This update for trivy fixes the following issues:
Changes in trivy:
Update to version 0.67.2 (bsc#1250625, CVE-2025-11065, bsc#1248897, CVE-2025-58058):
fetch-level: 1 to check out trivy-repo in the release workflow [backport: release/v0.67] (#9638)buildInfo for BlobInfo in rpc package [backport: release/v0.67] (#9615)BuildableClient insead of xhttp.Client (#9436)detection priority into coverage section (#9469)nuget package names in lower case (#9456)Package.ID for pnpm packages (#9330)Update to version 0.66.0 (bsc#1248937, CVE-2025-58058):
file component type of CycloneDX (#9372)systemFileFiltering Post Handler (#9359)package.json file (#9349)3.21.3 to 3.21.4 (#9283)Update to version 0.65.0:
--server flag (#9270)LaxSplitLicenses (#9232)Getter interface with GetParams for trivy-db sources (#9239)gh cache delete in canary worklfow (#9240)--confirm flag from gh cache delete command in canary builds (#9236)for_each on a map returns a resource for every key (#9156)filepath when removing duplicate packages (#9142)*.list to *.md5sums files for dpkg (#9131)GFDL-NIV-1.1 and GFDL-NIV-1.2 into Trivy mapping (#9116)root.io packages (#9117)ci(helm): bump Trivy version to 0.64.0 for Trivy Helm Chart 0.16.0 (#9107)
(CVE-2025-53547, bsc#1246151)
Update to version 0.64.1 (bsc#1243633, CVE-2025-47291, (bsc#1246730, CVE-2025-46569):
fix(misconf): skip rewriting expr if attr is nil [backport: release/v0.64] (#9127)
root.io packages [backport: release/v0.64] (#9120)table format (#8549)packages array of bun.lock file (#8998)Relationship field support (#8939)Minimum Trivy Version (#8880)--skip-dir and --skip-files flags for sbom command (#8886)--compliance flag (#8881)rpc (#8872)lo.IsNil to check VEX from OCI artifact (#8858)ci(helm): bump Trivy version to 0.62.0 for Trivy Helm Chart 0.14.0 (#8802)
chore(deps): bump the common group across 1 directory with 10 updates [backport: release/v0.62] (#8831)
yarn packages (#8535)last-applied-configuration (#8791)Skitionek/notify-microsoft-teams instead of aquasecurity fork (#8740)cargo lock files (#8676)evaluateStep to correctly set EvalContext for multiple instances of blocks (#8555)github.com/aquasecurity/jfather to github.com/go-json-experiment/json (#8591)github.event.pull_request.user.login for release PR check workflow (#8702)aquasecurity repository for test images (#8677)rego with repo on the RepoFlagGroup options error output (#8643)Update to version 0.61.1 (bsc#1239385, CVE-2025-22869, bsc#1240466, CVE-2025-30204):
aquasecurity repository for test images [backport: release/v0.61] (#8698)dpkgs (#8623)--report all (#8613)--file-patterns flag for all post analyzers (#7365)otherLicenses without normalize (#8502)trivy-db (#8492)--vuln-severity-source flag (#8269)PkgRelationships (#8442)pkgFilePaths map for all formats (#8380)mockery to update v2.52.2 version and rebuild mock files (#8390)scope for trivy registry login command (#8393)aqua-installer step to fix mage error (#8353)shortDescription and fullDescription fields for sarif reports (#8344)v1.23.5 (#8341)poetry v2 support (#8323)Update to version 0.59.1:
v1.23.5 [backport: release/v0.59] (#8343)poetry v2 support [backport: release/v0.59] (#8335)Update to version 0.59.0:
dpkg packages with different filePaths from different layers (#8298)hasExtractedLicensingInfos field for licenses that are not listed in the SPDX (#8077)github.com/liamg/jfather and github.com/liamg/iamgo (#8289)usr/share/buildinfo/ dir to detect content sets (#8222)License acquired from METADATA... logs (#8175)unknown dependencies (if exists) (#8104)golang.org/x/net from v0.32.0 to v0.33.0 (#8140)github.com/CycloneDX/cyclonedx-go from v0.9.1 to v0.9.2 (#8105)--distro flag to manually specify OS distribution for vulnerability scanning (#8070)BLOW_UNKNOWN error to download DBs (#8060)--generate-default-config command (#8046)project.* props (#8050)docs: add commercial content (#8030)
fix(misconf): allow null values only for tf variables [backport: release/v0.58] (#8238)
unknown dependencies (if exists) [backport: release/v0.58] (#8156)golang.org/x/net from v0.32.0 to v0.33.0 [backport: release/v0.58] (#8142)github.com/CycloneDX/cyclonedx-go from v0.9.1 to v0.9.2 [backport: release/v0.58] (#8136)BLOW_UNKNOWN error to download DBs [backport: release/v0.58] (#8121)project.* props [backport: release/v0.58] (#8119)workspaceRelationship (#7889)go.mod main module in the parser (#7977)overview page for others (#7972)flavors support (#7858)mirror.gcr.io (#7953)UID for removed packages (#7887)root/buildinfo/content_manifests/ contains files that are not contentSets files (#7912)git@github.com schema for misconfigs in sarif report (#7898)containerd image into archive and use in tests (#7816)Update to version 0.57.1:
root/buildinfo/content_manifests/ contains files that are not contentSets files [backport: release/v0.57] (#7939)errors.Join (#7845)Annotation instead of AttributionTexts for SPDX formats (#7811)EXCEPTIONS for misconfiguration scanning (#7776)CycloneDX reports (#7507)version and scope from upper/root depManagement and dependencies into parents (#7541)trivy auth to trivy registry (#7727)clean --all deletes only relevant dirs (#7704)trivy auth (#7664)git clone output to Stderr (#7561)Update to version 0.56.2:
fix(sbom): add options for DBs in private registries [backport: release/v0.56] (#7691)