Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v0.50.1
->v0.51.2
v2.10.6
->v2.11.1
v1.7.5
->v1.8.3
v3.14.3
->v3.15.0
v1.29.3
->v1.30.1
v1.32.0
->v1.33.1
v0.36.0
->v0.37.0
v0.50.3
->v0.51.1
Warning
Some dependencies could not be looked up. Check the Dependency Dashboard for more information.
Release Notes
aquasecurity/trivy (aquasecurity/trivy)
v0.51.2
Compare Source
Changelog
eadc6fb
fix: node-collector high and critical cves (#6707)cc489b1
Merge pull request from GHSA-xcq4-m2r3-cmrj013f71a
chore: auto-bump golang patch versions (#6711)113a5b2
fix(misconf): don't shift ignore rule related to code (#6708)733e5ac
fix(go): include only.version
|.ver
(no prefixes) ldflags forgobinaries
(#6705)d311e49
fix(go): add only non-empty root modules forgobinaries
(#6710)cf1a7bf
refactor: unify package addition and vulnerability scanning (#6579)d465d9d
fix: Golang version parsing from binaries w/GOEXPERIMENT (#6696)0af225c
fix(conda): add supportpip
deps forenvironment.yml
files (#6675)6f64d55
fix(misconf): skip Rego errors with a nil location (#6666)8c27430
fix(misconf): skip Rego errors with a nil location (#6638)c2b46d3
refactor: unify Library and Package structs (#6633)4368f11
fix: use of specified context to obtain cluster name (#6645)5ec62f8
docs: fix usage of image-config-scanners (#6635)v0.51.1
Compare Source
Changelog
8016b82
fix(fs): handle default skip dirs properly (#6628)7a25dad
fix(misconf): load cached tf modules (#6607)9c794c0
fix(misconf): do not use semver for parsing tf module versions (#6614)v0.51.0
Compare Source
⚡Release highlights and summary⚡
👉 https://github.com/aquasecurity/trivy/discussions/6622
Changelog
14c1024
refactor: move setting scanners when using compliance reports to flag parsing (#6619)998f750
feat: introduce package UIDs for improved vulnerability mapping (#6583)770b141
perf(misconf): Improve cause performance (#6586)3ccb1a0
docs: trivy-k8s new experiance remove un-used section (#6608)58cfd1b
chore(deps): bump github.com/docker/docker from 26.0.1+incompatible to 26.0.2+incompatible (#6612)715963d
docs: remove mention of GitLab Gold because it doesn't exist anymore (#6609)37da98d
feat(misconf): Use updated terminology for misconfiguration checks (#6476)cdee703
chore(deps): bump github.com/aws/aws-sdk-go-v2/feature/s3/manager from 1.15.15 to 1.16.15 (#6593)6a2225b
docs: usegeneric
link fromtrivy-repo
(#6606)a2a02de
docs: update trivy k8s with new experience (#6465)e739ab8
feat: support--skip-images
scanning flag (#6334)c6d5d85
BREAKING: add support for k8sdisable-node-collector
flag (#6311)194a814
chore(deps): bump github.com/zclconf/go-cty from 1.14.1 to 1.14.4 (#6601)03830c5
chore(deps): bump github.com/sigstore/rekor from 1.2.2 to 1.3.6 (#6599)8e814fa
chore(deps): bump google.golang.org/protobuf from 1.33.0 to 1.34.0 (#6597)2dc76ba
chore(deps): bump sigstore/cosign-installer from 3.4.0 to 3.5.0 (#6588)c17176b
chore(deps): bump github.com/testcontainers/testcontainers-go from 0.28.0 to 0.30.0 (#6595)bce70af
chore(deps): bump github.com/open-policy-agent/opa from 0.62.0 to 0.64.1 (#6596)4369a19
feat: add ubuntu 23.10 and 24.04 support (#6573)5566548
chore(deps): bump azure/setup-helm from 3.5 to 4 (#6590)a8af76a
chore(deps): bump actions/checkout from 4.1.2 to 4.1.4 (#6587)c8ed432
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ecr from 1.24.6 to 1.27.4 (#6598)551a46e
docs(go): add stdlib (#6580)261649b
chore(deps): bump github.com/containerd/containerd from 1.7.13 to 1.7.16 (#6592)acfddd4
chore(deps): bump github.com/go-openapi/runtime from 0.27.1 to 0.28.0 (#6600)419e3d2
feat(go): parse main mod version from build info settings (#6564)f0961d5
feat: respect custom exit code from plugin (#6584)a5d485c
docs: add asdf and mise installation method (#6063)29b8faf
feat(vuln): Handle scanning conan v2.x lockfiles (#6357)e3bef02
feat: add supportenvironment.yaml
files (#6569)916f6c6
fix: close plugin.yaml (#6577)8e6cd0e
fix: trivy k8s avoid deleting non-default node collector namespace (#6559)060d0bb
BREAKING: support excludekinds/namespaces
and includekinds/namespaces
(#6323)2d090ef
feat(go): add main module (#6574)6343e4f
feat: add relationships (#6563)a018ee1
ci: disableGo
cache forreusable-release.yaml
(#6572)5da053f
docs: mention--show-suppressed
is available in table (#6571)3d66cb8
chore: fix sqlite to support loong64 (#6511)9aca98c
fix(debian): sort dpkg info before parsing due to exclude directories (#6551)7811ad0
docs: update info about config file (#6547)fae710d
docs: remove RELEASE_VERSION from trivy.repo (#6546)d2d4022
fix(sbom): change error to warning for multiple OSes (#6541)164b025
fix(vuln): skip empty versions (#6542)5dd9bd4
feat(c): add license support for conan lock files (#6329)7c2017f
fix(terraform): Attribute and fileset fixes (#6544)63c9469
refactor: change warning if no vulnerability details are found (#6230)aa822c2
refactor(misconf): improve error handling in the Rego scanner (#6527)30cc88f
ci: use tmp dir inside Trivy repo dir for GoReleaser (#6533)e32215c
feat(go): parse main module of go binary files (#6530)d4da83c
chore(deps): bump golang.org/x/net from 0.21.0 to 0.23.0 (#6526)0d7d97d
refactor(misconf): simplify the retrieval of module annotations (#6528)9873cf3
chore(deps): bump github.com/hashicorp/go-getter from 1.7.3 to 1.7.4 (#6523)95c8fd9
docs(nodejs): add info about supported versions of pnpm lock files (#6510)12ec0df
feat(misconf): loading embedded checks as a fallback (#6502)9b7d713
fix(misconf): Parse JSON k8s manifests properly (#6490)13e72ec
refactor: remove parallel walk (#5180)a986199
fix: close pom.xml (#6507)46d5aba
fix(secret): convert severity for custom rules (#6500)34ab09d
fix(java): update logic to detectpom.xml
file snapshot artifacts from remote repositories (#6412)1ba5b59
fix: typo (#6283)4fab0f8
docs(k8s,image): fix command-line syntax issues (#6403)d770981
chore(deps): bump actions/checkout from 4.1.1 to 4.1.2 (#6435)4337068
fix(misconf): avoid panic if the scheme is not valid (#6496)d82d6cb
feat(image): goversion as stdlib (#6277)cfddfb3
fix: add color for error inside of log message (#6493)dfcb0f9
chore(deps): bump actions/add-to-project from 0.4.1 to 1.0.0 (#6438)183eaaf
docs: fix links to OPA docs (#6480)94d6e8c
refactor: replace zap with slog (#6466)336c47e
docs: update links to IaC schemas (#6477)06b4473
chore: bump Go to 1.22 (#6075)a51cedd
refactor(terraform): sync funcs with Terraform (#6415)53517d6
feat(misconf): add helm-api-version and helm-kube-version flag (#6332)ad544e9
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azidentity from 1.4.0 to 1.5.1 (#6426)089368d
chore(deps): bump github.com/go-openapi/strfmt from 0.22.0 to 0.23.0 (#6452)1163565
chore(deps): bump github.com/hashicorp/golang-lru/v2 from 2.0.6 to 2.0.7 (#6430)637da2b
chore(deps): bump aquaproj/aqua-installer from 2.2.0 to 3.0.0 (#6437)13190e9
fix(terraform): eval submodules (#6411)6bca7c3
refactor(terraform): remove unused options (#6446)8e4279b
refactor(terraform): remove unused file (#6445)e98c873
chore(deps): bump github.com/testcontainers/testcontainers-go to v0.28.0 (#6387)b1c2eab
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azcore from 1.9.0 to 1.10.0 (#6427)1c49a16
fix(misconf): Escape template value correctly (#6292)8dd0fcd
feat(misconf): add support for wildcard ignores (#6414)74e4c6e
fix(cloudformation): resolveDedicatedMasterEnabled
parsing issue (#6439)245c120
refactor(terraform): remove metrics collection (#6444)86714bf
feat(cloudformation): add support for logging and endpoint access for EKS (#6440)a758392
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.51.1 to 1.53.1 (#6424)4d00d8b
chore(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.27.4 to 1.27.10 (#6428)3ad2b3e
chore(deps): bump go.etcd.io/bbolt from 1.3.8 to 1.3.9 (#6429)8baccd7
fix(db): check schema version for image name only (#6410)e75a90f
chore(deps): bump github.com/google/wire from 0.5.0 to 0.6.0 (#6425)6625bd3
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.149.1 to 1.155.1 (#6433)826fe60
chore(deps): bump actions/cache from 4.0.0 to 4.0.2 (#6436)f23ed77
feat(misconf): Support private registries for misconf check bundle (#6327)df024e8
feat(cloudformation): inline ignore support for YAML templates (#6358)29dee32
feat(terraform): ignore resources by nested attributes (#6302)1a67472
perf(helm): load in-memory files (#6383)09e37b7
feat(aws): apply filter options to result (#6367)87a9aa6
feat(aws): quiet flag support (#6331)712dcd3
fix(misconf): clear location URI for SARIF (#6405)625f22b
test(cloudformation): add CF tests (#6315)6a2f6fd
fix(cloudformation): infer type after resolving a function (#6406)v0.50.4
Compare Source
Note
v0.50.3 hads a critical problem, and we deleted it and released v0.50.4.
Changelog
e47fd48
fix(sbom): change error to warning for multiple OSes (#6541)v0.50.2
Compare Source
Changelog
9aa9e17
ci: use tmp dir inside Trivy repo dir for GoReleaser (#6533)058f483
chore(deps): bump golang.org/x/net from 0.21.0 to 0.23.0 (#6526)9e3d2c5
chore(deps): bump github.com/hashicorp/go-getter from 1.7.3 to 1.7.4 (#6523)2ad8e33
fix(java): update logic to detectpom.xml
file snapshot artifacts from remote repositories (#6412)argoproj/argo-cd (argoproj/argo-cd)
v2.11.1
Compare Source
v2.11.0
Compare Source
Quick Start
Non-HA:
HA:
Release Signatures and Provenance
All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changelog
Full Changelog: argoproj/argo-cd@v2.11.0-rc3...v2.11.0
v2.10.10
Compare Source
v2.10.9
Compare Source
Quick Start
Non-HA:
HA:
Release Signatures and Provenance
All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changelog
Full Changelog: argoproj/argo-cd@v2.10.8...v2.10.9
v2.10.8
Compare Source
Quick Start
Non-HA:
HA:
Release Signatures and Provenance
All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changelog
Full Changelog: argoproj/argo-cd@v2.10.7...v2.10.8
v2.10.7
Compare Source
Quick Start
Non-HA:
HA:
Release Signatures and Provenance
All Argo CD container images are signed by cosign. A Provenance is generated for container images and CLI binaries which meet the SLSA Level 3 specifications. See the documentation on how to verify.
Upgrading
If upgrading from a different minor version, be sure to read the upgrading documentation.
Changelog
Full Changelog: argoproj/argo-cd@v2.10.6...v2.10.7
hashicorp/terraform (hashicorp/terraform)
v1.8.3
Compare Source
1.8.3 (May 8, 2024)
BUG FIXES:
terraform test
: Providers configured within an overridden module could panic. (#35110)core
: Fix crash when a provider incorrectly plans a nested object when the configuration isnull
(#35090)v1.8.2
Compare Source
1.8.2 (April 24, 2024)
BUG FIXES:
terraform apply
: Prevent panic when a provider erroneously provides unknown values. (#35048)terraform plan
: Replace panic with error message when self-referencing resources and data sources from thecount
andfor_each
meta attributes. (#35047)terraform test
: RestoreTF_ENV_*
variables being made available to testing modules. (#35014)terraform test
: Prevent crash when referencing local variables within overridden modules. (#35030)ENHANCEMENTS:
OTHER CHANGES:
cloud
block and environment variables likeTF_CLOUD_ORGANIZATION
remain unchanged. (#35050)NOTE:
Starting with this release, we are including a copy of our license file in all packaged versions of our releases, such as the release .zip files. If you are consuming these files directly and would prefer to extract the one terraform file instead of extracting everything, you need to add an extra argument specifying the file to extract, like this:
v1.8.1
Compare Source
1.8.1 (April 17, 2024)
BUG FIXES:
moved
block: Fix crash when move targets a module which no longer exists. (#34986)import
block: Fix crash when generating configuration for resources with complex sensitive attributes. (#34996)v1.8.0
Compare Source
1.8.0 (April 10, 2024)
If you are upgrading from Terraform v1.7 or earlier, please refer to
the Terraform v1.8 Upgrade Guide.
NEW FEATURES:
Providers can now offer functions which can be used from within the Terraform configuration language.
The syntax for calling a provider-contributed function is
provider::provider_name::function_name()
. (#34394)Providers can now transfer the ownership of a remote object between resources of different types, for situations where there are two different resource types that represent the same remote object type.
This extends the
moved
block behavior to support moving between two resources of different types only if the provider for the target resource type declares that it can convert from the source resource type. Refer to provider documentation for details on which pairs of resource types are supported.New
issensitive
function returns true if the given value is marked as sensitive.ENHANCEMENTS:
terraform test
: File-level variables can now refer to global variables. (#34699)When generating configuration based on
import
blocks, Terraform will detect strings that contain valid JSON syntax and generate them as calls to thejsonencode
function, rather than generating a single string. This is primarily motivated by readability, but might also be useful if you need to replace part of the literal value with an expression as you generalize your module beyond the one example used for importing.terraform plan
now uses a different presentation for describing changes to lists where the old and new lists have the same length. It now compares the elements with correlated indices and shows a separate diff for each one, rather than trying to show a diff for the list as a whole. The behavior is unchanged for lists of different lengths.terraform providers lock
accepts a new boolean option-enable-plugin-cache
. If specified, and if a global plugin cache is configured, Terraform will use the cache in the provider lock process. (#34632)built-in "terraform" provider: new
decode_tfvars
,encode_tfvars
, andencode_expr
functions, for unusual situations where it's helpful to manually generate or read from Terraform's "tfvars" format. (#34718)terraform show
's JSON rendering of a plan now includes two explicit flags"applyable"
and"complete"
, which both summarize characteristics of a plan that were previously only inferrable by consumers replicating some of Terraform Core's own logic. (#34642)"applyable"
means that it makes sense for a wrapping automation to offer to apply this plan."complete"
means that applying this plan is expected to achieve convergence between desired and actual state. If this flag is present and set tofalse
then wrapping automations should ideally encourage an operator to run another plan/apply round to continue making progress toward convergence.BUG FIXES:
iterator
argument within a dynamic block. (#34751)Previous Releases
For information on prior major and minor releases, see their changelogs:
helm/helm (helm/helm)
v3.15.0
: Helm v3.15.0Compare Source
Helm v3.15.0 is a feature release. Users are encouraged to upgrade for the best experience.
The community keeps growing, and we'd love to see you there!
Notable Changes
Installation and Upgrading
Download Helm v3.15.0. The common platform binaries are here:
This release was signed with
672C 657B E06B 4B30 969C 4A57 4614 49C2 5E36 B98E
and can be found at @mattfarina keybase account. Please use the attached signatures for verifying this release usinggpg
.The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with
bash
.What's Next
Changelog
c4e37b3
(Matt Farina)d7afa3b
(Matt Farina)7743467
(Matt Farina)214fb6e
(Calvin Krist)1b75d48
(Dirk Müller)dac23c8
(dependabot[bot])167d576
(dependabot[bot])dd37787
(deterclosed)0a69a0d
(Andrew Block)aaaf112
(dependabot[bot])7f53529
(dependabot[bot])25c4738
(Matt Farina)ff94e93
(dependabot[bot])d58d7b3
(Robert Sirchia)a23dd9e
(Matt Farina)275f2ab
(dependabot[bot])8b424ba
(Robert Sirchia)e22d881
(dependabot[bot])4f200fa
(dependabot[bot])764557c
(Matt Farina)5bc97b9
(dependabot[bot])e6db0ec
(dependabot[bot])8d19bcb
(George Jenkins)68294fd
(George Jenkins)8e6a514
(Matt Farina)94c1dea
(Ricardo Maraschini)cbab6d6
(dependabot[bot])de332ae
(dependabot[bot])a2dd34b
(dependabot[bot])57a1bb8
(weidongkl)8cab7c1
(dependabot[bot])5f9533f
(dependabot[bot])4790bb9
(George Jenkins)f980ad3
(dependabot[bot])c25736c
(Matt Carr)d2cf8c6
(MichaelMorris)fc74964
(MichaelMorris)f908379
(Alex Petrov)9e198fa
(Alex Petrov)v3.14.4
: Helm v3.14.4Compare Source
Helm v3.14.4 is a patch release. Users are encouraged to upgrade for the best experience. Users are encouraged to upgrade for the best experience.
The community keeps growing, and we'd love to see you there!
Installation and Upgrading
Download Helm v3.14.4. The common platform binaries are here:
This release was signed with
672C 657B E06B 4B30 969C 4A57 4614 49C2 5E36 B98E
and can be found at @mattfarina keybase account. Please use the attached signatures for verifying this release usinggpg
.The Quickstart Guide will get you going from there. For upgrade instructions or detailed installation notes, check the install guide. You can also use a script to install on any system with
bash
.What's Next
Changelog
81c902a
(Alex Petrov)5a11c76
(Alex Petrov)fb3d880
(deterclosed)01ac4a2
(dependabot[bot])138602d
(dependabot[bot])aa7d953
(Ricardo Maraschini)kubernetes/kubernetes (kubernetes/kubernetes)
v1.30.1
: Kubernetes v1.30.1Compare Source
See kubernetes-announce@. Additional binary downloads are linked in the CHANGELOG.
See the CHANGELOG for more details.
v1.30.0
: Kubernetes v1.30.0Compare Source
See kubernetes-announce@. Additional binary downloads are linked in the CHANGELOG.
See the CHANGELOG for more details.
v1.29.5
: Kubernetes v1.29.5Compare Source
See kubernetes-announce@. Additional binary downloads are linked in the CHANGELOG.
See the CHANGELOG for more details.
v1.29.4
: Kubernetes v1.29.4Compare Source
See kubernetes-announce@. Additional binary downloads are linked in the CHANGELOG.
See the CHANGELOG for more details.
kubernetes/minikube (kubernetes/minikube)
v1.33.1
Compare Source
📣😀 Please fill out our fast 5-question survey so that we can learn how & why you use minikube, and what improvements we should make. Thank you! 💃🎉
Release Notes
Version 1.33.1 - 2024-05-13
Bugs:
DNSSEC validation failed
errors #18830too many open files
errors #18832