Skip to content

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Oct 13, 2025

Bumps the aqua group with 2 updates: github.com/aquasecurity/trivy and github.com/aquasecurity/trivy-checks.

Updates github.com/aquasecurity/trivy from 0.67.0 to 0.67.2

Release notes

Sourced from github.com/aquasecurity/trivy's releases.

v0.67.2

Changelog

  • 60c57ad5ad7f270cecb51dff2dbf4d680114f6f8 release: v0.67.2 [release/v0.67] (#9639)
  • f3ee80c8e0a92a7d61f2fee21bfb9a44d95067da fix: Use fetch-level: 1 to check out trivy-repo in the release workflow [backport: release/v0.67] (#9638)

v0.67.1

Changelog

  • cbed239f3990f5d366c4604a0f57f7785e7e9ec5 release: v0.67.1 [release/v0.67] (#9614)
  • 1a840935bbd93b26bdbe3994d68487ca134fc407 fix: restore compatibility for google.protobuf.Value [backport: release/v0.67] (#9631)
  • 3bc1490c8ca941989e219b9fccacff0f72df950c fix: using SrcVersion instead of Version for echo detector [backport: release/v0.67] (#9629)
  • 542eee7c387de4ef885ee7364b0264c0fd614587 fix: add buildInfo for BlobInfo in rpc package [backport: release/v0.67] (#9615)
  • f65dd053096795e7beb88c92340430ee8d89c3e8 fix(vex): don't use reused BOM [backport: release/v0.67] (#9612)
Changelog

Sourced from github.com/aquasecurity/trivy's changelog.

0.67.2 (2025-10-10)

Bug Fixes

  • Use fetch-level: 1 to check out trivy-repo in the release workflow [backport: release/v0.67] (#9638) (f3ee80c)

0.67.1 (2025-10-09)

Bug Fixes

  • add buildInfo for BlobInfo in rpc package [backport: release/v0.67] (#9615) (542eee7)
  • restore compatibility for google.protobuf.Value [backport: release/v0.67] (#9631) (1a84093)
  • using SrcVersion instead of Version for echo detector [backport: release/v0.67] (#9629) (3bc1490)
  • vex: don't use reused BOM [backport: release/v0.67] (#9612) (f65dd05)
Commits
  • 60c57ad release: v0.67.2 [release/v0.67] (#9639)
  • f3ee80c fix: Use fetch-level: 1 to check out trivy-repo in the release workflow [ba...
  • cbed239 release: v0.67.1 [release/v0.67] (#9614)
  • 1a84093 fix: restore compatibility for google.protobuf.Value [backport: release/v0.67...
  • 3bc1490 fix: using SrcVersion instead of Version for echo detector [backport: release...
  • 542eee7 fix: add buildInfo for BlobInfo in rpc package [backport: release/v0.67...
  • f65dd05 fix(vex): don't use reused BOM [backport: release/v0.67] (#9612)
  • See full diff in compare view

Updates github.com/aquasecurity/trivy-checks from 1.11.3-0.20250604022615-9a7efa7c9169 to 1.12.1

Release notes

Sourced from github.com/aquasecurity/trivy-checks's releases.

v1.12.1

What's Changed

Full Changelog: aquasecurity/trivy-checks@v1.12.0...v1.12.1

v1.12.0

What's Changed

... (truncated)

Commits

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Oct 13, 2025
@dependabot dependabot bot requested a review from simar7 as a code owner October 13, 2025 16:14
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Oct 13, 2025
@github-actions github-actions bot added the deps label Oct 13, 2025
@dependabot dependabot bot force-pushed the dependabot/go_modules/aqua-a6628e641b branch from 8c8300f to 249582f Compare October 20, 2025 16:03
@dependabot dependabot bot force-pushed the dependabot/go_modules/aqua-a6628e641b branch from 249582f to baa202c Compare November 10, 2025 17:38
@dependabot @github
Copy link
Contributor Author

dependabot bot commented on behalf of github Nov 17, 2025

Dependabot tried to update this pull request, but something went wrong. We're looking into it, but in the meantime you can retry the update by commenting @dependabot recreate.

@dependabot dependabot bot force-pushed the dependabot/go_modules/aqua-a6628e641b branch from baa202c to 0e1baac Compare November 24, 2025 17:01
@dependabot dependabot bot force-pushed the dependabot/go_modules/aqua-a6628e641b branch 2 times, most recently from a820397 to 35306d3 Compare December 8, 2025 16:03
Bumps the aqua group with 2 updates: [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy) and [github.com/aquasecurity/trivy-checks](https://github.com/aquasecurity/trivy-checks).


Updates `github.com/aquasecurity/trivy` from 0.67.0 to 0.67.2
- [Release notes](https://github.com/aquasecurity/trivy/releases)
- [Changelog](https://github.com/aquasecurity/trivy/blob/v0.67.2/CHANGELOG.md)
- [Commits](aquasecurity/trivy@v0.67.0...v0.67.2)

Updates `github.com/aquasecurity/trivy-checks` from 1.11.3-0.20250604022615-9a7efa7c9169 to 1.12.1
- [Release notes](https://github.com/aquasecurity/trivy-checks/releases)
- [Commits](https://github.com/aquasecurity/trivy-checks/commits/v1.12.1)

---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
  dependency-version: 0.67.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: aqua
- dependency-name: github.com/aquasecurity/trivy-checks
  dependency-version: 1.12.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: aqua
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot bot force-pushed the dependabot/go_modules/aqua-a6628e641b branch from 35306d3 to a3e2550 Compare December 15, 2025 16:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file deps go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant