Skip to content
Closed
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
3944 commits
Select commit Hold shift + click to select a range
1ff9ac7
fix(vuln): compare `nuget` package names in lower case (#9456)
DmitriyLewen Sep 15, 2025
788f6fa
refactor: migrate from go-json-experiment to encoding/json/v2 (#9422)
knqyf263 Sep 15, 2025
8dce58c
ci(deps): add 3-day cooldown period for Dependabot updates (#9475)
knqyf263 Sep 15, 2025
cb25a07
feat(redhat): add os-release detection for RHEL-based images (#9458)
teddygood Sep 15, 2025
8b2575b
docs: Fix typo in terraform docs (#9492)
matt-andersen Sep 18, 2025
aff03eb
feat(cyclonedx): preserve SBOM structure when scanning SBOM files wit…
knqyf263 Sep 20, 2025
c938806
fix(misconf): strip build metadata suffixes from image history (#9498)
nikpivkin Sep 22, 2025
6d562a3
feat(sbom): added support for CoreOS (#9448)
amitverse Sep 22, 2025
842ebdc
docs: move info about `detection priority` into coverage section (#9469)
DmitriyLewen Sep 22, 2025
267a970
fix(misconf): wrap legacy ENV values in quotes to preserve spaces (#9…
nikpivkin Sep 22, 2025
366910b
chore(deps): bump the common group across 1 directory with 24 updates…
dependabot[bot] Sep 23, 2025
331cf5d
chore(deps): bump the aws group with 6 updates (#9481)
dependabot[bot] Sep 23, 2025
d57b160
refactor: remove google/wire dependency and implement manual DI (#9509)
knqyf263 Sep 23, 2025
352855e
refactor(fs): use underlyingPath to determine virtual files more reli…
nikpivkin Sep 23, 2025
404abb3
fix(nodejs): parse workspaces as objects for package-lock.json files …
DmitriyLewen Sep 24, 2025
7b663d8
feat(cli): change --list-all-pkgs default to true (#9510)
knqyf263 Sep 24, 2025
8e40d27
fix(misconf): unmark cty values before access (#9495)
nikpivkin Sep 24, 2025
42b3bf3
feat(cloudformation): support default values and list results in Fn::…
nikpivkin Sep 25, 2025
92ebc7e
fix(db): Dowload database when missing but metadata still exists (#9393)
tom1299 Sep 26, 2025
eba48af
feat: add documentation URL for database lock errors (#9531)
knqyf263 Sep 26, 2025
a4cbd6a
fix: close file descriptors and pipes on error paths (#9536)
knqyf263 Sep 26, 2025
e149094
docs: fix modules path and update code example (#9539)
nikpivkin Sep 26, 2025
e4af279
feat(seal): add seal support (#9370)
DmitriyLewen Sep 29, 2025
bfd2f6b
fix(misconf): handle tofu files in module detection (#9486)
nikpivkin Sep 29, 2025
c0c7a6b
fix(k8s): disable parallel traversal with fs cache for k8s images (#9…
afdesk Sep 30, 2025
c446a5c
docs: clarify inline ignore limitations for resource-less checks (#9537)
nikpivkin Sep 30, 2025
e7c16a7
refactor(misconf): replace github.com/liamg/memoryfs with internal ma…
nikpivkin Sep 30, 2025
fa6f1bf
fix(aws): use `BuildableClient` insead of `xhttp.Client` (#9436)
DmitriyLewen Sep 30, 2025
78f0d4a
fix(vex): don't suppress vulns for packages with infinity loop (#9465)
DmitriyLewen Sep 30, 2025
adeb362
release: v0.67.0 [main] (#9432)
aqua-bot Sep 30, 2025
f0fd432
fix: validate backport branch name (#9548)
knqyf263 Sep 30, 2025
3dd0ebb
ci(helm): bump Trivy version to 0.67.0 for Trivy Helm Chart 0.19.0 (#…
aqua-bot Sep 30, 2025
719ea29
chore: add context to the cache interface (#9565)
Oct 3, 2025
9058d51
chore(deps): Switch to go-viper/mapstructure (#9579)
mikelolasagasti Oct 6, 2025
36ab331
chore(deps): bump the common group across 1 directory with 7 updates …
dependabot[bot] Oct 6, 2025
3962ea4
chore(deps): bump the github-actions group across 1 directory with 9 …
dependabot[bot] Oct 6, 2025
e286c5e
fix(java): update order for resolving package fields from multiple de…
DmitriyLewen Oct 6, 2025
19615a8
refactor(misconf): add ID to scan.Rule (#9573)
nikpivkin Oct 6, 2025
4bef183
docs: bump pygments from 2.18.0 to 2.19.2 (#9596)
nikpivkin Oct 6, 2025
c638fc6
feat: allow ignoring findings by type in Rego (#9578)
nikpivkin Oct 6, 2025
3671251
docs: improve documentation for scanning raw IaC configurations (#9571)
nikpivkin Oct 7, 2025
05375d1
chore(deps): update to module-compatible docker-credential-gcr/v2 (#9…
mikelolasagasti Oct 7, 2025
d7aa84f
ci: add API diff workflow (#9600)
knqyf263 Oct 7, 2025
aeeb2a1
fix: restore compatibility for google.protobuf.Value (#9559)
knqyf263 Oct 7, 2025
b9e3e0b
ci: use pull_request_target for apidiff workflow to support fork PRs …
knqyf263 Oct 7, 2025
7422cc7
fix(vex): don't use reused BOM (#9604)
DmitriyLewen Oct 8, 2025
6def66e
fix: add `buildInfo` for `BlobInfo` in `rpc` package (#9608)
DmitriyLewen Oct 8, 2025
cff91ac
feat(fs): change artifact type to repository when git info is detecte…
knqyf263 Oct 8, 2025
66479f0
fix: using SrcVersion instead of Version for echo detector (#9552)
orizerah Oct 9, 2025
09162e5
fix(license): don't normalize `unlicensed` licenses into `unlicense` …
DmitriyLewen Oct 9, 2025
2f695b9
refactor: move the aws config (#9617)
Oct 9, 2025
6e53686
fix: Use `fetch-level: 1` to check out trivy-repo in the release work…
DmitriyLewen Oct 10, 2025
492797b
test(k8s): use a specific bundle for k8s misconfig scan (#9633)
afdesk Oct 10, 2025
e18b038
fix: Trim the end-of-range suffix (#9618)
raghur-orca Oct 13, 2025
4e1e6fc
test(helm): bump up Yamale dependency for Helm chart-testing-action (…
afdesk Oct 13, 2025
ce8d47e
ci(helm): bump Trivy version to 0.67.2 for Trivy Helm Chart 0.19.1 (#…
aqua-bot Oct 13, 2025
fd92773
chore(deps): bump the aws group with 6 updates (#9547)
dependabot[bot] Oct 14, 2025
84518db
chore(deps): bump the docker group with 3 updates (#9545)
dependabot[bot] Oct 14, 2025
b885d3a
fix: use context for analyzers (#9538)
DmitriyLewen Oct 14, 2025
35db88c
feat(sbom): use SPDX license IDs list to validate SPDX IDs (#9569)
DmitriyLewen Oct 14, 2025
804ea4a
fix(nodejs): use the default ID format to match licenses in pnpm pack…
DmitriyLewen Oct 14, 2025
84a7d9a
feat: add ArtifactID field to uniquely identify scan targets (#9663)
knqyf263 Oct 15, 2025
8e6a7ff
feat(cli): Add trivy cloud suppport (#9637)
Oct 15, 2025
fcd8dcd
docs: add vulnerability database contribution guide (#9667)
knqyf263 Oct 16, 2025
fc976be
feat: add ReportID field to scan reports (#9670)
knqyf263 Oct 17, 2025
2c43425
fix(sbom): add `buildInfo` info as properties (#9683)
DmitriyLewen Oct 20, 2025
559fe1f
refactor(cli): Update the cloud config command (#9676)
Oct 20, 2025
263aee0
test: update golden files for TestRepository* integration tests (#9684)
nikpivkin Oct 20, 2025
c32ddfc
refactor(misconf): add ManifestFromYAML for unified manifest parsing …
nikpivkin Oct 21, 2025
197c9e1
feat(misconf): include map key in manifest snippet for diagnostics (#…
nikpivkin Oct 21, 2025
7ca1b8f
ci: use merge commit for apidiff to avoid false positives (#9622)
knqyf263 Oct 22, 2025
43a7546
feat(misconf): Update Azure Container Schema (#9673)
yagreut Oct 22, 2025
68ca612
chore(deps): bump github.com/quic-go/quic-go from 0.52.0 to 0.54.1 (#…
yuzichen12123 Oct 22, 2025
a9a3031
feat(image): add RepoTags support for Docker archives (#9690)
knqyf263 Oct 22, 2025
807bbbd
refactor(misconf): type-safe parser results in generic scanner (#9685)
nikpivkin Oct 22, 2025
fa6f779
fix: close all opened resources if an error occurs (#9665)
fabriziosestito Oct 23, 2025
231492d
fix(nodejs): fix npmjs parser.pkgNameFromPath() panic issue (#9688)
derekhjray Oct 23, 2025
a282228
refactor(misconf): mark AVDID fields as deprecated and use ID interna…
nikpivkin Oct 23, 2025
e0c0416
ci: get base_sha using base.ref (#9704)
DmitriyLewen Oct 23, 2025
a6010c3
test: improve golden file management in integration tests (#9699)
knqyf263 Oct 24, 2025
d20216e
fix(report): correct field order in SARIF license results (#9712)
nikpivkin Oct 27, 2025
3cf4bfd
docs: add info about `java-db` subdir (#9706)
DmitriyLewen Oct 27, 2025
39051b7
docs: update vulnerability reporting guidelines in SECURITY.md (#9395)
knqyf263 Oct 28, 2025
fb0593b
fix(sbom): don’t panic on SBOM format if scanned CycloneDX file has e…
DmitriyLewen Oct 28, 2025
eff52eb
feat(java): add support remote repositories from settings.xml files (…
DmitriyLewen Oct 28, 2025
758f271
feat: include registry and repository in artifact ID calculation (#9689)
knqyf263 Oct 28, 2025
89fc7b6
refactor: add case-insensitive string set implementation (#9720)
knqyf263 Oct 29, 2025
212f078
fix(license): handle SPDX WITH exceptions as single license in catego…
DmitriyLewen Oct 29, 2025
29f0347
fix(os): Add photon 5.0 in supported OS (#9724)
u5surf Oct 30, 2025
d020f26
feat(report): add image reference to report metadata (#9729)
knqyf263 Oct 31, 2025
3fb8703
feat(misconf): Add RoleAssignments attribute (#9396)
yagreut Oct 31, 2025
445cd2b
feat(misconf): Add support for configurable Rego error limit (#9657)
simar7 Oct 31, 2025
18c0ee8
feat(dotnet): add dependency graph support for .deps.json files (#9726)
alexinslc Nov 1, 2025
012f3d7
feat(license): use separate SPDX ids to ignore SPDX expressions (#9087)
yutatokoi Nov 1, 2025
bf43629
fix(flag): remove viper.SetDefault to fix IsSet() for config-only fla…
knqyf263 Nov 3, 2025
c03facf
chore(deps): bump the github-actions group with 4 updates (#9739)
dependabot[bot] Nov 3, 2025
2690ac9
feat(image): pass global context to docker/podman image save func (#9…
derekhjray Nov 4, 2025
58819c5
feat(misconf): Update SecurityCenter schema (#9674)
yagreut Nov 4, 2025
c3bfecf
feat(misconf): Update azure storage schema (#9728)
yagreut Nov 4, 2025
cb58bf6
feat(misconf): Update Azure Compute schema (#9675)
yagreut Nov 4, 2025
6fb3fde
feat(report): switch ReportID from UUIDv4 to UUIDv7 (#9749)
knqyf263 Nov 5, 2025
69f400c
feat(misconf): add agentpools to azure container schema (#9714)
yagreut Nov 5, 2025
d70d994
feat(db): enable concurrent access to vulnerability database (#9750)
knqyf263 Nov 6, 2025
14ecdb5
docs: change SecObserve URLs in documentatio (#9771)
StefanFl Nov 10, 2025
0487d8e
docs: add info that `SSL_CERT_FILE` works on `Unix systems other than…
DmitriyLewen Nov 10, 2025
d87d9b9
fix(java): use `true` as default value for Repository Release|Snapsho…
DmitriyLewen Nov 10, 2025
be419c7
chore(deps): bump github.com/containerd/containerd/v2 from 2.1.4 to 2…
dependabot[bot] Nov 10, 2025
2ce48c7
chore(deps): bump github.com/opencontainers/selinux from 1.12.0 to 1.…
dependabot[bot] Nov 11, 2025
2c3aca5
docs: Fix typos and linguistic errors in documentation / hacktoberfes…
survivant Nov 11, 2025
09ea608
test(go): refactor mod_test.go to use txtar format (#9775)
knqyf263 Nov 11, 2025
08d51a8
fix(misconf): handle unsupported experimental flags in Dockerfile (#9…
nikpivkin Nov 11, 2025
6048173
feat(flag): add `--cacert` flag (#9781)
DmitriyLewen Nov 12, 2025
3a2a31d
test(go): set `GOPATH` for tests (#9785)
DmitriyLewen Nov 12, 2025
019af7f
feat(suse): Add new openSUSE, Micro and SLES releases end of life dat…
dirkmueller Nov 12, 2025
738b2b4
fix: update all documentation links (#9777)
thekovic Nov 13, 2025
612ee98
chore: trigger the trivy-www workflow (#9737)
Nov 13, 2025
cbad9ca
feat(report): add fingerprint generation for vulnerabilities (#9794)
knqyf263 Nov 17, 2025
31218f6
ci: remove unused preinstalled software/images for build tests to fre…
DmitriyLewen Nov 18, 2025
f64e0da
docs(server): fix info about scanning licenses on the client side. (#…
DmitriyLewen Nov 18, 2025
9da33b5
docs: restructure docs for new hosting (#9799)
Nov 18, 2025
c8d5ab7
feat(misconf): support https_traffic_only_enabled in Az storage accou…
nikpivkin Nov 19, 2025
a6ceff7
fix(misconf): ensure boolean metadata values are correctly interprete…
nikpivkin Nov 19, 2025
c6d95d7
feat(misconf): Update AppService schema (#9792)
yagreut Nov 19, 2025
ea2dc58
feat(misconf): Update Azure network schema for new checks (#9791)
yagreut Nov 19, 2025
5c42cc5
docs(misconf): Remove duplicate sections (#9819)
askpatrickw Nov 20, 2025
d8eaaeb
feat(sbom): add support for SPDX attestations (#9829)
knqyf263 Nov 21, 2025
3169ebf
chore(deps): bump github.com/containerd/containerd from 1.7.28 to 1.7…
dependabot[bot] Nov 21, 2025
5f9b695
test(k8s): update k8s integrtion test (#9725)
afdesk Nov 24, 2025
8876b46
chore(deps): bump the aws group with 7 updates (#9691)
dependabot[bot] Nov 25, 2025
e1f3f28
feat(image): add Sigstore bundle SBOM support (#9516)
RingoDev Nov 25, 2025
8967622
chore(deps): bump the common group across 1 directory with 20 updates…
dependabot[bot] Nov 25, 2025
e13d970
chore(deps): bump golang.org/x/crypto from 0.41.0 to 0.45.0 (#9827)
dependabot[bot] Nov 25, 2025
f5bbb0b
chore(deps): bump the docker group with 3 updates (#9776)
dependabot[bot] Nov 25, 2025
7b2b4d4
fix(misconf): map healthcheck start period flag to --start-period ins…
nikpivkin Nov 26, 2025
7aca801
fix(misconf): ensure value used as ignore marker is non-null and know…
nikpivkin Nov 26, 2025
96e7083
chore(cli): Remove Trivy Cloud (#9847)
Nov 26, 2025
51de2bd
refactor(misconf): parse azure_policy_enabled to addonprofile.azurepo…
nikpivkin Nov 27, 2025
15a5465
docs: catch some missed docs -> guide (#9850)
Nov 27, 2025
c274f5b
fix(vex): use a separate `visited` set for each DFS path (#9760)
DmitriyLewen Dec 1, 2025
e74e2b1
feat(aws): Add support for dualstack ECR endpoints (#9862)
fischaz Dec 2, 2025
e0fa76d
release: v0.68.0 [main] (#9549)
aqua-bot Dec 2, 2025
b503278
chore(deps): bump the testcontainers group with 2 updates (#9506)
dependabot[bot] Dec 3, 2025
c7accc8
fix: update cosing settings for GoReleaser after bumping cosing to v3…
DmitriyLewen Dec 3, 2025
96290ae
release: v0.68.1 [main] (#9867)
aqua-bot Dec 3, 2025
32f3df1
chore: update the install script (#9874)
Dec 3, 2025
7517112
ci(helm): bump Trivy version to 0.68.1 for Trivy Helm Chart 0.20.0 (#…
aqua-bot Dec 4, 2025
48dfede
feat(misconf): Update Azure Database schema (#9811)
yagreut Dec 5, 2025
9275e15
feat(misconf): initial ansible scanning support (#9332)
nikpivkin Dec 5, 2025
c2f82ad
feat(julia): enable vulnerability scanning for the Julia language eco…
mbauman Dec 5, 2025
9db123c
fix: remove trailing tab in statefulset template (#9889)
ThommyH Dec 8, 2025
39273f3
chore(deps): bump github.com/docker/cli from 29.0.3+incompatible to 2…
dependabot[bot] Dec 8, 2025
f58826f
chore(deps): bump the common group across 1 directory with 9 updates …
dependabot[bot] Dec 9, 2025
56b59e8
feat(php): add support for dev dependencies in Composer (#9910)
knqyf263 Dec 9, 2025
18ecf75
fix(misconf): respect .yml files when Helm charts are detected (#9912)
nikpivkin Dec 9, 2025
879e4fc
feat(helm): add sslCertDir parameter (#9697)
Dec 9, 2025
335cc99
fix(vex): add CVE-2025-66564 as not_affected into Trivy VEX file (#9924)
DmitriyLewen Dec 10, 2025
effc1c0
feat(debian): detect third-party packages using maintainer list (#9917)
knqyf263 Dec 11, 2025
1a901e5
ci: enable `check-latest` for `setup-go` (#9931)
DmitriyLewen Dec 11, 2025
d65b504
feat(cloudformation): add support for Fn::ForEach (#9508)
nikpivkin Dec 11, 2025
f50b96a
chore(alpine): add EOL date for alpine 3.23 (#9934)
DmitriyLewen Dec 12, 2025
d528250
chore(deps): bump alpine from `3.22.1` to `3.23.0` (#9935)
DmitriyLewen Dec 12, 2025
718ec29
docs: update binary signature verification for sigstore bundles (#9929)
igoradulian Dec 12, 2025
5eda0a4
chore(deps): bump github.com/quic-go/quic-go from 0.54.1 to 0.57.0 (#…
dependabot[bot] Dec 17, 2025
8777252
ci(helm): bump Trivy version to 0.68.2 for Trivy Helm Chart 0.20.1 (#…
aqua-bot Dec 17, 2025
75c4dc0
chore: add client option to install script (#9962)
Dec 19, 2025
10a50a7
perf(misconf): optimize string concatenation in azure scanner (#9969)
ankit98040 Dec 22, 2025
56f93a1
docs: add info that `--file-pattern` flag doesn't disable default beh…
DmitriyLewen Dec 22, 2025
74819bf
feat(vuln): skip vulnerability scanning for third-party packages in D…
knqyf263 Dec 22, 2025
d3096e7
feat(rootio): Update trivy db to support usage of Severity from root.…
urimils Dec 22, 2025
7a6594c
chore(deps): bump `golang.org/x/tools` to `v0.40.0` + `gopls` to `v0.…
DmitriyLewen Dec 22, 2025
517365c
refactor(debian): use txtar format for test data (#9957)
knqyf263 Dec 23, 2025
4caf731
feat(flag): add JSON Schema for trivy.yaml configuration file (#9971)
knqyf263 Dec 23, 2025
18acf4f
fix(image): race condition in image artifact inspection (#9966)
jinroh Dec 25, 2025
93915dc
refactor: add xslices.Map and replace lo.Map usages (#9984)
knqyf263 Dec 26, 2025
43d4e55
chore: update reference links to Go Wiki (#9987)
nikpivkin Dec 26, 2025
b64d5ad
feat(nodejs): parse licenses from `package-lock.json` file (#9983)
DmitriyLewen Dec 29, 2025
11dd3fa
fix(license): normalize licenses for PostAnalyzers (#9941)
DmitriyLewen Dec 29, 2025
b46cde0
fix(vuln): skip vulns detection for CentOS Stream family without scan…
amitverse Dec 29, 2025
08a3f92
test: fix assertion after 2026 roll over (#10002)
cdupuis Jan 5, 2026
60eb3f0
chore(deps): bump the github-actions group with 11 updates (#10001)
dependabot[bot] Jan 5, 2026
7f71b57
fix(docker): fix non-det scan results for images with embedded SBOM (…
AndreOganesian Jan 12, 2026
07ff788
feat(sbom): exclude PEP 770 SBOMs in .dist-info/sboms/ (#10033)
knqyf263 Jan 12, 2026
c5b8fef
docs: fix incorrect documentation URLs (#10038)
DmitriyLewen Jan 13, 2026
4e06c3d
fix: move enum into items for array-type fields in JSON Schema (#10039)
knqyf263 Jan 13, 2026
6462dc8
refactor(misconf)!: use ID instead of AVDID for providers mapping (#9…
nikpivkin Jan 13, 2026
f0e23ea
chore: switch to ID from AVDID in internal and user-facing fields (#9…
nikpivkin Jan 13, 2026
3c0ab97
fix(go): use ldflags version for all pseudo-versions (#10037)
DmitriyLewen Jan 13, 2026
cdb28ee
fix(secret): improve word boundary detection for Hugging Face tokens …
DmitriyLewen Jan 14, 2026
c3373b1
chore(deps): bump github.com/sigstore/cosign/v2 from 2.2.4 to 2.6.2 (…
dependabot[bot] Jan 14, 2026
51f5412
test: migrate private test helpers to `export_test.go` convention (#1…
DmitriyLewen Jan 14, 2026
37b5da8
feat(misconf): support for azurerm_*_web_app (#9944)
nikpivkin Jan 14, 2026
92d3465
feat(misconf): support for ARM resources defined as an object (#9959)
nikpivkin Jan 14, 2026
a0ecc8e
fix(misconf): safely parse rotation_period in google_kms_crypto_key (…
nikpivkin Jan 14, 2026
8c23bfd
test(misconf): simplify test values using *Test helpers (#9985)
nikpivkin Jan 14, 2026
ac061f8
fix(misconf): correct typos in block and attribute names (#9993)
nikpivkin Jan 14, 2026
b06ef6d
feat(misconf): add action block to Terraform schema (#10035)
nikpivkin Jan 14, 2026
5fced3a
feat(misconf): use Terraform plan configuration to partially restore …
nikpivkin Jan 14, 2026
809db46
fix(java): add hash of GAV+root pom file path for pkgID for packages …
DmitriyLewen Jan 15, 2026
5602951
refactor(misconf): move common logic to base value and simplify typed…
nikpivkin Jan 16, 2026
34baef2
feat(secret): add detection for Symfony default secret key (#9892)
murataslan1 Jan 16, 2026
5bb6540
docs: fix link to Docker Image Specification (#10057)
priteau Jan 19, 2026
c233735
fix: use canonical SPDX license IDs from embeded licenses.json (#10053)
DmitriyLewen Jan 19, 2026
1953824
feat: add AnalyzedBy field to track which analyzer detected packages …
knqyf263 Jan 19, 2026
d2dc46a
fix(rust): add cargo workspace members glob support (#10032)
Shikachuu Jan 20, 2026
fe7d20a
feat(report): add Trivy version to JSON output (#10065)
knqyf263 Jan 20, 2026
bf860cd
docs: fix mistake in config file example for skip-dirs/skip-files fla…
DmitriyLewen Jan 20, 2026
8025e90
chore(deps): bump github.com/theupdateframework/go-tuf/v2 from 2.3.0 …
dependabot[bot] Jan 22, 2026
31c4780
feat(rocky): enable modular package vulnerability detection (#10069)
knqyf263 Jan 22, 2026
b9415a3
fix(java): correctly propagate repositories from upper POMs to depend…
DmitriyLewen Jan 22, 2026
5d76153
chore(deps): bump github.com/sigstore/sigstore from 1.10.3 to 1.10.4 …
dependabot[bot] Jan 23, 2026
8b46122
chore(deps): bump github.com/sigstore/rekor from 1.4.3 to 1.5.0 (#10084)
dependabot[bot] Jan 23, 2026
f97ac7e
refactor: allow per-request transport options override (#10083)
knqyf263 Jan 23, 2026
f809066
feat(vex): support per-repo tls configuration (#10030)
alegrey91 Jan 24, 2026
676709d
feat(activestate): add support ActiveState images (#10081)
DmitriyLewen Jan 29, 2026
47d3103
fix(rust): implement version inheritance for Cargo mono repos (#10011)
Shikachuu Jan 29, 2026
2933b01
fix(java): correctly inherit properties from parent fields for pom.xm…
DmitriyLewen Jan 30, 2026
036c05b
fix(repo): return a nil interface for gitAuth if missing (#10097)
Riolku Jan 30, 2026
f00f8de
chore(deps): bump github.com/theupdateframework/go-tuf/v2 from 2.3.1 …
dependabot[bot] Jan 30, 2026
ba9feb6
chore: bump trivy-checks to v2 (#9875)
nikpivkin Jan 30, 2026
8fb9191
release: v0.69.0 [main] (#9886)
aqua-bot Jan 30, 2026
b9a8d2d
fix(server): exclude JavaDB and CheckBundle from /version endpoint (#…
knqyf263 Jan 30, 2026
cc64eeb
chore(deps): bump the aws group across 1 directory with 6 updates (#1…
dependabot[bot] Jan 30, 2026
1a72b32
feat(python): add pylock.toml (PEP 751) parser (#9632)
sneaky-potato Jan 30, 2026
65e151f
refactor(rust): use txtar format for cargo analyzer test data (#10104)
knqyf263 Jan 30, 2026
9a3e0a8
fix(java): Disable overwriting exclusions (#10088)
eschcam Jan 30, 2026
73c64af
ci(helm): bump Trivy version to 0.69.0 for Trivy Helm Chart 0.21.0 (#…
aqua-bot Jan 31, 2026
fc5f139
refactor: unify scanner error limit and compiler limit (#10106)
nikpivkin Feb 2, 2026
7415661
chore(deps): bump to alpine:3.23.3 and go-1.25.6 to fix CVEs (#10107)
sastorsl Feb 2, 2026
4c46d41
feat(server): include server version info in JSON output for client/s…
knqyf263 Feb 2, 2026
fa195b4
fix: update PhotonOS feed URL (#10122)
carrodher Feb 3, 2026
8d3d4ee
docs(terraform): add limitation for data sources and computed resourc…
nikpivkin Feb 4, 2026
b775a1b
fix(misconf): apply check aliases when filtering results via .trivyig…
nikpivkin Feb 4, 2026
5ffcdfc
ci: add composite action for Go setup (#10146)
knqyf263 Feb 5, 2026
d6e6331
feat(vuln): skip third-party packages in common Detect function (#10129)
knqyf263 Feb 5, 2026
82019c3
docs: update version endpoint example in client/server documentation …
Yamamoto-Ko-ki Feb 5, 2026
66bdec4
feat(misconf): adapt ARM k8s clusters (#9696) (#10125)
AndrewCharlesHay Feb 6, 2026
0b73503
refactor: reduce complexity of init in detect.go (#10163)
AndrewCharlesHay Feb 7, 2026
68c196f
refactor: remove unused Insecure field from ServiceOption (#10113)
BrajamohanDas-afk Feb 9, 2026
580c4ac
ci(helm): bump Trivy version to 0.69.1 for Trivy Helm Chart 0.21.1 (#…
aqua-bot Feb 9, 2026
823f363
feat(misconf): resolve Azure resources via resource_id (#10173)
Dharma-09 Feb 9, 2026
8662089
chore(deps): bump github.com/go-git/go-git/v5 from 5.16.4 to 5.16.5 (…
dependabot[bot] Feb 10, 2026
42216b5
docs: fix incorrect count of Python package managers (#10175)
valentinstn Feb 10, 2026
2c1f65b
feat(ubuntu): add eol data for 25.10 (#10181)
DmitriyLewen Feb 10, 2026
0f0d6db
fix(misconf): initialize custom annotation field if empty (#10123)
nikpivkin Feb 10, 2026
3a3d750
test: update Docker Engine integration tests for Docker API v0.29.0+ …
DmitriyLewen Feb 17, 2026
fb05196
chore(deps): update Docker client SDK to v29 (#10202)
DmitriyLewen Feb 18, 2026
1c09181
chore(deps): bump the common group across 1 directory with 24 updates…
dependabot[bot] Feb 18, 2026
5b54388
docs: migrate private registry documentation from GCR to GAR (#10208)
yusuke-koyoshi Feb 19, 2026
7acb5f6
feat(go): detect version from ELF symbol table for binaries built wit…
knqyf263 Feb 19, 2026
65f6650
[VULN-59766] chore(deps): remove direct dependency on github.com/dock…
L3n41c Apr 2, 2026
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
The table of contents is too big for display.
Diff view
Diff view
  •  
  •  
  •  
The diff you're trying to view is too large. We only load the first 3000 changed files.
50 changes: 0 additions & 50 deletions .circleci/config.yml

This file was deleted.

5 changes: 5 additions & 0 deletions .dockerignore
Original file line number Diff line number Diff line change
@@ -1 +1,6 @@
.git
.github
.cache
.circleci
integration
imgs
1 change: 1 addition & 0 deletions .gitattributes
Original file line number Diff line number Diff line change
@@ -0,0 +1 @@
* text=auto eol=lf
22 changes: 22 additions & 0 deletions .github/CODEOWNERS
Original file line number Diff line number Diff line change
@@ -0,0 +1,22 @@
# Global
* @knqyf263

# SBOM/Vulnerability scanning
pkg/dependency/ @knqyf263 @DmitriyLewen
pkg/fanal/ @knqyf263 @DmitriyLewen
pkg/sbom/ @knqyf263 @DmitriyLewen
pkg/scanner/ @knqyf263 @DmitriyLewen

# Misconfiguration scanning
docs/guide/scanner/misconfiguration/ @simar7 @nikpivkin
docs/guide/target/aws.md @simar7 @nikpivkin
pkg/fanal/analyzer/config/ @simar7 @nikpivkin
pkg/config/aws/ @simar7 @nikpivkin
pkg/iac/ @simar7 @nikpivkin

# Helm chart
helm/trivy/ @afdesk @simar7

# Kubernetes scanning
pkg/k8s/ @afdesk @simar7
docs/guide/target/kubernetes.md @afdesk @simar7
47 changes: 47 additions & 0 deletions .github/DISCUSSION_TEMPLATE/adopters.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,47 @@
title: "<company name>"
labels: ["adopters"]
body:
- type: textarea
id: info
attributes:
label: "[Optional] How do you use Trivy?"
validations:
required: false
- type: textarea
id: info
attributes:
label: "[Optional] Can you provide us with a quote on your favourite part of Trivy? This may be used on the trivy.dev website, posted on Twitter (@AquaTrivy) or similar marketing material."
validations:
required: false
- type: checkboxes
attributes:
label: "[Optional] Which targets are you scanning with Trivy?"
options:
- label: "Container Image"
- label: "Filesystem"
- label: "Git Repository"
- label: "Virtual Machine Image"
- label: "Kubernetes"
- label: "AWS"
- label: "SBOM"
validations:
required: false
- type: checkboxes
attributes:
label: "[Optional] What kind of issues are scanning with Trivy?"
options:
- label: "Software Bill of Materials (SBOM)"
- label: "Known vulnerabilities (CVEs)"
- label: "IaC issues and misconfigurations"
- label: "Sensitive information and secrets"
- label: "Software licenses"
- type: markdown
attributes:
value: |
## Get in touch
We are always looking for
* User feedback
* Collaboration with other companies and organisations
* Or just to have a chat with you about trivy.
If any of this interests you or your marketing team, please reach out at: oss@aquasec.com
We would love to hear from you!
124 changes: 124 additions & 0 deletions .github/DISCUSSION_TEMPLATE/bugs.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,124 @@
labels: ["kind/bug"]
body:
- type: markdown
attributes:
value: |
#### Note
Feel free to raise a bug report if something doesn't work as expected.
Please ensure that you're not creating a duplicate report by searching the [issues](https://github.com/aquasecurity/trivy/issues)/[discussions](https://github.com/aquasecurity/trivy/discussions) beforehand.
If you see any false positives or false negatives, please file a ticket [here](https://github.com/aquasecurity/trivy/discussions/new?category=false-detection).

**Do not open a GitHub issue, please.** Maintainers triage discussions and then create issues.

Please also check [our contribution guidelines](https://trivy.dev/docs/latest/community/contribute/discussion/).
- type: textarea
attributes:
label: Description
description: Briefly describe the problem you are having in a few paragraphs.
validations:
required: true
- type: textarea
attributes:
label: Desired Behavior
description: What did you expect to happen?
validations:
required: true
- type: textarea
attributes:
label: Actual Behavior
description: What happened instead?
validations:
required: true
- type: textarea
attributes:
label: Reproduction Steps
description: How do you trigger this bug? Please walk us through it step by step.
value: |
1.
2.
3.
...
render: bash
validations:
required: true
- type: dropdown
attributes:
label: Target
description: Which target are you scanning? It is equal to which subcommand you are using.
options:
- Container Image
- Filesystem
- Git Repository
- Virtual Machine Image
- Kubernetes
- AWS
- SBOM
validations:
required: false
- type: dropdown
attributes:
label: Scanner
description: Which scanner are you using?
options:
- Vulnerability
- Misconfiguration
- Secret
- License
validations:
required: false
- type: dropdown
attributes:
label: Output Format
description: Which output format are you using?
options:
- Table
- JSON
- Template
- SARIF
- CycloneDX
- SPDX
validations:
required: false
- type: dropdown
attributes:
label: Mode
description: Which mode are you using? Specify "Standalone" if you are not using `trivy server`.
options:
- Standalone
- Client/Server
validations:
required: false
- type: textarea
attributes:
label: Debug Output
description: Output of run with `--debug`
placeholder: "$ trivy <target> <subject> --debug"
render: bash
validations:
required: true
- type: input
attributes:
label: Operating System
description: On what operating system are you running Trivy?
placeholder: "e.g. macOS Big Sur"
validations:
required: true
- type: textarea
attributes:
label: Version
description: Output of `trivy --version`
placeholder: "$ trivy --version"
render: bash
validations:
required: true
- type: checkboxes
attributes:
label: Checklist
description: Have you tried the following?
options:
- label: Run `trivy clean --all`
- label: Read [the troubleshooting](https://trivy.dev/docs/latest/references/troubleshooting/)
- type: markdown
attributes:
value: |
We would be happy if you could share how you are using Trivy [here](https://github.com/aquasecurity/trivy/discussions/new?category=adopters).
28 changes: 28 additions & 0 deletions .github/DISCUSSION_TEMPLATE/documentation.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,28 @@
labels: ["kind/documentation"]
body:
- type: markdown
attributes:
value: |
#### Note
Feel free to create a docs report if something doesn't work as expected or is unclear in the documentation.
Please ensure that you're not creating a duplicate report by searching the [issues](https://github.com/aquasecurity/trivy/issues)/[discussions](https://github.com/aquasecurity/trivy/discussions) beforehand.

Please also check [our contribution guidelines](https://trivy.dev/docs/latest/community/contribute/discussion/).
- type: textarea
attributes:
label: Description
description: Briefly describe the what has been unclear in the existing documentation
validations:
required: true
- type: textarea
attributes:
label: Link
description: Please provide a link to the current documentation or where you thought to find the information you were looking for
validations:
required: false
- type: textarea
attributes:
label: Suggestions
description: What would you like to have added or changed in the documentation?
validations:
required: true
96 changes: 96 additions & 0 deletions .github/DISCUSSION_TEMPLATE/false-detection.yml
Original file line number Diff line number Diff line change
@@ -0,0 +1,96 @@
body:
- type: markdown
attributes:
value: |
#### Note
Feel free to raise a bug report if something doesn't work as expected.
Please ensure that you're not creating a duplicate report by searching the [issues](https://github.com/aquasecurity/trivy/issues)/[discussions](https://github.com/aquasecurity/trivy/discussions) beforehand.

**Do not open a GitHub issue, please.** Maintainers triage discussions and then create issues.

Please also check [our contribution guidelines](https://trivy.dev/docs/latest/community/contribute/discussion/).
- type: input
attributes:
label: IDs
description: List the IDs of vulnerabilities, misconfigurations, secrets, or licenses that are either not detected or mistakenly detected.
placeholder: "e.g. CVE-2021-44228, CVE-2022-22965"
validations:
required: true
- type: textarea
attributes:
label: Description
description: Describe the false detection.
validations:
required: true
- type: textarea
attributes:
label: Reproduction Steps
description: How do you trigger this bug? Please walk us through it step by step.
value: |
1.
2.
3.
...
render: bash
validations:
required: true
- type: dropdown
attributes:
label: Target
description: Which target are you scanning? It is equal to which subcommand you are using.
options:
- Container Image
- Filesystem
- Git Repository
- Virtual Machine Image
- Kubernetes
- AWS
- SBOM
validations:
required: true
- type: dropdown
attributes:
label: Scanner
description: Which scanner are you using?
options:
- Vulnerability
- Misconfiguration
- Secret
- License
validations:
required: true
- type: input
attributes:
label: Target OS
description: What operating system are you scanning? Fill in this field if the scanning target is an operating system.
placeholder: "Example: Ubuntu 22.04"
validations:
required: false
- type: textarea
attributes:
label: Debug Output
description: Output of run with `--debug`
placeholder: "$ trivy <target> <subject> --debug"
render: bash
validations:
required: true
- type: textarea
attributes:
label: Version
description: Output of `trivy --version`
placeholder: "$ trivy --version"
render: bash
validations:
required: true
- type: checkboxes
attributes:
label: Checklist
options:
- label: Read [the documentation regarding wrong detection](https://trivy.dev/docs/latest/community/contribute/discussion/#false-detection)
- label: Ran Trivy with `-f json` that shows data sources and confirmed that the security advisory in data sources was correct
validations:
required: true
- type: markdown
attributes:
value: |
We would be happy if you could share how you are using Trivy [here](https://github.com/aquasecurity/trivy/discussions/new?category=adopters).
Loading