Skip to content

Commit ac0d54f

Browse files
chore(deps): bump the trivy group with 2 updates (#2402)
Bumps the trivy group with 2 updates: [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy) and [github.com/aquasecurity/trivy-db](https://github.com/aquasecurity/trivy-db). Updates `github.com/aquasecurity/trivy` from 0.68.2 to 0.69.0 - [Release notes](https://github.com/aquasecurity/trivy/releases) - [Changelog](https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md) - [Commits](aquasecurity/trivy@v0.68.2...v0.69.0) Updates `github.com/aquasecurity/trivy-db` from 0.0.0-20250929072116-eba1ced2340a to 0.0.0-20251222105351-a833f47f8f0d - [Release notes](https://github.com/aquasecurity/trivy-db/releases) - [Commits](https://github.com/aquasecurity/trivy-db/commits) --- updated-dependencies: - dependency-name: github.com/aquasecurity/trivy dependency-version: 0.69.0 dependency-type: direct:production update-type: version-update:semver-minor dependency-group: trivy - dependency-name: github.com/aquasecurity/trivy-db dependency-version: 0.0.0-20251222105351-a833f47f8f0d dependency-type: direct:production update-type: version-update:semver-patch dependency-group: trivy ... Signed-off-by: dependabot[bot] <support@github.com> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
1 parent 28af642 commit ac0d54f

2 files changed

Lines changed: 184 additions & 184 deletions

File tree

go.mod

Lines changed: 50 additions & 50 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,6 @@
11
module github.com/future-architect/vuls
22

3-
go 1.25
3+
go 1.25.5
44

55
require (
66
github.com/Azure/azure-sdk-for-go/sdk/storage/azblob v1.6.4
@@ -9,8 +9,8 @@ require (
99
github.com/MaineK00n/vuls-data-update v0.0.0-20251125094749-e6f7ed9f8ca3
1010
github.com/MaineK00n/vuls2 v0.0.1-alpha.0.20260130013332-a13a8cff2129
1111
github.com/Ullaakut/nmap/v2 v2.2.2
12-
github.com/aquasecurity/trivy v0.68.2
13-
github.com/aquasecurity/trivy-db v0.0.0-20250929072116-eba1ced2340a
12+
github.com/aquasecurity/trivy v0.69.0
13+
github.com/aquasecurity/trivy-db v0.0.0-20251222105351-a833f47f8f0d
1414
github.com/aquasecurity/trivy-java-db v0.0.0-20240109071736-184bd7481d48
1515
github.com/asaskevich/govalidator v0.0.0-20230301143203-a9d515a09cc2
1616
github.com/aws/aws-sdk-go-v2 v1.41.1
@@ -69,12 +69,12 @@ require (
6969
require (
7070
cel.dev/expr v0.24.0 // indirect
7171
cloud.google.com/go v0.121.6 // indirect
72-
cloud.google.com/go/auth v0.17.0 // indirect
72+
cloud.google.com/go/auth v0.18.0 // indirect
7373
cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
7474
cloud.google.com/go/compute/metadata v0.9.0 // indirect
7575
cloud.google.com/go/iam v1.5.3 // indirect
76-
cloud.google.com/go/monitoring v1.24.2 // indirect
77-
cloud.google.com/go/storage v1.56.0 // indirect
76+
cloud.google.com/go/monitoring v1.24.3 // indirect
77+
cloud.google.com/go/storage v1.57.1 // indirect
7878
dario.cat/mergo v1.0.2 // indirect
7979
filippo.io/edwards25519 v1.1.0 // indirect
8080
github.com/Azure/azure-sdk-for-go/sdk/azcore v1.20.0 // indirect
@@ -84,9 +84,9 @@ require (
8484
github.com/Azure/go-ansiterm v0.0.0-20250102033503-faa5f7b0171c // indirect
8585
github.com/AzureAD/microsoft-authentication-library-for-go v1.6.0 // indirect
8686
github.com/GoogleCloudPlatform/docker-credential-gcr/v2 v2.1.30 // indirect
87-
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.29.0 // indirect
88-
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.53.0 // indirect
89-
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.53.0 // indirect
87+
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.30.0 // indirect
88+
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.54.0 // indirect
89+
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.54.0 // indirect
9090
github.com/MaineK00n/go-cisco-version v0.0.0-20250909032920-fe1559e481f8 // indirect
9191
github.com/MaineK00n/go-paloalto-version v0.0.0-20250909032857-57479910413b // indirect
9292
github.com/MakeNowJust/heredoc v1.0.0 // indirect
@@ -111,7 +111,7 @@ require (
111111
github.com/aquasecurity/go-version v0.0.1 // indirect
112112
github.com/aquasecurity/iamgo v0.0.10 // indirect
113113
github.com/aquasecurity/jfather v0.0.8 // indirect
114-
github.com/aquasecurity/trivy-checks v1.11.3-0.20250604022615-9a7efa7c9169 // indirect
114+
github.com/aquasecurity/trivy-checks v1.12.2-0.20251219190323-79d27547baf5 // indirect
115115
github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.4 // indirect
116116
github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.17 // indirect
117117
github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.17 // indirect
@@ -141,7 +141,7 @@ require (
141141
github.com/clipperhouse/stringish v0.1.1 // indirect
142142
github.com/clipperhouse/uax29/v2 v2.3.0 // indirect
143143
github.com/cloudflare/circl v1.6.1 // indirect
144-
github.com/cncf/xds/go v0.0.0-20250501225837-2ac532fd4443 // indirect
144+
github.com/cncf/xds/go v0.0.0-20251022180443-0feb69152e9f // indirect
145145
github.com/containerd/containerd v1.7.29 // indirect
146146
github.com/containerd/errdefs v1.0.0 // indirect
147147
github.com/containerd/log v0.1.0 // indirect
@@ -153,14 +153,14 @@ require (
153153
github.com/decred/dcrd/dcrec/secp256k1/v4 v4.4.0 // indirect
154154
github.com/dgryski/go-rendezvous v0.0.0-20200823014737-9f7001d12a5f // indirect
155155
github.com/dlclark/regexp2 v1.11.0 // indirect
156-
github.com/docker/cli v29.0.3+incompatible // indirect
156+
github.com/docker/cli v29.1.1+incompatible // indirect
157157
github.com/docker/distribution v2.8.3+incompatible // indirect
158158
github.com/docker/docker-credential-helpers v0.9.3 // indirect
159159
github.com/docker/go-units v0.5.0 // indirect
160160
github.com/dustin/go-humanize v1.0.1 // indirect
161161
github.com/emicklei/go-restful/v3 v3.13.0 // indirect
162162
github.com/emirpasic/gods v1.18.1 // indirect
163-
github.com/envoyproxy/go-control-plane/envoy v1.32.4 // indirect
163+
github.com/envoyproxy/go-control-plane/envoy v1.35.0 // indirect
164164
github.com/envoyproxy/protoc-gen-validate v1.2.1 // indirect
165165
github.com/evanphx/json-patch v5.9.11+incompatible // indirect
166166
github.com/exponent-io/jsonpath v0.0.0-20210407135951-1de76d718b3f // indirect
@@ -176,23 +176,23 @@ require (
176176
github.com/go-git/go-git/v5 v5.16.4 // indirect
177177
github.com/go-gorp/gorp/v3 v3.1.0 // indirect
178178
github.com/go-ini/ini v1.67.0 // indirect
179-
github.com/go-jose/go-jose/v4 v4.1.2 // indirect
179+
github.com/go-jose/go-jose/v4 v4.1.3 // indirect
180180
github.com/go-logr/logr v1.4.3 // indirect
181181
github.com/go-logr/stdr v1.2.2 // indirect
182-
github.com/go-openapi/jsonpointer v0.22.1 // indirect
183-
github.com/go-openapi/jsonreference v0.21.3 // indirect
184-
github.com/go-openapi/swag v0.25.1 // indirect
185-
github.com/go-openapi/swag/cmdutils v0.25.1 // indirect
186-
github.com/go-openapi/swag/conv v0.25.1 // indirect
187-
github.com/go-openapi/swag/fileutils v0.25.1 // indirect
188-
github.com/go-openapi/swag/jsonname v0.25.1 // indirect
189-
github.com/go-openapi/swag/jsonutils v0.25.1 // indirect
190-
github.com/go-openapi/swag/loading v0.25.1 // indirect
191-
github.com/go-openapi/swag/mangling v0.25.1 // indirect
192-
github.com/go-openapi/swag/netutils v0.25.1 // indirect
193-
github.com/go-openapi/swag/stringutils v0.25.1 // indirect
194-
github.com/go-openapi/swag/typeutils v0.25.1 // indirect
195-
github.com/go-openapi/swag/yamlutils v0.25.1 // indirect
182+
github.com/go-openapi/jsonpointer v0.22.4 // indirect
183+
github.com/go-openapi/jsonreference v0.21.4 // indirect
184+
github.com/go-openapi/swag v0.25.4 // indirect
185+
github.com/go-openapi/swag/cmdutils v0.25.4 // indirect
186+
github.com/go-openapi/swag/conv v0.25.4 // indirect
187+
github.com/go-openapi/swag/fileutils v0.25.4 // indirect
188+
github.com/go-openapi/swag/jsonname v0.25.4 // indirect
189+
github.com/go-openapi/swag/jsonutils v0.25.4 // indirect
190+
github.com/go-openapi/swag/loading v0.25.4 // indirect
191+
github.com/go-openapi/swag/mangling v0.25.4 // indirect
192+
github.com/go-openapi/swag/netutils v0.25.4 // indirect
193+
github.com/go-openapi/swag/stringutils v0.25.4 // indirect
194+
github.com/go-openapi/swag/typeutils v0.25.4 // indirect
195+
github.com/go-openapi/swag/yamlutils v0.25.4 // indirect
196196
github.com/go-redis/redis/v8 v8.11.5 // indirect
197197
github.com/go-sql-driver/mysql v1.9.3 // indirect
198198
github.com/go-stack/stack v1.8.1 // indirect
@@ -208,8 +208,8 @@ require (
208208
github.com/google/go-querystring v1.1.0 // indirect
209209
github.com/google/licenseclassifier/v2 v2.0.0 // indirect
210210
github.com/google/s2a-go v0.1.9 // indirect
211-
github.com/googleapis/enterprise-certificate-proxy v0.3.6 // indirect
212-
github.com/googleapis/gax-go/v2 v2.15.0 // indirect
211+
github.com/googleapis/enterprise-certificate-proxy v0.3.9 // indirect
212+
github.com/googleapis/gax-go/v2 v2.16.0 // indirect
213213
github.com/gopherjs/gopherjs v1.17.2 // indirect
214214
github.com/gorilla/websocket v1.5.4-0.20250319132907-e064f32e3674 // indirect
215215
github.com/gregjones/httpcache v0.0.0-20190611155906-901d90724c79 // indirect
@@ -244,7 +244,7 @@ require (
244244
github.com/lestrrat-go/dsig-secp256k1 v1.0.0 // indirect
245245
github.com/lestrrat-go/httpcc v1.0.1 // indirect
246246
github.com/lestrrat-go/httprc/v3 v3.0.1 // indirect
247-
github.com/lestrrat-go/jwx/v3 v3.0.11 // indirect
247+
github.com/lestrrat-go/jwx/v3 v3.0.12 // indirect
248248
github.com/lestrrat-go/option v1.0.1 // indirect
249249
github.com/lestrrat-go/option/v2 v2.0.0 // indirect
250250
github.com/lib/pq v1.10.9 // indirect
@@ -275,15 +275,16 @@ require (
275275
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
276276
github.com/mxk/go-flowrate v0.0.0-20140419014527-cca7078d478f // indirect
277277
github.com/ncruces/go-strftime v1.0.0 // indirect
278+
github.com/nikolalohinski/gonja/v2 v2.4.2 // indirect
278279
github.com/nsf/termbox-go v1.1.1 // indirect
279280
github.com/oklog/ulid/v2 v2.1.1 // indirect
280281
github.com/olekukonko/cat v0.0.0-20250911104152-50322a0618f6 // indirect
281282
github.com/olekukonko/errors v1.1.0 // indirect
282283
github.com/olekukonko/ll v0.1.4-0.20260115111900-9e59c2286df0 // indirect
283-
github.com/open-policy-agent/opa v1.10.1 // indirect
284+
github.com/open-policy-agent/opa v1.11.0 // indirect
284285
github.com/opencontainers/go-digest v1.0.0 // indirect
285286
github.com/opencontainers/image-spec v1.1.1 // indirect
286-
github.com/owenrumney/squealer v1.2.11 // indirect
287+
github.com/owenrumney/squealer v1.2.12 // indirect
287288
github.com/pandatix/go-cvss v0.6.2 // indirect
288289
github.com/pelletier/go-toml/v2 v2.2.4 // indirect
289290
github.com/peterbourgon/diskv v2.0.1+incompatible // indirect
@@ -293,7 +294,7 @@ require (
293294
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
294295
github.com/prometheus/client_golang v1.23.2 // indirect
295296
github.com/prometheus/client_model v0.6.2 // indirect
296-
github.com/prometheus/common v0.66.1 // indirect
297+
github.com/prometheus/common v0.67.4 // indirect
297298
github.com/prometheus/procfs v0.17.0 // indirect
298299
github.com/rcrowley/go-metrics v0.0.0-20250401214520-65e299d6c5c9 // indirect
299300
github.com/redis/rueidis v1.0.70 // indirect
@@ -306,7 +307,7 @@ require (
306307
github.com/samber/oops v1.18.1 // indirect
307308
github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 // indirect
308309
github.com/schollz/progressbar/v3 v3.19.0 // indirect
309-
github.com/segmentio/asm v1.2.0 // indirect
310+
github.com/segmentio/asm v1.2.1 // indirect
310311
github.com/sergi/go-diff v1.4.0 // indirect
311312
github.com/shopspring/decimal v1.4.0 // indirect
312313
github.com/skeema/knownhosts v1.3.2 // indirect
@@ -315,7 +316,7 @@ require (
315316
github.com/spf13/cast v1.10.0 // indirect
316317
github.com/spf13/pflag v1.0.10 // indirect
317318
github.com/spf13/viper v1.21.0 // indirect
318-
github.com/spiffe/go-spiffe/v2 v2.5.0 // indirect
319+
github.com/spiffe/go-spiffe/v2 v2.6.0 // indirect
319320
github.com/stretchr/objx v0.5.2 // indirect
320321
github.com/stretchr/testify v1.11.1 // indirect
321322
github.com/subosito/gotenv v1.6.0 // indirect
@@ -326,7 +327,7 @@ require (
326327
github.com/ulikunitz/xz v0.5.15 // indirect
327328
github.com/valyala/fastjson v1.6.4 // indirect
328329
github.com/vbatts/tar-split v0.12.2 // indirect
329-
github.com/vektah/gqlparser/v2 v2.5.30 // indirect
330+
github.com/vektah/gqlparser/v2 v2.5.31 // indirect
330331
github.com/vmihailenco/msgpack/v5 v5.4.1 // indirect
331332
github.com/vmihailenco/tagparser/v2 v2.0.0 // indirect
332333
github.com/x448/float16 v0.8.4 // indirect
@@ -338,19 +339,18 @@ require (
338339
github.com/yashtewari/glob-intersection v0.2.0 // indirect
339340
github.com/zclconf/go-cty v1.17.0 // indirect
340341
github.com/zclconf/go-cty-yaml v1.1.0 // indirect
341-
github.com/zeebo/errs v1.4.0 // indirect
342342
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
343-
go.opentelemetry.io/contrib/detectors/gcp v1.36.0 // indirect
344-
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.61.0 // indirect
343+
go.opentelemetry.io/contrib/detectors/gcp v1.38.0 // indirect
344+
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.63.0 // indirect
345345
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63.0 // indirect
346346
go.opentelemetry.io/otel v1.38.0 // indirect
347347
go.opentelemetry.io/otel/metric v1.38.0 // indirect
348348
go.opentelemetry.io/otel/sdk v1.38.0 // indirect
349349
go.opentelemetry.io/otel/sdk/metric v1.38.0 // indirect
350350
go.opentelemetry.io/otel/trace v1.38.0 // indirect
351351
go.uber.org/multierr v1.11.0 // indirect
352-
go.uber.org/zap v1.27.0 // indirect
353-
go.yaml.in/yaml/v2 v2.4.2 // indirect
352+
go.uber.org/zap v1.27.1 // indirect
353+
go.yaml.in/yaml/v2 v2.4.3 // indirect
354354
go.yaml.in/yaml/v3 v3.0.4 // indirect
355355
golang.org/x/crypto v0.46.0 // indirect
356356
golang.org/x/exp v0.0.0-20251219203646-944ab1f22d93 // indirect
@@ -359,12 +359,12 @@ require (
359359
golang.org/x/sys v0.40.0 // indirect
360360
golang.org/x/time v0.14.0 // indirect
361361
golang.org/x/tools v0.40.0 // indirect
362-
google.golang.org/api v0.254.0 // indirect
363-
google.golang.org/genproto v0.0.0-20250603155806-513f23925822 // indirect
364-
google.golang.org/genproto/googleapis/api v0.0.0-20250825161204-c5933d9347a5 // indirect
365-
google.golang.org/genproto/googleapis/rpc v0.0.0-20251022142026-3a174f9686a8 // indirect
366-
google.golang.org/grpc v1.76.0 // indirect
367-
google.golang.org/protobuf v1.36.10 // indirect
362+
google.golang.org/api v0.260.0 // indirect
363+
google.golang.org/genproto v0.0.0-20251202230838-ff82c1b0f217 // indirect
364+
google.golang.org/genproto/googleapis/api v0.0.0-20251202230838-ff82c1b0f217 // indirect
365+
google.golang.org/genproto/googleapis/rpc v0.0.0-20251222181119-0a764e51fe1b // indirect
366+
google.golang.org/grpc v1.78.0 // indirect
367+
google.golang.org/protobuf v1.36.11 // indirect
368368
gopkg.in/evanphx/json-patch.v4 v4.12.0 // indirect
369369
gopkg.in/inf.v0 v0.9.1 // indirect
370370
gopkg.in/warnings.v0 v0.1.2 // indirect
@@ -384,12 +384,12 @@ require (
384384
k8s.io/klog/v2 v2.130.1 // indirect
385385
k8s.io/kube-openapi v0.0.0-20250710124328-f3f2b991d03b // indirect
386386
k8s.io/kubectl v0.34.0 // indirect
387-
k8s.io/utils v0.0.0-20250604170112-4c0f3b243397 // indirect
387+
k8s.io/utils v0.0.0-20250820121507-0af2bda4dd1d // indirect
388388
modernc.org/libc v1.67.4 // indirect
389389
modernc.org/mathutil v1.7.1 // indirect
390390
modernc.org/memory v1.11.0 // indirect
391391
modernc.org/sqlite v1.42.2 // indirect
392-
mvdan.cc/sh/v3 v3.11.0 // indirect
392+
mvdan.cc/sh/v3 v3.12.0 // indirect
393393
oras.land/oras-go/v2 v2.6.0 // indirect
394394
sigs.k8s.io/json v0.0.0-20241014173422-cfa47c3a1cc8 // indirect
395395
sigs.k8s.io/kustomize/api v0.20.1 // indirect

0 commit comments

Comments
 (0)