9251)
- chore: bump Go to 1.24.7 (#9435)
- chore: bump
mockeryto update v2.52.2 version and rebuild mock files (#8390) - chore: bump containerd to v2.0.0 (#7875)
- chore: bump go to 1.23.4 (#8123)
- chore: bump golangci-lint to v1.61.0 (#7853)
- chore: bump up Go version to 1.24.4 (#9031)
- chore: downgrade the failed block expand message to debug (#7964)
- chore: drop FreeBSD 32-bit support (#9102)
- chore: enable int-conversion from perfsprint (#8194)
- chore: enable staticcheck (#8815)
- chore: fix errors and typos in docs (#8963)
- chore: fix some function names in comment (#9314)
- chore: implement process-safe temp file cleanup (#9241)
- chore: lint
errors.Join(#7845) - chore: migrate protoc setup from Docker to buf CLI (#9184)
- chore: remove Go checks (#7907)
- chore: remove aws iam related scripts (#8179)
- chore: remove debug prints (#8347)
- chore: remove mockery (#8417)
- chore: replace deprecated tenv linter with usetesting (#8504)
- chore: trigger the trivy-www workflow (#9737)
- chore: typo fix to replace
regowithrepoon the RepoFlagGroup options error output (#8643) - chore: update Docker lib (#8681)
- chore: update code owners (#8303)
- chore: update template URL for brew formula (#9221)
- chore: update the rpm download Update (#9202)
- chore: use go.mod for managing Go tools (#8493)
- chore: use require.ErrorContains when possible (#8291)
- ci(deps): add 3-day cooldown period for Dependabot updates (#9475)
- ci(helm): auto public Helm chart after PR merged (#7526)
- ci(helm): bump Trivy version to 0.57.1 for Trivy Helm Chart 0.9.0 (#7945)
- ci(helm): bump Trivy version to 0.58.0 for Trivy Helm Chart 0.10.0 (#8038)
- ci(helm): bump Trivy version to 0.58.1 for Trivy Helm Chart 0.10.0 (#8170)
- ci(helm): bump Trivy version to 0.59.0 for Trivy Helm Chart 0.11.0 (#8311)
- ci(helm): bump Trivy version to 0.59.1 for Trivy Helm Chart 0.11.1 (#8354)
- ci(helm): bump Trivy version to 0.60.0 for Trivy Helm Chart 0.12.0 (#8494)
- ci(helm): bump Trivy version to 0.61.0 for Trivy Helm Chart 0.13.0 (#8638)
- ci(helm): bump Trivy version to 0.61.1 for Trivy Helm Chart 0.13.1 (#8753)
- ci(helm): bump Trivy version to 0.62.0 for Trivy Helm Chart 0.14.0 (#8802)
- ci(helm): bump Trivy version to 0.62.1 for Trivy Helm Chart 0.14.1 (#8836)
- ci(helm): bump Trivy version to 0.63.0 for Trivy Helm Chart 0.15.0 (#8946)
- ci(helm): bump Trivy version to 0.64.0 for Trivy Helm Chart 0.16.0 (#9107)
- ci(helm): bump Trivy version to 0.64.1 for Trivy Helm Chart 0.16.1 (#9135)
- ci(helm): bump Trivy version to 0.65.0 for Trivy Helm Chart 0.17.0 (#9288)
- ci(helm): bump Trivy version to 0.66.0 for Trivy Helm Chart 0.18.0 (#9425)
- ci(helm): bump Trivy version to 0.67.0 for Trivy Helm Chart 0.19.0 (#9554)
- ci(helm): bump Trivy version to 0.67.2 for Trivy Helm Chart 0.19.1 (#9641)
- ci(helm): create a helm branch for patches from main (#8673)
- ci(spdx): add
aqua-installerstep to fixmageerror (#8353) - ci(vuln): reduce github action script injection attack risk (#8610)
- ci: add API diff workflow (#9600)
- ci: add auto-ready-for-review workflow (#9179)
- ci: add workflow to restrict direct PRs to release branches (#8240)
- ci: delete cache after artifacts upload in canary workflow (#9177)
- ci: enable
check-latestforsetup-go[backport: release/v0.68] (#9946) - ci: fix path to main dir for canary builds (#8231)
- ci: get base_sha using base.ref (#9704)
- ci: improve PR title validation workflow (#8720)
- ci: migrate GitHub Actions from version tags to SHA pinning (#9405)
- ci: move runner.os context from job-level env to step-level in canary workflow (#9233)
- ci: optimize golangci-lint performance with cache-based strategy (#9173)
- ci: remove invalid
--confirmflag fromgh cache deletecommand in canary builds (#9236) - ci: remove unused preinstalled software/images for build tests to free up disk space. (#9814)
- ci: skip undefined labels in discussion triage action (#9175)
- ci: specify repository for
gh cache deletein canary worklfow (#9240) - ci: update GitHub Actions cache to v4 (#8475)
- ci: use
Skitionek/notify-microsoft-teamsinstead ofaquasecurityfork (#8740) - ci: use
github.event.pull_request.user.loginfor release PR check workflow (#8702) - ci: use environment variables in GitHub Actions for improved security (#9433)
- ci: use gh pr view to get PR number for forked repositories in auto-ready workflow (#9183)
- ci: use merge commit for apidiff to avoid false positives (#9622)
- ci: use pull_request_target for apidiff workflow to support fork PRs (#9605)
- docs(cli): improve flag value display format (#8560)
- docs(java): Update info about dev deps in gradle lock (#8830)
- docs(java): add info about supported scopes (#7842)
- docs(k8s): add a note about multi-container pods (#7815)
- docs(misconf): Remove duplicate sections (#9819)
- docs(misconf): Reorganize misconfiguration scan pages (#8206)
- docs(misconf): simplify misconfiguration docs (#9030)
- docs(python): Mention pip-compile (#8484)
- docs(python): fix type with METADATA file name (#9090)
- docs(report): Improve SARIF reporting doc (#7655)
- docs(report): add nuanses about secret/license scanner in summary table (#9442)
- docs(report): fix reporting doc format (#7671)
- docs(server): fix info about scanning licenses on the client side. (#9805)
- docs(vex): use debian minor version in examples (#8166)
- docs(vuln): remove OSV for Python from data sources (#8841)
- docs: Add info about helm charts release (#8640)
- docs: Fix broken link to "Built-in Checks" (#9375)
- docs: Fix broken links (#7900)
- docs: Fix typo in terraform docs (#9492)
- docs: Fix typos and linguistic errors in documentation / hacktoberfest (#9586)
- docs: Fix typos in documentation (#8361)
- docs: Update maintainer docs (#8674)
- docs: Updated JSON schema version 2 in the trivy documentation (#8188)
- docs: add Headlamp to the Trivy Ecosystem page (#7916)
- docs: add PR review policy for maintainers (#9032)
- docs: add Windows install instructions (#7800)
- docs: add
overviewpage forothers(#7972) - docs: add abbreviation list (#8453)
- docs: add commercial content (#8030)
- docs: add example of creating whitelist of checks (#7821)
- docs: add explanation for how to use non-system certificates (#9081)
- docs: add info about
java-dbsubdir (#9706) - docs: add info that
SSL_CERT_FILEworks onUnix systems other than macOSonly (#9772) - docs: add note about disabled DS016 check (#7724)
- docs: add note about temporary podman socket (#7921)
- docs: add partners page (#8988)
- docs: add section on customizing default check data (#9114)
- docs: add terminology page to explain Trivy concepts (#7996)
- docs: add vulnerability database contribution guide (#9667)
- docs: apt-transport-https is a transitional package (#7678)
- docs: bump pygments from 2.18.0 to 2.19.2 (#9596)
- docs: catch some missed docs -> guide (#9850)
- docs: change --disable-metrics to --disable-telemetry in example (#8999) (#9003)
- docs: change SecObserve URLs in documentatio (#9771)
- docs: change in java.md: fix the Trity -to-> Trivy typo (#8813)
- docs: clarify inline ignore limitations for resource-less checks (#9537)
- docs: combine trivy.dev into trivy docs (#7884)
- docs: correct Ruby documentation (#8402)
- docs: document eol supportability (#9434)
- docs: drop AWS account scanning (#7997)
- docs: fix a broken link (#8546)
- docs: fix assets with versioning (#8996)
- docs: fix dead links (#7998)
- docs: fix mistakes/typos (#7942)
- docs: fix modules path and update code example (#9539)
- docs: fix navigate links (#8336)
- docs: improve databases documentation (#7732)
- docs: improve documentation for scanning raw IaC configurations (#9571)
- docs: improve skipping files documentation (#8749)
- docs: move info about
detection priorityinto coverage section (#9469) - docs: partners page content updates (#9149)
- docs: remove slack (#8565)
- docs: replace short codes with Unicode emojis (#8296)
- docs: restructure docs for new hosting (#9799)
- docs: trivy partners page updates (#9133)
- docs: update VEX documentation index page (#8458)
- docs: update links to Semaphore pages (#9352)
- docs: update vulnerability reporting guidelines in SECURITY.md (#9395)
- feat(alma): add AlmaLinux 10 support (#9207)
- feat(alpine): add maintainer field extraction for APK packages (#8930)
- feat(aws): Add support for dualstack ECR endpoints (#9862)
- feat(cli): Add available version checking (#8553)
- feat(cli): Add trivy cloud suppport (#9637)
- feat(cli): add
trivy auth(#7664) - feat(cli): add version constraints to annoucements (#9023)
- feat(cli): change --list-all-pkgs default to true (#9510)
- feat(cli): error out when ignore file cannot be found (#7624)
- feat(cli): rename
trivy authtotrivy registry(#7727) - feat(cloudformation): support default values and list results in Fn::FindInMap (#9515)
- feat(cyclonedx): Add initial support for loading external VEX files from SBOM references (#8254)
- feat(cyclonedx): add file checksums to
CycloneDXreports (#7507) - feat(cyclonedx): preserve SBOM structure when scanning SBOM files with vulnerability updates (#9439)
- feat(db): append errors (#7843)
- feat(db): enable concurrent access to vulnerability database (#9750)
- feat(dotnet): add dependency graph support for .deps.json files (#9726)
- feat(echo): Add Echo Support (#8833)
- feat(flag): add
--cacertflag (#9781) - feat(flag): add schema validation for
--serverflag (#9270) - feat(fs): change artifact type to repository when git info is detected (#9613)
- feat(fs): optimize scanning performance by direct file access for known paths (#8525)
- feat(fs): use git commit hash as cache key for clean repositories (#8278)
- feat(go): construct dependencies in the parser (#7973)
- feat(go): construct dependencies of
go.modmain module in the parser (#7977) - feat(go): fix parsing main module version for go >= 1.24 (#8433)
- feat(go): support license scanning in both GOPATH and vendor (#8843)
- feat(image): add Docker context resolution (#9166)
- feat(image): add RepoTags support for Docker archives (#9690)
- feat(image): add Sigstore bundle SBOM support (#9516)
- feat(image): pass global context to docker/podman image save func (#9733)
- feat(image): prevent scanning oversized container images (#8178)
- feat(image): return error early if total size of layers exceeds limit (#8294)
- feat(image): save layers metadata into report (#8394)
- feat(java): add support remote repositories from settings.xml files (#9708)
- feat(java): dereference all maven settings.xml env placeholders (#9024)
- feat(k8s): add default commands for unknown platform (#7863)
- feat(k8s): add support for controllers (#8614)
- feat(k8s): get components from namespaced resources (#8918)
- feat(k8s): improve artifact selections for specific namespaces (#8248)
- feat(license): Support compound licenses (licenses using SPDX operators) (#8816)
- feat(license): improve work text licenses with custom classification (#8888)
- feat(license): improve work with custom classification of licenses from config file (#8861)
- feat(license): observe pkg types option in license scanner (#9091)
- feat(license): scan vendor directory for license for go.mod files (#8689)
- feat(license): use separate SPDX ids to ignore SPDX expressions (#9087)
- feat(minimos): Add support for MinimOS (#8792)
- feat(misconf): Add RoleAssignments attribute (#9396)
- feat(misconf): Add support for
Minimum Trivy Version(#8880) - feat(misconf): Add support for aws_ami (#8499)
- feat(misconf): Add support for configurable Rego error limit (#9657)
- feat(misconf): Show misconfig ID in output (#7762)
- feat(misconf): Update AppService schema (#9792)
- feat(misconf): Update Azure Compute schema (#9675)
- feat(misconf): Update Azure Container Schema (#9673)
- feat(misconf): Update Azure network schema for new checks (#9791)
- feat(misconf): Update SecurityCenter schema (#9674)
- feat(misconf): Update azure storage schema (#9728)
- feat(misconf): adapt AWS::DynamoDB::Table (#8529)
- feat(misconf): adapt AWS::EC2::VPC (#8534)
- feat(misconf): adapt aws_default_security_group (#8538)
- feat(misconf): adapt aws_opensearch_domain (#8550)
- feat(misconf): add OpenTofu file extension support (#8747)
- feat(misconf): add agentpools to azure container schema (#9714)
- feat(misconf): add misconfiguration location to junit template (#8793)
- feat(misconf): add option to pass Rego scanner to IaC scanner (#8369)
- feat(misconf): add private ip google access attribute to subnetwork (#9199)
- feat(misconf): added audit config attribute (#9249)
- feat(misconf): added logging and versioning to the gcp storage bucket (#9226)
- feat(misconf): convert AWS managed policy to document (#8757)
- feat(misconf): export raw Terraform data to Rego (#8741)
- feat(misconf): export unresolvable field of IaC types to Rego (#7765)
- feat(misconf): generate placeholders for random provider resources (#8051)
- feat(misconf): include map key in manifest snippet for diagnostics (#9681)
- feat(misconf): log causes of HCL file parsing errors (#7634)
- feat(misconf): normalize CreatedBy for buildah and legacy docker builder (#8953)
- feat(misconf): public network support for Azure Storage Account (#7601)
- feat(misconf): render causes for Terraform (#8360)
- feat(misconf): ssl_mode support for GCP SQL DB instance (#7564)
- feat(misconf): support auto_provisioning_defaults in google_container_cluster (#8705)
- feat(misconf): support for ignoring by inline comments for Dockerfile (#8115)
- feat(misconf): support for ignoring by inline comments for Helm (#8138)
- feat(misconf): support https_traffic_only_enabled in Az storage account (#9784)
- feat(nodejs): add a bun.lock analyzer (#8897)
- feat(nodejs): add bun.lock parser (#8851)
- feat(nodejs): add root and workspace for
yarnpackages (#8535) - feat(nodejs): respect peer dependencies for dependency tree (#7989)
- feat(oracle): add
flavorssupport (#7858) - feat(parser): ignore white space in pom.xml files (#7747)
- feat(python): add support for poetry dev dependencies (#8152)
- feat(python): add support for uv (#8080)
- feat(python): add support for uv dev and optional dependencies (#8134)
- feat(redhat): Add EOL date for RHEL 10. (#8910)
- feat(redhat): add os-release detection for RHEL-based images (#9458)
- feat(repo): add git repository metadata to reports (#9252)
- feat(report): add CVSS vectors in sarif report (#9157)
- feat(report): add fingerprint generation for vulnerabilities (#9794)
- feat(report): add image reference to report metadata (#9729)
- feat(report): switch ReportID from UUIDv4 to UUIDv7 (#9749)
- feat(report): update gitlab template to populate operating_system value (#7735)
- feat(rust): add root and workspace relationships/package for
cargolock files (#8676) - feat(sbom): add SHA-512 hash support for CycloneDX SBOM (#9126)
- feat(sbom): add manufacturer field to CycloneDX tools metadata (#9019)
- feat(sbom): add support for SPDX attestations (#9829)
- feat(sbom): added support for CoreOS (#9448)
- feat(sbom): use SPDX license IDs list to validate SPDX IDs (#9569)
- feat(seal): add seal support (#9370)
- feat(secret): Add built-in secrets rules for Private Packagist (#7826)
- feat(secret): implement streaming secret scanner with byte offset tracking (#9264)
- feat(suse): Add new openSUSE, Micro and SLES releases end of life dates (#9788)
- feat(suse): Align SUSE/OpenSUSE OS Identifiers (#7965)
- feat(terraform): add partial evaluation for policy templates (#8967)
- feat(terraform): use .terraform cache for remote modules in plan scanning (#9277)
- feat(ubuntu): add end of life date for Ubuntu 25.04 (#9077)
- feat(ubuntu): add eol date for 20.04-ESM (#8981)
- feat(vuln): add Root.io support for container image scanning (#9073)
- feat: Update registry fallbacks (#7679)
- feat: Update registry fallbacks [backport: release/v0.57] (#7944)
- feat: add ArtifactID field to uniquely identify scan targets (#9663)
- feat: add Bottlerocket OS package analyzer (#8653)
- feat: add HTTP request/response tracing support (#9125)
- feat: add JSONC support for comments and trailing commas (#8862)
- feat: add ReportID field to scan reports (#9670)
- feat: add
--distroflag to manually specify OS distribution for vulnerability scanning (#8070) - feat: add
--vuln-severity-sourceflag (#8269) - feat: add
workspaceRelationship(#7889) - feat: add a examples field to check metadata (#8068)
- feat: add cvss v4 score and vector in scan response (#7968)
- feat: add documentation URL for database lock errors (#9531)
- feat: add end of life date for Ubuntu 24.10 (#7787)
- feat: add graceful shutdown with signal handling (#9242)
- feat: add report summary table (#8177)
- feat: add support for registry mirrors (#8244)
- feat: add timeout handling for cache database operations (#9307)
- feat: allow ignoring findings by type in Rego (#9578)
- feat: include registry and repository in artifact ID calculation (#9689)
- feat: reject unsupported artifact types in remote image retrieval (#9052)
- feat: replace TinyGo with standard Go for WebAssembly modules (#8496)
- feat: terraform parser option to set current working directory (#8909)
- fix(alma): parse epochs from rpmqa file (#9101)
- fix(alma): parse epochs from rpmqa file [backport: release/v0.64] (#9119)
- fix(alpine): add
UIDfor removed packages (#7887) - fix(aws): change CPU and Memory type of ContainerDefinition to a string (#7995)
- fix(aws): update amazon linux 2 EOL date (#9176)
- fix(aws): use
BuildableClientinsead ofxhttp.Client(#9436) - fix(cli): Add more non-sensitive flags to telemetry (#9110)
- fix(cli): Add more non-sensitive flags to telemetry [backport: release/v0.64] (#9124)
- fix(cli): Handle empty ignore files more gracefully (#7962)
- fix(cli):
clean --alldeletes only relevant dirs (#7704) - fix(cli): add config name to skip-policy-update alias (#7820)
- fix(cli): add some values to the telemetry call (#9056)
- fix(cli): disable
--skip-dirand--skip-filesflags forsbomcommand (#8886) - fix(cli): don't use allow values for
--complianceflag (#8881) - fix(cli): ensure correct command is picked by telemetry (#9260)
- fix(cli): panic: attempt to get os.Args[1] when len(os.Args) < 2 (#9206)
- fix(conda): memory leak by adding closure method for
package.jsonfile (#9349) - fix(cyclonedx): handle multiple license types (#9378)
- fix(db): Dowload database when missing but metadata still exists (#9393)
- fix(db): fix case when 2 trivy-db were copied at the same time (#8452)
- fix(db): fix javadb downloading error handling (#7642)
- fix(debian): don't include empty licenses for
dpkgs(#8623) - fix(debian): infinite loop (#7928)
- fix(deps): bump alpine from
3.22.1to3.23.0[backport: release/v0.68] (#9949) - fix(flag): remove viper.SetDefault to fix IsSet() for config-only flags (#9732)
- fix(flag): skip hidden flags for
--generate-default-configcommand (#8046) - fix(fs): add missing defered Cleanup() call to post analyzer fs (#7882)
- fix(fs): avoid shadowing errors in file.glob (#9286)
- fix(fs): check postAnalyzers for StaticPaths (#8543)
- fix(fs): fix cache key generation to use UUID (#8275)
- fix(go): Do not trim v prefix from versions in Go Mod Analyzer (#7733)
- fix(go): merge nested flags into string for ldflags for Go binaries (#8368)
- fix(helm): properly handle multiple archived dependencies (#7782)
- fix(image): disable AVD-DS-0007 for history scanning (#8366)
- fix(image): use standardized HTTP client for ECR authentication (#9322)
- fix(java): correctly inherit
versionandscopefrom upper/rootdepManagementanddependenciesinto parents (#7541) - fix(java): correctly overwrite version from depManagement if dependency uses
project.*props (#8050) - fix(java): correctly overwrite version from depManagement if dependency uses
project.*props [backport: release/v0.58] (#8119) - fix(java): exclude dev dependencies in gradle lockfile (#8803)
- fix(java): update order for resolving package fields from multiple demManagement (#9575)
- fix(java): use
trueas default value for Repository Release|Snapshot Enabled in pom.xml and settings.xml files (#9751) - fix(julia): add
Relationshipfield support (#8939) - fix(k8s)!: support k8s multi container (#7444)
- fix(k8s): add missed option
PkgRelationships(#8442) - fix(k8s): check all results for vulnerabilities (#7946)
- fix(k8s): correct compare artifact versions (#8682)
- fix(k8s): correct compare artifact versions [backport: release/v0.61] (#8699)
- fix(k8s): disable parallel traversal with fs cache for k8s images (#9534)
- fix(k8s): remove using
last-applied-configuration(#8791) - fix(k8s): show report for
--report all(#8613) - fix(k8s): skip passed misconfigs for the summary report (#8684)
- fix(k8s): skip passed misconfigs for the summary report [backport: release/v0.61] (#8748)
- fix(k8s): skip resources without misconfigs (#7797)
- fix(k8s): support kubernetes v1.31 (#7810)
- fix(k8s): use in-memory cache backend during misconfig scanning (#8873)
- fix(license): add missed
GFDL-NIV-1.1andGFDL-NIV-1.2into Trivy mapping (#9116) - fix(license): always trim leading and trailing spaces for licenses (#8095)
- fix(license): don't normalize
unlicensedlicenses intounlicense(#9611) - fix(license): fix license normalization for Universal Permissive License (#7766)
- fix(license): handle SPDX WITH exceptions as single license in category detection (#9380)
- fix(license): handle WITH operator for
LaxSplitLicenses(#9232) - fix(misconf): .Config.User always takes precedence over USER in .History (#9050)
- fix(misconf): Check values wholly prior to evalution (#8604)
- fix(misconf): Improve logging for unsupported checks (#8634)
- fix(misconf): Update trivy-checks default repo to
mirror.gcr.io(#7953) - fix(misconf): add ephemeral block type to config schema (#8513)
- fix(misconf): add missing variable as unknown (#8683)
- fix(misconf): allow null values only for tf variables (#8112)
- fix(misconf): allow null values only for tf variables [backport: release/v0.58] (#8238)
- fix(misconf): change default ACL of digitalocean_spaces_bucket to private (#7577)
- fix(misconf): check if for-each is known when expanding dyn block (#8808)
- fix(misconf): check if for-each is known when expanding dyn block [backport: release/v0.62] (#8826)
- fix(misconf): check if metadata is not nil (#8647)
- fix(misconf): check if property is not nil before conversion (#7578)
- fix(misconf): correct Azure value-to-time conversion in AsTimeValue (#9015)
- fix(misconf): correctly adapt azure storage account (#9138)
- fix(misconf): correctly handle all YAML tags in K8S templates (#8259)
- fix(misconf): correctly parse empty port ranges in google_compute_firewall (#9237)
- fix(misconf): disable git terminal prompt on tf module load (#8026)
- fix(misconf): do not erase variable type for child modules (#7941)
- fix(misconf): do not log scanners when misconfig scanning is disabled (#8345)
- fix(misconf): do not log scanners when misconfig scanning is disabled [backport: release/v0.59] (#8349)
- fix(misconf): do not skip loading documents from subdirectories (#8526)
- fix(misconf): do not use cty.NilVal for non-nil values (#8567)
- fix(misconf): ecs include enhanced for container insights (#8326)
- fix(misconf): ensure boolean metadata values are correctly interpreted (#9770)
- fix(misconf): ensure ignore rules respect subdirectory chart paths (#9324)
- fix(misconf): ensure module source is known (#9404)
- fix(misconf): ensure value used as ignore marker is non-null and known (#9835)
- fix(misconf): filter null nodes when parsing json manifest (#8785)
- fix(misconf): fix for Azure Storage Account network acls adaptation (#7602)
- fix(misconf): fix incorrect k8s locations due to JSON to YAML conversion (#8073)
- fix(misconf): fix log bucket in schema (#9235)
- fix(misconf): handle heredocs in dockerfile instructions (#8284)
- fix(misconf): handle null properties in CloudFormation templates (#7813)
- fix(misconf): handle tofu files in module detection (#9486)
- fix(misconf): handle unsupported experimental flags in Dockerfile (#9769)
- fix(misconf): identify the chart file exactly by name (#8590)
- fix(misconf): load full Terraform module (#7925)
- fix(misconf): map healthcheck start period flag to --start-period instead of --startPeriod (#9837)
- fix(misconf): move disabled checks filtering after analyzer scan (#9002)
- fix(misconf): perform operations on attribute safely (#8774)
- fix(misconf): populate context correctly for module instances (#8656)
- fix(misconf): preserve original paths of remote submodules from .terraform (#9294)
- fix(misconf): properly expand dynamic blocks (#7612)
- fix(misconf): properly resolve local Terraform cache (#7983)
- fix(misconf): reduce log noise on incompatible check (#9029)
- fix(misconf): set default values for AWS::EKS::Cluster.ResourcesVpcConfig (#8548)
- fix(misconf): skip Azure CreateUiDefinition (#8503)
- fix(misconf): skip rewriting expr if attr is nil (#9113)
- fix(misconf): skip rewriting expr if attr is nil [backport: release/v0.64] (#9127)
- fix(misconf): strip build metadata suffixes from image history (#9498)
- fix(misconf): unmark cty values before access (#9495)
- fix(misconf): use argument value in WithIncludeDeprecatedChecks (#8942)
- fix(misconf): use correct field log_bucket instead of target_bucket in gcp bucket (#9296)
- fix(misconf): use log instead of fmt for logging (#8033)
- fix(misconf): wrap AWS EnvVar to iac types (#7407)
- fix(misconf): wrap legacy ENV values in quotes to preserve spaces (#9497)
- fix(nodejs): correctly parse
packagesarray ofbun.lockfile (#8998) - fix(nodejs): don't use prerelease logic for compare npm constraints (#9208)
- fix(nodejs): fix npmjs parser.pkgNameFromPath() panic issue (#9688)
- fix(nodejs): parse workspaces as objects for package-lock.json files (#9518)
- fix(nodejs): use snapshot string as
Package.IDfor pnpm packages (#9330) - fix(nodejs): use the default ID format to match licenses in pnpm packages. (#9661)
- fix(oracle): add architectures support for advisories (#4809)
- fix(oracle): add architectures support for advisories [backport: release/v0.58] (#8125)
- fix(os): Add photon 5.0 in supported OS (#9724)
- fix(os): add mapping OS aliases (#8466)
- fix(plugin): don't remove plugins when updating index.yaml file (#9358)
- fix(python): add
poetryv2 support (#8323) - fix(python): add
poetryv2 support [backport: release/v0.59] (#8335) - fix(python): impove package name normalization (#9290)
- fix(python): skip dev group's deps for poetry (#8106)
- fix(python): skip dev group's deps for poetry [backport: release/v0.58] (#8158)
- fix(redhat): Also try to find buildinfo in root layer (layer 0) (#8924)
- fix(redhat): check
usr/share/buildinfo/dir to detect content sets (#8222) - fix(redhat): correct rewriting of recommendations for the same vulnerability (#8063)
- fix(redhat): correct rewriting of recommendations for the same vulnerability [backport: release/v0.58] (#8135)
- fix(redhat): don't return error if
root/buildinfo/content_manifests/contains files that are notcontentSetsfiles (#7912) - fix(redhat): don't return error if
root/buildinfo/content_manifests/contains files that are notcontentSetsfiles [backport: release/v0.57] (#7939) - fix(redhat): include arch in PURL qualifiers (#7654)
- fix(redhat): include arch in PURL qualifiers [backport: release/v0.56] (#7702)
- fix(redhat): save contentSets for OS packages in fs/vm modes (#8820)
- fix(redhat): trim invalid suffix from content_sets in manifest parsing (#8818)
- fix(redhat): trim invalid suffix from content_sets in manifest parsing [backport: release/v0.62] (#8824)
- fix(repo):
git cloneoutput to Stderr (#7561) - fix(repo): preserve RepoMetadata on FS cache hit (#9389)
- fix(repo): sanitize git repo URL before inserting into report metadata (#9391)
- fix(report): Fix invalid URI in SARIF report (#7645)
- fix(report): clean buffer after flushing (#8725)
- fix(report): correct field order in SARIF license results (#9712)
- fix(report): don't panic when report contains vulns, but doesn't contain packages for
tableformat (#8549) - fix(report): handle
git@github.comschema for misconfigs insarifreport (#7898) - fix(report): remove html escaping for
shortDescriptionandfullDescriptionfields for sarif reports (#8344) - fix(rootio): check full version to detect
root.iopackages (#9117) - fix(rootio): check full version to detect
root.iopackages [backport: release/v0.64] (#9120) - fix(rootio): fix severity selection (#9181)
- fix(sbom): use
Annotationinstead ofAttributionTextsforSPDXformats (#7811) - fix(sbom): Fixes for Programming Language Vulnerabilities and SBOM Package Maintainer Details (#7871)
- fix(sbom): add SBOM file's filePath as Application FilePath if we can't detect its path (#8346)
- fix(sbom): add
buildInfoinfo as properties (#9683) - fix(sbom): add options for DBs in private registries (#7660)
- fix(sbom): add options for DBs in private registries [backport: release/v0.56] (#7691)
- fix(sbom): add support for
filecomponent type ofCycloneDX(#9372) - fix(sbom): attach nested packages to Application (#8144)
- fix(sbom): attach nested packages to Application [backport: release/v0.58] (#8168)
- fix(sbom): don’t panic on SBOM format if scanned CycloneDX file has empty metadata (#9562)
- fix(sbom): fix wrong overwriting of applications obtained from different sbom files but having same app type (#8052)
- fix(sbom): fix wrong overwriting of applications obtained from different sbom files but having same app type [backport: release/v0.58] (#8124)
- fix(sbom): improve logic for binding direct dependency to parent component (#8489)
- fix(sbom): merge in-graph and out-of-graph OS packages in scan results (#9194)
- fix(sbom): preserve OS packages from multiple SBOMs (#8325)
- fix(sbom): preserve OS packages from multiple SBOMs [backport: release/v0.59] (#8333)
- fix(sbom): remove unnecessary OS detection check in SBOM decoding (#9034)
- fix(sbom): scan results of SBOMs generated from container images are missing layers (#7635)
- fix(sbom): use correct field for licenses in CycloneDX reports (#9057)
- fix(sbom): use root package for
unknowndependencies (if exists) (#8104) - fix(sbom): use root package for
unknowndependencies (if exists) [backport: release/v0.58] (#8156) - fix(secret): add UTF-8 validation in secret scanner to prevent protobuf marshalling errors (#9253)
- fix(secret): fix line numbers for multiple-line secrets (#9104)
- fix(secret): ignore .dist-info directories during secret scanning (#8646)
- fix(server): add HTTP transport setup to server mode (#9217)
- fix(server): add missed Relationship field for
rpc(#8872) - fix(server): fix redis key when trying to delete blob (#8649)
- fix(server): secrets inspectation for the config analyzer in client server mode (#8418)
- fix(spdx): init
pkgFilePathsmap for all formats (#8380) - fix(spdx): save text licenses into
otherLicenseswithout normalize (#8502) - fix(spdx): use the
hasExtractedLicensingInfosfield for licenses that are not listed in the SPDX (#8077) - fix(suse): SUSE - update OSType constants and references for compatility (#8236)
- fix(suse): SUSE - update OSType constants and references for compatility [backport: release/v0.58] (#8237)
- fix(terraform):
evaluateStepto correctly setEvalContextfor multiple instances of blocks (#8555) - fix(terraform):
for_eachon a map returns a resource for every key (#9156) - fix(terraform): apply parser options to submodule parsing (#8377)
- fix(terraform): hcl object expressions to return references (#8271)
- fix(terraform): set null value as fallback for missing variables (#7669)
- fix(vex): don't suppress vulns for packages with infinity loop (#9465)
- fix(vex): don't use reused BOM (#9604)
- fix(vex): don't use reused BOM [backport: release/v0.67] (#9612)
- fix(vex): use
lo.IsNilto checkVEXfrom OCI artifact (#8858) - fix(vex): use a separate
visitedset for each DFS path (#9760) - fix(vuln): compare
nugetpackage names in lower case (#9456) - fix(wolfi): support new APK database location (#8937)
- fix: Add missing version check flags (#8951)
- fix: CVE-2024-45337: Misuse of ServerConfig.PublicKeyCallback may cause authorization bypass (#8088)
- fix: CVE-2025-21613 and CVE-2025-21614 : go-git: argument injection via the URL field (#8207)
- fix: CVE-2025-21613 and CVE-2025-21614 : go-git: argument injection via the URL field [backport: release/v0.58] (#8215)
- fix: Correctly check for semver versions for trivy version check (#8948)
- fix: Improve version comparisons when build identifiers are present (#7873)
- fix: Trim the end-of-range suffix (#9618)
- fix: Updated twitter icon (#7772)
- fix: Use
fetch-level: 1to check out trivy-repo in the release workflow (#9636) - fix: Use
fetch-level: 1to check out trivy-repo in the release workflow [backport: release/v0.67] (#9638) - fix: add
buildInfoforBlobInfoinrpcpackage (#9608) - fix: add
buildInfoforBlobInfoinrpcpackage [backport: release/v0.67] (#9615) - fix: also check
filepathwhen removing duplicate packages (#9142) - fix: check post-analyzers for StaticPaths (#8904)
- fix: close all opened resources if an error occurs (#9665)
- fix: close file descriptors and pipes on error paths (#9536)
- fix: create temp file under composite fs dir (#9387)
- fix: de-duplicate same
dpkgpackages with different filePaths from different layers (#8298) - fix: don't show corrupted trivy-db warning for first run (#8991)
- fix: don't use
scopefortrivy registry logincommand (#8393) - fix: early-return, indent-error-flow and superfluous-else rules from revive (#8796)
- fix: enable err-error and errorf rules from perfsprint linter (#7859)
- fix: enable usestdlibvars linter (#7770)
- fix: filter all files when processing files installed from package managers (#8842)
- fix: handle
BLOW_UNKNOWNerror to download DBs (#8060) - fix: handle
BLOW_UNKNOWNerror to download DBs [backport: release/v0.58] (#8121) - fix: improve conversion of image config to Dockerfile (#8308)
- fix: julia parser panicing (#8883)
- fix: migrate from
*.listto*.md5sumsfiles fordpkg(#9131) - fix: more revive rules (#8814)
- fix: octalLiteral from go-critic (#8811)
- fix: persistent flag option typo (#9374)
- fix: prevent graceful shutdown message on normal exit (#9244)
- fix: respect GITHUB_TOKEN to download artifacts from GHCR (#7580)
- fix: restore compatibility for google.protobuf.Value (#9559)
- fix: restore compatibility for google.protobuf.Value [backport: release/v0.67] (#9631)
- fix: supporting .egg-info/METADATA in python.Packaging analyzer (#9151)
- fix: suppress debug log for context cancellation errors (#9298)
- fix: testifylint last issues (#8768)
- fix: unused-parameter rule from revive (#8794)
- fix: update all documentation links (#8045)
- fix: update all documentation links (#9777)
- fix: update cosing settings for GoReleaser after bumping cosing to v3 (#9863)
- fix: use
--file-patternsflag for all post analyzers (#7365) - fix: use context for analyzers (#9538)
- fix: use-any from revive (#8810)
- fix: using SrcVersion instead of Version for echo detector (#9552)
- fix: using SrcVersion instead of Version for echo detector [backport: release/v0.67] (#9629)
- fix: validate backport branch name (#9548)
- fix: wasm module test (#8099)
- perf(misconf): parse input for Rego once (#8483)
- perf(misconf): retrieve check metadata from annotations once (#8478)
- perf(secret): only match secrets of meaningful length, allow example strings to not be matched (#8602)
- perf: avoid heap allocation in applier findPackage (#7883)
- refactor(cli): Update the cloud config command (#9676)
- refactor(cloudformation): remove unused ScanFile method from Scanner (#8927)
- refactor(db): change logic to detect wrong DB (#8864)
- refactor(db): use
Getterinterface withGetParamsfor trivy-db sources (#9239) - refactor(flag): improve flag system architecture and extensibility (#8718)
- refactor(fs): use underlyingPath to determine virtual files more reliably (#9302)
- refactor(k8s): add v prefix for Go packages (#7839)
- refactor(k8s): scan config files as a folder (#7690)
- refactor(license): improve license expression normalization (#8257)
- refactor(license): simplify compound license scanning (#8896)
- refactor(misconf): Deprecate
EXCEPTIONSfor misconfiguration scanning (#7776) - refactor(misconf): Remove unused options (#7896)
- refactor(misconf): Simplify misconfig checks bundle parsing (#8533)
- refactor(misconf): add ID to scan.Rule (#9573)
- refactor(misconf): add ManifestFromYAML for unified manifest parsing (#9680)
- refactor(misconf): decouple input fs and track extracted files with fs references (#9281)
- refactor(misconf): get a block or attribute without calling HasChild (#8586)
- refactor(misconf): introduce generic scanner (#7515)
- refactor(misconf): make Rego scanner independent of config type (#7517)
- refactor(misconf): mark AVDID fields as deprecated and use ID internally (#9576)
- refactor(misconf): migrate from custom Azure JSON parser (#9222)
- refactor(misconf): parse azure_policy_enabled to addonprofile.azurepolicy.enabled (#9851)
- refactor(misconf): remove module outputs from parser.EvaluateAll (#8587)
- refactor(misconf): remove unused methods for ec2.Instance (#8536)
- refactor(misconf): remove unused methods from iac types (#8782)
- refactor(misconf): remove unused methods from providers (#8781)
- refactor(misconf): remove unused terraform attribute methods (#8657)
- refactor(misconf): replace github.com/liamg/memoryfs with internal mapfs and testing/fstest (#9282)
- refactor(misconf): rewrite Rego module filtering using functional filters (#9061)
- refactor(misconf): set Trivy version by default in Rego scanner (#9001)
- refactor(misconf): simplify k8s scanner (#7717)
- refactor(misconf): switch to x/json (#8719)
- refactor(misconf): type-safe parser results in generic scanner (#9685)
- refactor(misconf): use OPA v1 (#8518)
- refactor(misconf): use atomic.Int32 (#9385)
- refactor(python): use once + debug for
License acquired from METADATA...logs (#8175) - refactor(report): write tables after rendering all results (#8357)
- refactor(sbom): simplify relationship generation (#7985)
- refactor(secret): clarify secret scanner messages (#9409)
- refactor(secret): optimize performance by moving ToLower operation outside loop (#7862)
- refactor(server): change custom advisory and vulnerability data types fr… (#8923)
- refactor(terraform): make Scan method of Terraform plan scanner private (#9272)
- refactor(terraform): remove result sorting from scanner (#8928)
- refactor(terraform): simplify AllReferences method signature in Attribute (#8906)
- refactor(ubuntu): update time handling for fixing time (#8780)
- refactor(vex): improve SBOM reference handling with project standards (#8457)
- refactor: add case-insensitive string set implementation (#9720)
- refactor: add generic Set implementation (#8149)
- refactor: add hook interface for extended functionality (#8585)
- refactor: centralize HTTP transport configuration (#9058)
- refactor: export
systemFileFilteringPost Handler (#9359) - refactor: migrate from
github.com/aquasecurity/jfathertogithub.com/go-json-experiment/json(#8591) - refactor: migrate from go-json-experiment to encoding/json/v2 (#9422)
- refactor: move the aws config (#9617)
- refactor: remove aws flag helper message (#9080)
- refactor: remove google/wire dependency and implement manual DI (#9509)
- refactor: remove support for custom Terraform checks (#7901)
- refactor: rename scanner to service (#8584)
- refactor: simplify Detect function signature (#9280)
- refactor: switch to stable azcontainerregistry SDK package (#9319)
- refactor: use slices package instead of custom function (#8172)
- refactor: use strings.SplitSeq instead of strings.Split in for-loop (#8983)
- refactor: use trivy-checks/pkg/specs package (#8226)
- release: v0.56.2 [release/v0.56] (#7694)
- release: v0.57.0 [main] (#7710)
- release: v0.57.1 [release/v0.57] (#7943)
- release: v0.58.0 [main] (#7874)
- release: v0.58.1 [release/v0.58] (#8120)
- release: v0.58.2 [release/v0.58] (#8216)
- release: v0.59.0 [main] (#8041)
- release: v0.59.1 [release/v0.59] (#8334)
- release: v0.60.0 [main] (#8327)
- release: v0.61.0 [main] (#8507)
- release: v0.61.1 [release/v0.61] (#8704)
- release: v0.62.0 [main] (#8669)
- release: v0.62.1 [release/v0.62] (#8825)
- release: v0.63.0 [main] (#8809)
- release: v0.64.0 [main] (#8955)
- release: v0.64.1 [release/v0.64] (#9122)
- release: v0.65.0 [main] (#9108)
- release: v0.66.0 [main] (#9289)
- release: v0.67.0 [main] (#9432)
- release: v0.67.1 [release/v0.67] (#9614)
- release: v0.67.2 [release/v0.67] (#9639)
- release: v0.68.0 [main] (#9549)
- release: v0.68.1 [main] (#9867)
- release: v0.68.2 [release/v0.68] (#9950)
- style: Fix MD syntax in self-hosting.md (#8523)
- test(go): refactor mod_test.go to use txtar format (#9775)
- test(go): set
GOPATHfor tests (#9785) - test(helm): bump up Yamale dependency for Helm chart-testing-action (#9653)
- test(k8s): update k8s integrtion test (#9725)
- test(k8s): use a specific bundle for k8s misconfig scan (#9633)
- test(misconf): drop gcp iam test covered by another case (#9285)
- test(misconf): move terraform scan tests to integration tests (#9271)
- test(misconf): remove BenchmarkCalculate using outdated check metadata (#9291)
- test(server): replace mock driver with memory cache in server tests (#8416)
- test: add HTTP basic authentication to git test server (#9407)
- test: add end-to-end testing framework with image scan and proxy tests (#9231)
- test: change branch in spdx schema link to check in integration tests (#7935)
- test: change branch in spdx schema link to check in integration tests [backport: release/v0.57] (#7940)
- test: define constants for test images (#7739)
- test: improve and extend tests for iac/adapters/arm (#9028)
- test: improve golden file management in integration tests (#9699)
- test: include integration tests in linting and fix all issues (#9060)
- test: replace Go checks with Rego (#7867)
- test: replace mock with memory cache and fix non-deterministic tests (#8410)
- test: replace mock with memory cache in scanner tests (#8413)
- test: save
containerdimage into archive and use in tests (#7816) - test: set dummy value for NUGET_PACKAGES (#8107)
- test: update golden files for TestRepository* integration tests (#9684)
- test: use
aquasecurityrepository for test images (#8677) - test: use
aquasecurityrepository for test images [backport: release/v0.61] (#8698) - test: use forked images (#7755)
- test: use memory cache (#8403)
- test: use table-driven tests in Helm scanner tests (#8592)
Список пакетов
openSUSE Leap 16.0
Ссылки
- SUSE Security Ratings
- SUSE Bug 1227010
- SUSE Bug 1232948
- SUSE Bug 1234512
- SUSE Bug 1235265
- SUSE Bug 1237618
- SUSE Bug 1239225
- SUSE Bug 1239385
- SUSE Bug 1240466
- SUSE Bug 1241724
- SUSE Bug 1243633
- SUSE Bug 1246151
- SUSE Bug 1246730
- SUSE Bug 1248897
- SUSE Bug 1248937
- SUSE Bug 1250625
- SUSE Bug 1251363
- SUSE Bug 1251547
- SUSE Bug 1253512
- SUSE Bug 1253786
Описание
HashiCorp's go-getter library is vulnerable to argument injection when executing Git to discover remote branches. This vulnerability does not affect the go-getter/v2 branch and package.
Затронутые продукты
Ссылки
- CVE-2024-3817
- SUSE Bug 1226999
Описание
Applications and libraries which misuse connection.serverAuthenticate (via callback field ServerConfig.PublicKeyCallback) may be susceptible to an authorization bypass. The documentation for ServerConfig.PublicKeyCallback says that "A call to this function does not guarantee that the key offered is in fact used to authenticate." Specifically, the SSH protocol allows clients to inquire about whether a public key is acceptable before proving control of the corresponding private key. PublicKeyCallback may be called with multiple keys, and the order in which the keys were provided cannot be used to infer which key the client successfully authenticated with, if any. Some applications, which store the key(s) passed to PublicKeyCallback (or derived information) and make security relevant determinations based on it once the connection is established, may make incorrect assumptions. For example, an attacker may send public keys A and B, and then authenticate with A. PublicKeyCallback would be called only twice, first with A and then with B. A vulnerable application may then make authorization decisions based on key B for which the attacker does not actually control the private key. Since this API is widely misused, as a partial mitigation golang.org/x/cry...@v0.31.0 enforces the property that, when successfully authenticating via public key, the last key passed to ServerConfig.PublicKeyCallback will be the key used to authenticate the connection. PublicKeyCallback will now be called multiple times with the same key, if necessary. Note that the client may still not control the last key passed to PublicKeyCallback if the connection is then authenticated with a different method, such as PasswordCallback, KeyboardInteractiveCallback, or NoClientAuth. Users should be using the Extensions field of the Permissions return value from the various authentication callbacks to record data associated with the authentication attempt instead of referencing external state. Once the connection is established the state corresponding to the successful authentication attempt can be retrieved via the ServerConn.Permissions field. Note that some third-party libraries misuse the Permissions type by sharing it across authentication attempts; users of third-party libraries should refer to the relevant projects for guidance.
Затронутые продукты
Ссылки
- CVE-2024-45337
- SUSE Bug 1234482
Описание
An attacker can craft an input to the Parse functions that would be processed non-linearly with respect to its length, resulting in extremely slow parsing. This could cause a denial of service.
Затронутые продукты
Ссылки
- CVE-2024-45338
- SUSE Bug 1234794
Описание
golang-jwt is a Go implementation of JSON Web Tokens. Unclear documentation of the error behavior in `ParseWithClaims` can lead to situation where users are potentially not checking errors in the way they should be. Especially, if a token is both expired and invalid, the errors returned by `ParseWithClaims` return both error codes. If users only check for the `jwt.ErrTokenExpired ` using `error.Is`, they will ignore the embedded `jwt.ErrTokenSignatureInvalid` and thus potentially accept invalid tokens. A fix has been back-ported with the error handling logic from the `v5` branch to the `v4` branch. In this logic, the `ParseWithClaims` function will immediately return in "dangerous" situations (e.g., an invalid signature), limiting the combined errors only to situations where the signature is valid, but further validation failed (e.g., if the signature is valid, but is expired AND has the wrong audience). This fix is part of the 4.5.1 release. We are aware that this changes the behaviour of an established function and is not 100 % backwards compatible, so updating to 4.5.1 might break your code. In case you cannot update to 4.5.0, please make sure that you are properly checking for all errors ("dangerous" ones first), so that you are not running in the case detailed above.
Затронутые продукты
Ссылки
- CVE-2024-51744
- SUSE Bug 1232936
Описание
A flaw was found in github.com/go-viper/mapstructure/v2, in the field processing component using mapstructure.WeakDecode. This vulnerability allows information disclosure through detailed error messages that may leak sensitive input values via malformed user-supplied data processed in security-critical contexts.
Затронутые продукты
Ссылки
- CVE-2025-11065
- SUSE Bug 1250608
Описание
go-git is a highly extensible git implementation library written in pure Go. An argument injection vulnerability was discovered in go-git versions prior to v5.13. Successful exploitation of this vulnerability could allow an attacker to set arbitrary values to git-upload-pack flags. This only happens when the file transport protocol is being used, as that is the only protocol that shells out to git binaries. This vulnerability is fixed in 5.13.0.
Затронутые продукты
Ссылки
- CVE-2025-21613
- SUSE Bug 1235572
Описание
go-git is a highly extensible git implementation library written in pure Go. A denial of service (DoS) vulnerability was discovered in go-git versions prior to v5.13. This vulnerability allows an attacker to perform denial of service attacks by providing specially crafted responses from a Git server which triggers resource exhaustion in go-git clients. Users running versions of go-git from v4 and above are recommended to upgrade to v5.13 in order to mitigate this vulnerability.
Затронутые продукты
Ссылки
- CVE-2025-21614
Описание
An attacker can pass a malicious malformed token which causes unexpected memory to be consumed during parsing.
Затронутые продукты
Ссылки
- CVE-2025-22868
- SUSE Bug 1239185
- SUSE Bug 1239186
Описание
SSH servers which implement file transfer protocols are vulnerable to a denial of service attack from clients which complete the key exchange slowly, or not at all, causing pending content to be read into memory, but never transmitted.
Затронутые продукты
Ссылки
- CVE-2025-22869
- SUSE Bug 1239322
Описание
The tokenizer incorrectly interprets tags with unquoted attribute values that end with a solidus character (/) as self-closing. When directly using Tokenizer, this can result in such tags incorrectly being marked as self-closing, and when using the Parse functions, this can result in content following such tags as being placed in the wrong scope during DOM construction, but only when tags are in foreign content (e.g. <math>, <svg>, etc contexts).
Затронутые продукты
Ссылки
- CVE-2025-22872
- SUSE Bug 1241710
- SUSE Bug 1265255
- SUSE Bug 1265256
Описание
Go JOSE provides an implementation of the Javascript Object Signing and Encryption set of standards in Go, including support for JSON Web Encryption (JWE), JSON Web Signature (JWS), and JSON Web Token (JWT) standards. In versions on the 4.x branch prior to version 4.0.5, when parsing compact JWS or JWE input, Go JOSE could use excessive memory. The code used strings.Split(token, ".") to split JWT tokens, which is vulnerable to excessive memory consumption when processing maliciously crafted tokens with a large number of `.` characters. An attacker could exploit this by sending numerous malformed tokens, leading to memory exhaustion and a Denial of Service. Version 4.0.5 fixes this issue. As a workaround, applications could pre-validate that payloads passed to Go JOSE do not contain an excessive number of `.` characters.
Затронутые продукты
Ссылки
- CVE-2025-27144
- SUSE Bug 1237608
- SUSE Bug 1237609
Описание
golang-jwt is a Go implementation of JSON Web Tokens. Starting in version 3.2.0 and prior to versions 5.2.2 and 4.5.2, the function parse.ParseUnverified splits (via a call to strings.Split) its argument (which is untrusted data) on periods. As a result, in the face of a malicious request whose Authorization header consists of Bearer followed by many period characters, a call to that function incurs allocations to the tune of O(n) bytes (where n stands for the length of the function's argument), with a constant factor of about 16. This issue is fixed in 5.2.2 and 4.5.2.
Затронутые продукты
Ссылки
- CVE-2025-30204
- SUSE Bug 1240441
- SUSE Bug 1240442
Описание
Open Policy Agent (OPA) is an open source, general-purpose policy engine. Prior to version 1.4.0, when run as a server, OPA exposes an HTTP Data API for reading and writing documents. Requesting a virtual document through the Data API entails policy evaluation, where a Rego query containing a single data document reference is constructed from the requested path. This query is then used for policy evaluation. A HTTP request path can be crafted in a way that injects Rego code into the constructed query. The evaluation result cannot be made to return any other data than what is generated by the requested path, but this path can be misdirected, and the injected Rego code can be crafted to make the query succeed or fail; opening up for oracle attacks or, given the right circumstances, erroneous policy decision results. Furthermore, the injected code can be crafted to be computationally expensive, resulting in a Denial Of Service (DoS) attack. This issue has been patched in version 1.4.0. A workaround involves having network access to OPA's RESTful APIs being limited to `localhost` and/or trusted networks, unless necessary for production reasons.
Затронутые продукты
Ссылки
- CVE-2025-46569
- SUSE Bug 1246710
Описание
containerd is an open-source container runtime. A bug was found in the containerd's CRI implementation where containerd, starting in version 2.0.1 and prior to version 2.0.5, doesn't put usernamespaced containers under the Kubernetes' cgroup hierarchy, therefore some Kubernetes limits are not honored. This may cause a denial of service of the Kubernetes node. This bug has been fixed in containerd 2.0.5+ and 2.1.0+. Users should update to these versions to resolve the issue. As a workaround, disable usernamespaced pods in Kubernetes temporarily.
Затронутые продукты
Ссылки
- CVE-2025-47291
- SUSE Bug 1243632
Описание
The html.Parse function in golang.org/x/net/html has quadratic parsing complexity when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
Затронутые продукты
Ссылки
- CVE-2025-47911
- SUSE Bug 1251308
Описание
SSH clients receiving SSH_AGENT_SUCCESS when expecting a typed response will panic and cause early termination of the client process.
Затронутые продукты
Ссылки
- CVE-2025-47913
- SUSE Bug 1253506
Описание
SSH Agent servers do not validate the size of messages when processing new identity requests, which may cause the program to panic if the message is malformed due to an out of bounds read.
Затронутые продукты
Ссылки
- CVE-2025-47914
- SUSE Bug 1253967
Описание
Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock file can lead to local code execution when dependencies are updated. Fields in a Chart.yaml file, that are carried over to a Chart.lock file when dependencies are updated and this file is written, can be crafted in a way that can cause execution if that same content were in a file that is executed (e.g., a bash.rc file or shell script). If the Chart.lock file is symlinked to one of these files updating dependencies will write the lock file content to the symlinked file. This can lead to unwanted execution. Helm warns of the symlinked file but did not stop execution due to symlinking. This issue has been resolved in Helm v3.18.4.
Затронутые продукты
Ссылки
- CVE-2025-53547
- SUSE Bug 1246150
Описание
xz is a pure golang package for reading and writing xz-compressed files. Prior to version 0.5.14, it is possible to put data in front of an LZMA-encoded byte stream without detecting the situation while reading the header. This can lead to increased memory consumption because the current implementation allocates the full decoding buffer directly after reading the header. The LZMA header doesn't include a magic number or has a checksum to detect such an issue according to the specification. Note that the code recognizes the issue later while reading the stream, but at this time the memory allocation has already been done. This issue has been patched in version 0.5.14.
Затронутые продукты
Ссылки
- CVE-2025-58058
- SUSE Bug 1248889
Описание
SSH servers parsing GSSAPI authentication requests do not validate the number of mechanisms specified in the request, allowing an attacker to cause unbounded memory consumption.
Затронутые продукты
Ссылки
- CVE-2025-58181
- SUSE Bug 1253784
Описание
The html.Parse function in golang.org/x/net/html has an infinite parsing loop when processing certain inputs, which can lead to denial of service (DoS) if an attacker provides specially crafted HTML content.
Затронутые продукты
Ссылки
- CVE-2025-58190
- SUSE Bug 1251309