Teppei Fukuda
8016b821a2
fix(fs): handle default skip dirs properly ( #6628 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-05-04 05:34:54 +00:00
Nikita Pivkin
7a25dadb44
fix(misconf): load cached tf modules ( #6607 )
2024-05-04 04:24:39 +00:00
Nikita Pivkin
9c794c0ffc
fix(misconf): do not use semver for parsing tf module versions ( #6614 )
2024-05-04 02:45:29 +00:00
DmitriyLewen
14c1024b47
refactor: move setting scanners when using compliance reports to flag parsing ( #6619 )
2024-05-03 11:27:37 +00:00
Teppei Fukuda
998f750432
feat: introduce package UIDs for improved vulnerability mapping ( #6583 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-05-03 11:14:34 +00:00
simar7
770b14113c
perf(misconf): Improve cause performance ( #6586 )
...
Signed-off-by: Simar <simar@linux.com >
2024-05-03 05:04:10 +00:00
chenk
3ccb1a0f10
docs: trivy-k8s new experiance remove un-used section ( #6608 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-05-03 04:50:53 +00:00
dependabot[bot]
58cfd1b074
chore(deps): bump github.com/docker/docker from 26.0.1+incompatible to 26.0.2+incompatible ( #6612 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-03 04:05:14 +00:00
Marlon M
715963d754
docs: remove mention of GitLab Gold because it doesn't exist anymore ( #6609 )
2024-05-03 04:03:59 +00:00
simar7
37da98df45
feat(misconf): Use updated terminology for misconfiguration checks ( #6476 )
...
Signed-off-by: Simar <simar@linux.com >
2024-05-02 18:16:17 +00:00
dependabot[bot]
cdee7030ac
chore(deps): bump github.com/aws/aws-sdk-go-v2/feature/s3/manager from 1.15.15 to 1.16.15 ( #6593 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 13:34:52 +00:00
DmitriyLewen
6a2225b425
docs: use generic link from trivy-repo ( #6606 )
2024-05-02 13:34:41 +00:00
chenk
a2a02de7c5
docs: update trivy k8s with new experience ( #6465 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-05-02 12:59:22 +00:00
chenk
e739ab8506
feat: support --skip-images scanning flag ( #6334 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-05-02 11:49:39 +00:00
chenk
c6d5d856ce
BREAKING: add support for k8s disable-node-collector flag ( #6311 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-05-02 11:08:59 +00:00
dependabot[bot]
194a814688
chore(deps): bump github.com/zclconf/go-cty from 1.14.1 to 1.14.4 ( #6601 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 10:50:48 +00:00
dependabot[bot]
03830c50c9
chore(deps): bump github.com/sigstore/rekor from 1.2.2 to 1.3.6 ( #6599 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 10:29:16 +00:00
dependabot[bot]
8e814fa23d
chore(deps): bump google.golang.org/protobuf from 1.33.0 to 1.34.0 ( #6597 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 08:32:24 +00:00
dependabot[bot]
2dc76ba782
chore(deps): bump sigstore/cosign-installer from 3.4.0 to 3.5.0 ( #6588 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 08:31:57 +00:00
dependabot[bot]
c17176ba97
chore(deps): bump github.com/testcontainers/testcontainers-go from 0.28.0 to 0.30.0 ( #6595 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 08:31:02 +00:00
dependabot[bot]
bce70af369
chore(deps): bump github.com/open-policy-agent/opa from 0.62.0 to 0.64.1 ( #6596 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 07:08:01 +00:00
DmitriyLewen
4369a19af7
feat: add ubuntu 23.10 and 24.04 support ( #6573 )
2024-05-02 06:40:11 +00:00
dependabot[bot]
5566548b78
chore(deps): bump azure/setup-helm from 3.5 to 4 ( #6590 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 06:35:05 +00:00
dependabot[bot]
a8af76a471
chore(deps): bump actions/checkout from 4.1.2 to 4.1.4 ( #6587 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 06:27:31 +00:00
dependabot[bot]
c8ed432f28
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ecr from 1.24.6 to 1.27.4 ( #6598 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 06:26:47 +00:00
Teppei Fukuda
551a46efcc
docs(go): add stdlib ( #6580 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-05-02 06:24:30 +00:00
dependabot[bot]
261649b115
chore(deps): bump github.com/containerd/containerd from 1.7.13 to 1.7.16 ( #6592 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 06:01:21 +00:00
dependabot[bot]
acfddd4570
chore(deps): bump github.com/go-openapi/runtime from 0.27.1 to 0.28.0 ( #6600 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 06:00:50 +00:00
Oscar Alberto Tovar
419e3d2023
feat(go): parse main mod version from build info settings ( #6564 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2024-05-02 05:33:13 +00:00
Teppei Fukuda
f0961d54f6
feat: respect custom exit code from plugin ( #6584 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-05-02 05:07:49 +00:00
Jean-Yves LENHOF
a5d485cf8a
docs: add asdf and mise installation method ( #6063 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-04-30 07:32:14 +00:00
Damian E
29b8faf5fa
feat(vuln): Handle scanning conan v2.x lockfiles ( #6357 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2024-04-29 10:37:25 +00:00
DmitriyLewen
e3bef02018
feat: add support environment.yaml files ( #6569 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-04-29 10:33:53 +00:00
guangwu
916f6c66f8
fix: close plugin.yaml ( #6577 )
...
Signed-off-by: guoguangwu <guoguangwug@gmail.com >
2024-04-29 06:13:03 +00:00
chenk
8e6cd0e917
fix: trivy k8s avoid deleting non-default node collector namespace ( #6559 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-04-27 16:39:47 +00:00
chenk
060d0bb641
BREAKING: support exclude kinds/namespaces and include kinds/namespaces ( #6323 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-04-27 14:30:17 +00:00
Teppei Fukuda
2d090ef2df
feat(go): add main module ( #6574 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-04-27 10:00:14 +00:00
Teppei Fukuda
6343e4fc71
feat: add relationships ( #6563 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-04-27 09:15:12 +00:00
DmitriyLewen
a018ee1f9b
ci: disable Go cache for reusable-release.yaml ( #6572 )
2024-04-27 08:40:32 +00:00
Teppei Fukuda
5da053f302
docs: mention --show-suppressed is available in table ( #6571 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-04-27 07:08:47 +00:00
zhaixiaojuan
3d66cb8d88
chore: fix sqlite to support loong64 ( #6511 )
2024-04-26 10:44:24 +00:00
Yaney
9aca98cca8
fix(debian): sort dpkg info before parsing due to exclude directories ( #6551 )
2024-04-26 07:15:29 +00:00
DmitriyLewen
7811ad0d24
docs: update info about config file ( #6547 )
...
Co-authored-by: simar7 <1254783+simar7@users.noreply.github.com >
2024-04-25 11:30:49 +00:00
Jakob Maležič
fae710db8f
docs: remove RELEASE_VERSION from trivy.repo ( #6546 )
2024-04-24 07:18:39 +00:00
Teppei Fukuda
d2d4022ef3
fix(sbom): change error to warning for multiple OSes ( #6541 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-04-24 06:54:41 +00:00
Teppei Fukuda
164b025413
fix(vuln): skip empty versions ( #6542 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-04-24 06:03:12 +00:00
DmitriyLewen
5dd9bd4701
feat(c): add license support for conan lock files ( #6329 )
2024-04-24 05:29:02 +00:00
fwereade
7c2017fa7a
fix(terraform): Attribute and fileset fixes ( #6544 )
2024-04-23 22:03:43 +00:00
DmitriyLewen
63c9469bdd
refactor: change warning if no vulnerability details are found ( #6230 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-04-22 17:54:26 +00:00
Nikita Pivkin
aa822c260f
refactor(misconf): improve error handling in the Rego scanner ( #6527 )
2024-04-22 15:46:10 +00:00
DmitriyLewen
30cc88fa87
ci: use tmp dir inside Trivy repo dir for GoReleaser ( #6533 )
2024-04-22 12:23:05 +00:00
DmitriyLewen
e32215c99d
feat(go): parse main module of go binary files ( #6530 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2024-04-22 11:58:44 +00:00
dependabot[bot]
d4da83c633
chore(deps): bump golang.org/x/net from 0.21.0 to 0.23.0 ( #6526 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-22 04:38:28 +00:00
Nikita Pivkin
0d7d97d131
refactor(misconf): simplify the retrieval of module annotations ( #6528 )
2024-04-20 03:00:18 +00:00
l-qing
9873cf3b9c
chore(deps): bump github.com/hashicorp/go-getter from 1.7.3 to 1.7.4 ( #6523 )
2024-04-19 07:55:24 +00:00
DmitriyLewen
95c8fd912e
docs(nodejs): add info about supported versions of pnpm lock files ( #6510 )
2024-04-19 07:38:32 +00:00
Nikita Pivkin
12ec0dfe9e
feat(misconf): loading embedded checks as a fallback ( #6502 )
2024-04-19 06:22:31 +00:00
simar7
9b7d7132b7
fix(misconf): Parse JSON k8s manifests properly ( #6490 )
2024-04-19 01:17:43 +00:00
Teppei Fukuda
13e72eca58
refactor: remove parallel walk ( #5180 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-04-17 18:24:18 +00:00
guangwu
a9861994e5
fix: close pom.xml ( #6507 )
...
Signed-off-by: guoguangwu <guoguangwug@gmail.com >
2024-04-17 11:22:52 +00:00
DmitriyLewen
46d5abad42
fix(secret): convert severity for custom rules ( #6500 )
2024-04-16 07:51:03 +00:00
DmitriyLewen
34ab09d559
fix(java): update logic to detect pom.xml file snapshot artifacts from remote repositories ( #6412 )
2024-04-16 07:48:58 +00:00
guangwu
1ba5b59527
fix: typo ( #6283 )
...
Signed-off-by: guoguangwu <guoguangwug@gmail.com >
2024-04-16 02:38:13 +00:00
Saeid Bostandoust
4fab0f8b99
docs(k8s,image): fix command-line syntax issues ( #6403 )
2024-04-16 02:33:46 +00:00
dependabot[bot]
d7709816c3
chore(deps): bump actions/checkout from 4.1.1 to 4.1.2 ( #6435 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-16 02:30:58 +00:00
Nikita Pivkin
4337068208
fix(misconf): avoid panic if the scheme is not valid ( #6496 )
2024-04-15 20:14:34 +00:00
Pete Wagner
d82d6cb731
feat(image): goversion as stdlib ( #6277 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-04-15 18:25:04 +00:00
DmitriyLewen
cfddfb33c1
fix: add color for error inside of log message ( #6493 )
2024-04-15 11:13:54 +00:00
dependabot[bot]
dfcb0f90db
chore(deps): bump actions/add-to-project from 0.4.1 to 1.0.0 ( #6438 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-15 11:06:35 +00:00
Nikita Pivkin
183eaafb4e
docs: fix links to OPA docs ( #6480 )
2024-04-12 19:52:50 +00:00
Teppei Fukuda
94d6e8ced6
refactor: replace zap with slog ( #6466 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: Nikita Pivkin <nikita.pivkin@smartforce.io >
Co-authored-by: simar7 <1254783+simar7@users.noreply.github.com >
2024-04-11 18:59:09 +00:00
Nikita Pivkin
336c47ecc3
docs: update links to IaC schemas ( #6477 )
2024-04-11 02:24:06 +00:00
Teppei Fukuda
06b44738e7
chore: bump Go to 1.22 ( #6075 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: Simar <simar@linux.com >
2024-04-08 10:53:00 +00:00
Nikita Pivkin
a51ceddada
refactor(terraform): sync funcs with Terraform ( #6415 )
2024-04-06 05:10:53 +00:00
Jan-Otto Kröpke
53517d622b
feat(misconf): add helm-api-version and helm-kube-version flag ( #6332 )
...
Co-authored-by: Simar <simar@linux.com >
2024-04-06 05:07:56 +00:00
dependabot[bot]
ad544e97cc
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azidentity from 1.4.0 to 1.5.1 ( #6426 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-04 06:49:05 +00:00
dependabot[bot]
089368d968
chore(deps): bump github.com/go-openapi/strfmt from 0.22.0 to 0.23.0 ( #6452 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-04 06:37:32 +00:00
dependabot[bot]
116356500e
chore(deps): bump github.com/hashicorp/golang-lru/v2 from 2.0.6 to 2.0.7 ( #6430 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-04 06:34:27 +00:00
dependabot[bot]
637da2b178
chore(deps): bump aquaproj/aqua-installer from 2.2.0 to 3.0.0 ( #6437 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-04 06:33:36 +00:00
Nikita Pivkin
13190e92d9
fix(terraform): eval submodules ( #6411 )
...
Co-authored-by: William Reade <william@stacklet.io >
2024-04-04 03:40:40 +00:00
Nikita Pivkin
6bca7c3c79
refactor(terraform): remove unused options ( #6446 )
2024-04-04 00:29:31 +00:00
Nikita Pivkin
8e4279b863
refactor(terraform): remove unused file ( #6445 )
2024-04-04 00:13:25 +00:00
Prajyot Parab
e98c873ed0
chore(deps): bump github.com/testcontainers/testcontainers-go to v0.28.0 ( #6387 )
...
Signed-off-by: Prajyot-Parab <prajyot.parab2@ibm.com >
2024-04-03 16:55:03 +00:00
dependabot[bot]
b1c2eab5aa
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azcore from 1.9.0 to 1.10.0 ( #6427 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-03 16:36:44 +00:00
simar7
1c49a16c65
fix(misconf): Escape template value correctly ( #6292 )
...
Signed-off-by: Simar <simar@linux.com >
2024-04-03 04:30:18 +00:00
Nikita Pivkin
8dd0fcd61b
feat(misconf): add support for wildcard ignores ( #6414 )
2024-04-03 00:43:29 +00:00
Nikita Pivkin
74e4c6e012
fix(cloudformation): resolve DedicatedMasterEnabled parsing issue ( #6439 )
2024-04-02 22:42:46 +00:00
Nikita Pivkin
245c120532
refactor(terraform): remove metrics collection ( #6444 )
2024-04-02 22:41:57 +00:00
Nikita Pivkin
86714bf6bf
feat(cloudformation): add support for logging and endpoint access for EKS ( #6440 )
2024-04-02 22:41:30 +00:00
dependabot[bot]
a75839212c
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.51.1 to 1.53.1 ( #6424 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-02 16:04:23 +00:00
dependabot[bot]
4d00d8b52a
chore(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.27.4 to 1.27.10 ( #6428 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-02 14:32:29 +00:00
dependabot[bot]
3ad2b3e255
chore(deps): bump go.etcd.io/bbolt from 1.3.8 to 1.3.9 ( #6429 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-02 11:23:47 +00:00
DmitriyLewen
8baccd7909
fix(db): check schema version for image name only ( #6410 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-04-02 11:22:43 +00:00
dependabot[bot]
e75a90f2e5
chore(deps): bump github.com/google/wire from 0.5.0 to 0.6.0 ( #6425 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-02 11:20:08 +00:00
dependabot[bot]
6625bd32e0
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.149.1 to 1.155.1 ( #6433 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-02 11:18:50 +00:00
dependabot[bot]
826fe60732
chore(deps): bump actions/cache from 4.0.0 to 4.0.2 ( #6436 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-02 11:17:12 +00:00
Jeff Rescignano
f23ed77598
feat(misconf): Support private registries for misconf check bundle ( #6327 )
2024-04-01 05:45:58 +00:00
Nikita Pivkin
df024e88dd
feat(cloudformation): inline ignore support for YAML templates ( #6358 )
2024-03-29 05:23:01 +00:00
Nikita Pivkin
29dee32814
feat(terraform): ignore resources by nested attributes ( #6302 )
2024-03-29 03:55:18 +00:00
Nikita Pivkin
1a67472d2b
perf(helm): load in-memory files ( #6383 )
2024-03-29 03:55:00 +00:00
Nikita Pivkin
09e37b7c67
feat(aws): apply filter options to result ( #6367 )
2024-03-29 01:12:23 +00:00
Nikita Pivkin
87a9aa60d1
feat(aws): quiet flag support ( #6331 )
2024-03-29 01:11:27 +00:00
Nikita Pivkin
712dcd3007
fix(misconf): clear location URI for SARIF ( #6405 )
2024-03-29 01:10:06 +00:00
Nikita Pivkin
625f22b819
test(cloudformation): add CF tests ( #6315 )
2024-03-29 01:08:06 +00:00
Nikita Pivkin
6a2f6fde4f
fix(cloudformation): infer type after resolving a function ( #6406 )
2024-03-28 21:50:36 +00:00
DmitriyLewen
5f69937cc6
fix(sbom): fix error when parent of SPDX Relationships is not a package. ( #6399 )
2024-03-27 07:07:12 +00:00
DmitriyLewen
258d153461
fix(nodejs): merge Indirect, Dev, ExternalReferences fields for same deps from package-lock.json files v2 or later ( #6356 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-03-27 06:08:58 +00:00
DmitriyLewen
ade033a837
docs: add info about support for package license detection in fs/repo modes ( #6381 )
2024-03-27 05:51:09 +00:00
DmitriyLewen
f85c9fac6f
fix(nodejs): add support for parsing workspaces from package.json as an object ( #6231 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2024-03-27 05:46:25 +00:00
DmitriyLewen
9d7f5c948e
fix: use 0600 perms for tmp files for post analyzers ( #6386 )
2024-03-27 05:32:22 +00:00
Nikita Pivkin
f148eb10f2
fix(helm): scan the subcharts once ( #6382 )
2024-03-26 17:10:16 +00:00
Nikita Pivkin
97f95c4ddf
docs(terraform): add file patterns for Terraform Plan ( #6393 )
2024-03-26 17:04:40 +00:00
Nikita Pivkin
abd62ae74e
fix(terraform): сhecking SSE encryption algorithm validity ( #6341 )
2024-03-26 03:31:28 +00:00
DmitriyLewen
7c409fd270
fix(java): parse modules from pom.xml files once ( #6312 )
2024-03-24 09:57:32 +00:00
dependabot[bot]
1b68327b65
chore(deps): bump github.com/docker/docker from 25.0.3+incompatible to 25.0.5+incompatible ( #6364 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-24 09:55:08 +00:00
DmitriyLewen
a2482c14e1
fix(server): add Locations for Packages in client/server mode ( #6366 )
2024-03-24 09:46:56 +00:00
DmitriyLewen
e866bd5b5d
fix(sbom): add check for CreationInfo to nil when detecting SPDX created using Trivy ( #6346 )
2024-03-24 09:45:45 +00:00
DmitriyLewen
1870f28461
fix(report): don't include empty strings in .vulnerabilities[].identifiers[].url when gitlab.tpl is used ( #6348 )
2024-03-24 09:44:40 +00:00
Stefan Mayr
6c81e5505e
chore(ubuntu): Add Ubuntu 22.04 EOL date ( #6371 )
2024-03-24 07:26:49 +00:00
dependabot[bot]
8ec3938e01
chore(deps): bump google.golang.org/protobuf from 1.32.0 to 1.33.0 ( #6321 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-19 01:04:16 +00:00
DmitriyLewen
f6c5d58001
feat(java): add support licenses and graph for gradle lock files ( #6140 )
2024-03-19 00:59:31 +00:00
Teppei Fukuda
c4022d61b3
feat(vex): consider root component for relationships ( #6313 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-03-19 00:51:18 +00:00
DmitriyLewen
317792433e
fix: increase the default buffer size for scanning dpkg status files by 2 times ( #6298 )
2024-03-18 09:42:54 +00:00
Edoardo Vacchi
dd9620ef38
chore: updates wazero to v1.7.0 ( #6301 )
...
Signed-off-by: Edoardo Vacchi <evacchi@users.noreply.github.com >
2024-03-18 09:41:34 +00:00
Ivo Šmíd
eb3ceb323d
feat(sbom): Support license detection for SBOM scan ( #6072 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-03-18 09:34:26 +00:00
Teppei Fukuda
ab74caa87f
refactor(sbom): use intermediate representation for SPDX ( #6310 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-03-18 08:52:11 +00:00
Nikita Pivkin
71da44f7e1
docs(terraform): improve documentation for filtering by inline comments ( #6284 )
2024-03-12 14:49:07 +00:00
Nikita Pivkin
102b6df738
fix(terraform): fix policy document retrieval ( #6276 )
2024-03-12 14:48:16 +00:00
Nikita Pivkin
aa19aaf4e4
refactor(terraform): remove unused custom error ( #6303 )
2024-03-12 14:43:09 +00:00
Teppei Fukuda
8fcef352b3
refactor(sbom): add intermediate representation for BOM ( #6240 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
2024-03-12 06:56:10 +00:00
DmitriyLewen
fb8c516ded
fix(amazon): check only major version of AL to find advisories ( #6295 )
2024-03-11 08:46:25 +00:00
DmitriyLewen
96bd7ac594
fix(db): use schema version as tag only for trivy-db and trivy-java-db registries by default ( #6219 )
2024-03-11 06:57:56 +00:00
DmitriyLewen
12c5bf0805
fix(nodejs): add name validation for package name from package.json ( #6268 )
2024-03-11 05:23:51 +00:00
Matthias Fechner
d6c40ce058
docs: Added install instructions for FreeBSD ( #6293 )
2024-03-11 04:58:12 +00:00
Parvez
9d2057a7c2
feat(image): customer podman host or socket option ( #6256 )
...
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-03-11 04:27:57 +00:00
Edoardo Vacchi
2a9d9bd214
chore(deps): bump wazero from 1.2.1 to 1.6.0 ( #6290 )
...
Signed-off-by: Edoardo Vacchi <evacchi@users.noreply.github.com >
2024-03-11 04:08:09 +00:00
DmitriyLewen
617c3e31bd
feat(java): mark dependencies from maven-invoker-plugin integration tests pom.xml files as Dev ( #6213 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-03-08 10:13:49 +00:00
Damian E
56cedc0d67
fix(license): reorder logic of how python package licenses are acquired ( #6220 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-03-08 06:37:55 +00:00
Nikita Pivkin
d7d7265eb0
test(terraform): skip cached modules ( #6281 )
2024-03-08 00:37:58 +00:00
Chris King
6639911662
feat(secret): Support for detecting Hugging Face Access Tokens ( #6236 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-03-07 14:00:52 +00:00
Nikita Pivkin
337cb75353
fix(cloudformation): support of all SSE algorithms for s3 ( #6270 )
2024-03-07 01:12:04 +00:00
Nikita Pivkin
9361cdb7e2
feat(terraform): Terraform Plan snapshot scanning support ( #6176 )
...
Co-authored-by: Simar <simar@linux.com >
Co-authored-by: simar7 <1254783+simar7@users.noreply.github.com >
2024-03-04 22:37:31 +00:00
dependabot[bot]
ee01e6e2f4
chore(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.26.6 to 1.27.4 ( #6249 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-04 14:33:33 +00:00
guangwu
3d2f583ecd
fix: typo function name and comment optimization ( #6200 )
...
Signed-off-by: guoguangwu <guoguangwu@magic-shield.com >
2024-03-04 14:24:40 +00:00
DmitriyLewen
c4b5ab7881
fix(java): don't ignore runtime scope for pom.xml files ( #6223 )
2024-03-04 14:23:13 +00:00
dependabot[bot]
355c1b583b
chore(deps): bump helm/kind-action from 1.8.0 to 1.9.0 ( #6242 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-04 13:49:43 +00:00
dependabot[bot]
7244ece536
chore(deps): bump golangci/golangci-lint-action from 3.7.0 to 4.0.0 ( #6243 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-04 13:41:39 +00:00
dependabot[bot]
5cd0566843
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.48.1 to 1.51.1 ( #6251 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-04 13:38:30 +00:00
dependabot[bot]
ebb74a5de0
chore(deps): bump github.com/hashicorp/go-uuid from 1.0.1 to 1.0.3 ( #6253 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-04 11:35:03 +00:00
dependabot[bot]
24a8d6aaa8
chore(deps): bump github.com/open-policy-agent/opa from 0.61.0 to 0.62.0 ( #6250 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-04 11:22:55 +00:00
dependabot[bot]
9d0d7ad886
chore(deps): bump github.com/containerd/containerd from 1.7.12 to 1.7.13 ( #6247 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-04 11:18:00 +00:00
dependabot[bot]
e8230e19d7
chore(deps): bump go.uber.org/zap from 1.26.0 to 1.27.0 ( #6246 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-04 10:59:18 +00:00
Damian E
04535b554a
fix(license): add FilePath to results to allow for license path filtering via trivyignore file ( #6215 )
...
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-03-04 09:38:51 +00:00
simar7
939e34e37c
chore(deps): Upgrade iac deps ( #6255 )
2024-03-04 09:30:55 +00:00
DmitriyLewen
7cb6c02a4e
feat: add info log message about dev deps suppression ( #6211 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2024-03-04 09:30:30 +00:00
DmitriyLewen
c1d26ec334
test(k8s): use test-db for k8s integration tests ( #6222 )
2024-02-28 16:17:59 +00:00
DmitriyLewen
4f70468bdd
ci: add maximize-build-space for Test job ( #6221 )
2024-02-28 10:06:52 +00:00
Nikita Pivkin
1dfece89d0
fix(terraform): fix root module search ( #6160 )
...
Co-authored-by: simar7 <1254783+simar7@users.noreply.github.com >
2024-02-28 03:31:03 +00:00
DmitriyLewen
e1ea02c7b8
test(parser): squash test data for yarn ( #6203 )
2024-02-27 07:24:22 +00:00
Nikita Pivkin
64926d8423
fix(terraform): do not re-expand dynamic blocks ( #6151 )
2024-02-27 07:02:29 +00:00
Anais Urlichs
eb54bb5da5
docs: update ecosystem page reporting with db app ( #6201 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2024-02-27 02:47:30 +00:00
chenk
dc76c6e4f4
fix: k8s summary separate infra and user finding results ( #6120 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-02-27 02:29:41 +00:00
chenk
1b7e47424b
fix: add context to target finding on k8s table view ( #6099 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-02-26 06:58:47 +00:00
guangwu
876ab84b36
fix: Printf format err ( #6198 )
...
Signed-off-by: guoguangwu <guoguangwu@magic-shield.com >
2024-02-26 06:07:35 +00:00
Teppei Fukuda
eef7c4fb40
refactor: better integration of the parser into Trivy ( #6183 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-02-26 05:55:15 +00:00
dependabot[bot]
069aae59ec
chore(deps): bump helm.sh/helm/v3 from 3.14.1 to 3.14.2 ( #6189 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-23 03:17:15 +00:00
Adam Carruthers
4a9ac6d199
feat(terraform): Add hyphen and non-ASCII support for domain names in credential extraction ( #6108 )
...
Co-authored-by: simar7 <1254783+simar7@users.noreply.github.com >
2024-02-23 00:54:40 +00:00
Juan Ariza Toledano
9c5e5a04ee
fix(vex): CSAF filtering should consider relationships ( #5923 )
...
Signed-off-by: juan131 <jariza@vmware.com >
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2024-02-22 10:23:11 +00:00
Maxime Durand
388f47669d
refactor(report): Replacing source_location in github report when scanning an image ( #5999 )
...
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
2024-02-22 09:56:18 +00:00
Teppei Fukuda
cd3e4bcac2
feat(vuln): ignore vulnerabilities by PURL ( #6178 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-02-22 09:55:13 +00:00
renypaul
ce81c05851
feat(java): add support for fetching packages from repos mentioned in pom.xml ( #6171 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-02-22 09:50:08 +00:00
chenk
cf0f0d00c2
feat(k8s): rancher rke2 version support ( #5988 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-02-22 04:35:47 +00:00
chenk
8a3a113eea
docs: update kbom distribution for scanning ( #6019 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-02-21 16:16:23 +00:00
Teppei Fukuda
19495ba7c2
chore: update CODEOWNERS ( #6173 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-02-21 16:14:12 +00:00
DmitriyLewen
e787e1af01
fix(swift): try to use branch to resolve version ( #6168 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-02-21 14:52:47 +00:00
Nikita Pivkin
327cf88397
fix(terraform): ensure consistent path handling across OS ( #6161 )
2024-02-21 07:19:07 +00:00
DmitriyLewen
82214736a9
fix(java): add only valid libs from pom.properties files from jars ( #6164 )
2024-02-20 06:51:43 +00:00
saso
7694df11fb
fix(sbom): skip executable file analysis if Rekor isn't a specified SBOM source ( #6163 )
2024-02-20 06:44:35 +00:00
Teppei Fukuda
74dc5b6804
chore(deps): merge go-dep-parser into Trivy ( #6094 )
...
Signed-off-by: Arunprasad Rajkumar <arajkuma@redhat.com >
Signed-off-by: guoguangwu <guoguangwu@magic-shield.com >
Signed-off-by: dependabot[bot] <support@github.com >
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: Masahiro <mur4m4s4.331@gmail.com >
Co-authored-by: Tomoya Amachi <tomoya.amachi@gmail.com >
Co-authored-by: Masahiro <lomycisw@gmail.com >
Co-authored-by: Liz Rice <liz@lizrice.com >
Co-authored-by: Johannes <johannes@jitesoft.com >
Co-authored-by: aprp <doelaudi@gmail.com >
Co-authored-by: rahul2393 <rahulyadavsep92@gmail.com >
Co-authored-by: Arunprasad Rajkumar <ar.arunprasad@gmail.com >
Co-authored-by: Emrecan BATI <emrecanbati@gmail.com >
Co-authored-by: sherif84 <12298259+sherif84@users.noreply.github.com >
Co-authored-by: Sherif Fathalla <sfathall@akamai.com >
Co-authored-by: sherif <sherif.mailbox@gmail.com >
Co-authored-by: Sam Lane <samuel.lane@hotmail.com >
Co-authored-by: Ankush K <akhobragade@gmail.com >
Co-authored-by: Ankush K <akhobragade42@gmail.com >
Co-authored-by: Tauseef <tauseefmlk@gmail.com >
Co-authored-by: Daniel <danfaizer@gmail.com >
Co-authored-by: Matthieu MOREL <mmorel-35@users.noreply.github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: afdesk <work@afdesk.com >
Co-authored-by: AndreyLevchenko <levchenko.andrey@gmail.com >
Co-authored-by: Kobus van Schoor <10784365+kobus-v-schoor@users.noreply.github.com >
Co-authored-by: Jan-Otto Kröpke <github@jkroepke.de >
Co-authored-by: jerbob92 <jerbob92@users.noreply.github.com >
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
Co-authored-by: Shira Cohen <97398476+ShiraCohen33@users.noreply.github.com >
Co-authored-by: astevenson-microsoft <78623826+astevenson-microsoft@users.noreply.github.com >
Co-authored-by: Kyriakos Georgiou <kgeorgiou@users.noreply.github.com >
Co-authored-by: mycodeself <mycodeself@users.noreply.github.com >
Co-authored-by: DavidSalame <75929252+davidsalame1@users.noreply.github.com >
Co-authored-by: Tom Fay <tom@teamfay.co.uk >
Co-authored-by: Tom Fay <tomfay@microsoft.com >
Co-authored-by: François Poirotte <fpoirotte@users.noreply.github.com >
Co-authored-by: Guy Ben-Aharon <baguy3@gmail.com >
Co-authored-by: Catminusminus <37803616+Catminusminus@users.noreply.github.com >
Co-authored-by: Lior Vaisman Argon <97836016+VaismanLior@users.noreply.github.com >
Co-authored-by: Matthieu Maitre <mmaitre@microsoft.com >
Co-authored-by: Andrea Scarpino <andrea@scarpino.dev >
Co-authored-by: MorAlon1 <101275199+MorAlon1@users.noreply.github.com >
Co-authored-by: liorj-orca <96177663+liorj-orca@users.noreply.github.com >
Co-authored-by: Nikita Pivkin <100182843+nikpivkin@users.noreply.github.com >
Co-authored-by: guangwu <guoguangwu@magic-shield.com >
Co-authored-by: Nikita Pivkin <nikita.pivkin@smartforce.io >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
Co-authored-by: yuriShafet <5830215+yuriShafet@users.noreply.github.com >
Co-authored-by: Octogonapus <firey45@gmail.com >
2024-02-19 11:16:35 +00:00
DmitriyLewen
32a02a95dd
docs(report): add remark about path to filter licenses using .trivyignore.yaml file ( #6145 )
2024-02-16 09:04:57 +00:00
Mike Thomas
fb79ea7c95
docs: update template path for gitlab-ci tutorial ( #6144 )
2024-02-16 08:58:08 +00:00
Kristina Trotsko
c6844a73f1
feat(report): support for filtering licenses and secrets via rego policy files ( #6004 )
2024-02-16 08:39:03 +00:00
DmitriyLewen
a813506f41
fix(cyclonedx): move root component from scanned cyclonedx file to output cyclonedx file ( #6113 )
2024-02-16 08:36:29 +00:00
simar7
14adbb4464
refactor(deps): Merge defsec into trivy ( #6109 )
...
Signed-off-by: Simar <simar@linux.com >
2024-02-16 08:31:32 +00:00
dependabot[bot]
efe0e0f8f3
chore(deps): bump helm.sh/helm/v3 from 3.14.0 to 3.14.1 ( #6142 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-15 17:24:09 +00:00
Stefan Fleckenstein
73dde32632
docs: add SecObserve in CI/CD and reporting ( #6139 )
2024-02-15 10:12:59 +00:00
DmitriyLewen
aadbad1d78
fix(alpine): exclude empty licenses for apk packages ( #6130 )
2024-02-14 10:57:25 +00:00
Anais Urlichs
14a0981efa
docs: add docs tutorial on custom policies with rego ( #6104 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
Co-authored-by: simar7 <1254783+simar7@users.noreply.github.com >
2024-02-14 08:40:11 +00:00
DmitriyLewen
3ac63887dc
fix(nodejs): use project dir when searching for workspaces for Yarn.lock files ( #6102 )
2024-02-13 13:39:43 +00:00
Teppei Fukuda
3c1601b6cb
feat(vuln): show suppressed vulnerabilities in table ( #6084 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
2024-02-13 12:35:06 +00:00
Teppei Fukuda
c107e1af29
docs: rename governance to principles ( #6107 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-02-12 14:27:35 +00:00
Teppei Fukuda
b26f217172
docs: add governance ( #6090 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-02-12 11:56:49 +00:00
simar7
7bd3b630bb
refactor(deps): Merge trivy-iac into Trivy ( #6005 )
2024-02-12 11:01:27 +00:00
DmitriyLewen
535b5a96d9
feat(java): add dependency location support for gradle files ( #6083 )
2024-02-08 09:43:35 +00:00
dependabot[bot]
428420ee84
chore(deps): bump github.com/aws/aws-sdk-go-v2/feature/s3/manager from 1.15.11 to 1.15.15 ( #6038 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-07 05:34:28 +00:00
DmitriyLewen
7fec991c58
fix(misconf): get user from Config.User ( #6070 )
2024-02-07 05:11:10 +00:00
DmitriyLewen
6ccc0a554b
fix: check unescaped BomRef when matching PkgIdentifier ( #6025 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-02-06 11:09:53 +00:00
Alexander Münch
458c5d95e6
docs: Fix broken link to "pronunciation" ( #6057 )
2024-02-06 11:09:08 +00:00
dependabot[bot]
5c0ff6dad1
chore(deps): bump actions/upload-artifact from 3 to 4 ( #6047 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-06 09:57:41 +00:00
dependabot[bot]
e2bd7f75d5
chore(deps): bump github.com/spf13/viper from 1.16.0 to 1.18.2 ( #6042 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-06 06:47:02 +00:00
dependabot[bot]
f95fbcb672
chore(deps): bump k8s.io/api from 0.29.0 to 0.29.1 ( #6043 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-06 03:37:41 +00:00
DmitriyLewen
7651bf59b2
ci: reduce root-reserve-mb size for maximize-build-space ( #6064 )
2024-02-05 13:09:15 +00:00
dependabot[bot]
fc20dfdd80
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.48.0 to 1.48.1 ( #6041 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-05 03:33:34 +00:00
dependabot[bot]
3bd80e7c28
chore(deps): bump github.com/open-policy-agent/opa from 0.60.0 to 0.61.0 ( #6039 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-05 03:33:05 +00:00
DmitriyLewen
2900a21176
fix: fix cursor usage in Redis Clear function ( #6056 )
2024-02-02 11:55:50 +00:00
dependabot[bot]
85cb9a7639
chore(deps): bump github.com/go-openapi/runtime from 0.26.0 to 0.27.1 ( #6037 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-02 11:52:05 +00:00
DmitriyLewen
4e962c02aa
fix(nodejs): add local packages support for pnpm-lock.yaml files ( #6034 )
2024-02-02 11:19:54 +00:00
dependabot[bot]
aa48a7b865
chore(deps): bump sigstore/cosign-installer from 3.3.0 to 3.4.0 ( #6046 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-02 11:04:16 +00:00
dependabot[bot]
8aabbea2d3
chore(deps): bump github.com/go-openapi/strfmt from 0.21.7 to 0.22.0 ( #6044 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-02 10:56:39 +00:00
dependabot[bot]
ec02a655af
chore(deps): bump actions/cache from 3.3.2 to 4.0.0 ( #6048 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-02 08:55:01 +00:00
DmitriyLewen
27d35baa4a
test: fix flaky TestDockerEngine ( #6054 )
2024-02-02 08:48:51 +00:00
dependabot[bot]
c3a66da9c3
chore(deps): bump github.com/google/go-containerregistry from 0.17.0 to 0.19.0 ( #6040 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-01 17:11:52 +00:00
dependabot[bot]
2000fe24c6
chore(deps): bump easimon/maximize-build-space from 9 to 10 ( #6049 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-01 17:10:37 +00:00
dependabot[bot]
2be642154f
chore(deps): bump alpine from 3.19.0 to 3.19.1 ( #6051 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-01 17:10:02 +00:00
dependabot[bot]
41c0ef642e
chore(deps): bump github.com/moby/buildkit from 0.11.6 to 0.12.5 ( #6028 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-02-01 12:13:26 +00:00
DmitriyLewen
729a0512ab
fix(java): recursive check all nested depManagements with import scope for pom.xml files ( #5982 )
2024-02-01 06:19:17 +00:00
dependabot[bot]
884745b5e5
chore(deps): bump github.com/opencontainers/runc from 1.1.5 to 1.1.12 ( #6029 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-01 04:00:55 +00:00
Teppei Fukuda
59e54334d1
fix(cli): inconsistent behavior across CLI flags, environment variables, and config files ( #5843 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-02-01 03:25:30 +00:00
Andrey Fedotov
5924c021da
feat(rust): Support workspace.members parsing for Cargo.toml analysis ( #5285 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-29 08:34:43 +00:00
Nikita Pivkin
4df9363890
docs: add note about Bun ( #6001 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-26 10:52:25 +00:00
DmitriyLewen
70dd572ef7
fix(report): use AWS_REGION env for secrets in asff template ( #6011 )
2024-01-26 08:19:27 +00:00
guangwu
13f797f885
fix: check returned error before deferring f.Close() ( #6007 )
...
Signed-off-by: guoguangwu <guoguangwu@magic-shield.com >
2024-01-26 07:57:37 +00:00
DmitriyLewen
adfde63d00
feat(misconf): add support of buildkit instructions when building dockerfile from image config ( #5990 )
2024-01-25 11:22:43 +00:00
Teppei Fukuda
e2eb70ecb8
feat(vuln): enable --vex for all targets ( #5992 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
2024-01-25 10:34:34 +00:00
Nikita Pivkin
f9da021315
docs: update link to data sources ( #6000 )
2024-01-25 10:23:32 +00:00
DmitriyLewen
b4b90cfe20
feat(java): add support for line numbers for pom.xml files ( #5991 )
2024-01-25 07:25:38 +00:00
DmitriyLewen
fb36c4ed09
refactor(sbom): use new metadata.tools struct for CycloneDX ( #5981 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-23 13:59:48 +00:00
Anais Urlichs
f6be42b71d
docs: Update troubleshooting guide with image not found error ( #5983 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-23 08:29:09 +00:00
Anais Urlichs
bb6caea5cb
style: update band logos ( #5968 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2024-01-23 06:45:55 +00:00
simar7
189a46a01c
chore(deps): Update misconfig deps ( #5956 )
2024-01-23 06:44:10 +00:00
Anais Urlichs
91a2547d15
docs: update cosign tutorial and commands, update kyverno policy ( #5929 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
Co-authored-by: saso <sasoakira6114@gmail.com >
2024-01-22 07:44:16 +00:00
Anais Urlichs
a96f66f176
docs: update command to scan go binary ( #5969 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2024-01-19 08:28:46 +00:00
chenk
2212d14432
fix: handle non-parsable images names ( #5965 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-01-19 08:27:35 +00:00
dependabot[bot]
7cad04bdf1
chore(deps): bump aquaproj/aqua-installer from 2.1.2 to 2.2.0 ( #5693 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-17 09:00:37 +00:00
DmitriyLewen
fbc1a83f32
fix(amazon): save system files for pkgs containing amzn in src ( #5951 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-17 06:57:41 +00:00
Devin Trejo
260aa281f4
fix(alpine): Add EOL support for alpine 3.19. ( #5938 )
...
Signed-off-by: Devin Trejo <dtrejo@palantir.com >
2024-01-16 07:59:08 +00:00
Bishwa Thapa
2c9d7c6b50
feat: allow end-users to adjust K8S client QPS and burst ( #5910 )
2024-01-15 19:08:52 +00:00
Nikita Pivkin
ffe2ca7cb5
chore(deps): bump go-ebs-file ( #5934 )
2024-01-15 10:32:24 +00:00
DmitriyLewen
f90d4ee436
fix(nodejs): find licenses for packages with slash ( #5836 )
2024-01-15 07:11:12 +00:00
DmitriyLewen
c75143f5e8
fix(sbom): use group field for pom.xml and nodejs files for CycloneDX reports ( #5922 )
2024-01-15 06:57:46 +00:00
chenk
a3fac90b47
fix: ignore no init containers ( #5939 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-01-15 06:14:57 +00:00
Fatih Tokus
b1b4734f55
docs: Fix documentation of ecosystem ( #5940 )
2024-01-15 06:13:27 +00:00
Laurent Commarieu
a2b654945a
docs(misconf): multiple ignores in comment ( #5926 )
2024-01-12 04:36:55 +00:00
DmitriyLewen
ae134a9b38
fix(secret): find aws secrets ending with a comma or dot ( #5921 )
2024-01-11 08:00:33 +00:00
dependabot[bot]
c8c55fe21e
chore(deps): bump github.com/aws/aws-sdk-go-v2/feature/s3/manager from 1.11.90 to 1.15.11 ( #5885 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Simar <simar@linux.com >
2024-01-11 07:30:40 +00:00
mfreeman451
4d2e785ff2
docs: ✨ Updated ecosystem docs with reference to new community app ( #5918 )
2024-01-11 07:25:44 +00:00
DmitriyLewen
7895657c89
fix(java): don't remove excluded deps from upper pom's ( #5838 )
2024-01-10 09:39:52 +00:00
DmitriyLewen
37e7e3eabf
fix(java): check if a version exists when determining GAV by file name for jar files ( #5630 )
2024-01-10 07:22:50 +00:00
Teppei Fukuda
d0c81e23c4
feat(vex): add PURL matching for CSAF VEX ( #5890 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-01-10 06:37:19 +00:00
DmitriyLewen
958e1f11f7
fix(secret): AWS Secret Access Key must include only secrets with aws text. ( #5901 )
2024-01-09 11:51:30 +00:00
DmitriyLewen
56c4e248aa
revert(report): don't escape new line characters for sarif format ( #5897 )
2024-01-09 11:50:35 +00:00
Itay Shakury
92d9b3dbba
docs: improve filter by rego ( #5402 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-09 05:52:03 +00:00
dependabot[bot]
a626cdf334
chore(deps): bump github.com/cloudflare/circl from 1.3.6 to 1.3.7 ( #5892 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-08 17:33:06 +00:00
Fatih Tokus
47b6c2817a
docs: add_scan2html_to_trivy_ecosystem ( #5875 )
2024-01-08 10:33:20 +00:00
yusuke-koyoshi
0ebb6c4682
fix(vm): update ext4-filesystem fix reading groupdescriptor in 32bit mode ( #5888 )
2024-01-08 06:06:37 +00:00
Juan Ariza Toledano
c47ed0d816
feat(vex): Add support for CSAF format ( #5535 )
...
Signed-off-by: juan131 <jariza@vmware.com >
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-06 10:48:39 +00:00
dependabot[bot]
2cdd65dd64
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/sts from 1.26.2 to 1.26.7 ( #5880 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-05 19:38:44 +00:00
dependabot[bot]
cba67d1f06
chore(deps): bump actions/setup-go from 4 to 5 ( #5845 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-05 16:31:44 +00:00
dependabot[bot]
d990e702a2
chore(deps): bump actions/stale from 8 to 9 ( #5846 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-05 12:35:25 +00:00
dependabot[bot]
c72dfbfbb0
chore(deps): bump github.com/open-policy-agent/opa from 0.58.0 to 0.60.0 ( #5853 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-05 12:31:33 +00:00
dependabot[bot]
121898423b
chore(deps): bump sigstore/cosign-installer from 3.2.0 to 3.3.0 ( #5847 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-05 12:31:32 +00:00
dependabot[bot]
682210ac64
chore(deps): bump modernc.org/sqlite from 1.23.1 to 1.28.0 ( #5854 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-04 19:10:54 +00:00
dependabot[bot]
e1a60cc88c
chore(deps): bump alpine from 3.18.5 to 3.19.0 ( #5849 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-04 19:03:00 +00:00
dependabot[bot]
b508414ca2
chore(deps): bump actions/setup-python from 4 to 5 ( #5848 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-04 19:01:57 +00:00
Nikita Pivkin
df3e90af8f
feat(python): parse licenses from dist-info folder ( #4724 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-04 18:20:55 +00:00
dependabot[bot]
fa2e88360b
chore(deps): bump github.com/secure-systems-lab/go-securesystemslib from 0.7.0 to 0.8.0 ( #5852 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-04 09:29:08 +00:00
DmitriyLewen
30eff9c83e
feat(nodejs): add yarn alias support ( #5818 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-04 05:16:35 +00:00
dependabot[bot]
013df4c6b8
chore(deps): bump github.com/samber/lo from 1.38.1 to 1.39.0 ( #5850 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-04 05:12:39 +00:00
dependabot[bot]
b1489f3485
chore(deps): bump github.com/hashicorp/go-getter from 1.7.2 to 1.7.3 ( #5856 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-03 11:53:52 +00:00
dependabot[bot]
7f2e4223ff
chore(deps): bump google.golang.org/protobuf from 1.31.0 to 1.32.0 ( #5855 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-03 11:43:57 +00:00
Teppei Fukuda
da597c479c
refactor: propagate time through context values ( #5858 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-01-03 09:43:45 +00:00
Teppei Fukuda
1607eee77c
refactor: move PkgRef under PkgIdentifier ( #5831 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-12-29 06:52:36 +00:00
DmitriyLewen
b3d516eafe
fix(cyclonedx): fix unmarshal for licenses ( #5828 )
2023-12-29 05:28:13 +00:00
dependabot[bot]
c17b6603db
chore(deps): bump github.com/go-git/go-git/v5 from 5.10.1 to 5.11.0 ( #5830 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-29 05:26:15 +00:00
Juan Ariza Toledano
1f0d6290c3
feat(vuln): include pkg identifier on detected vulnerabilities ( #5439 )
...
Signed-off-by: juan131 <jariza@vmware.com >
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
Co-authored-by: Nikita Pivkin <nikita.pivkin@smartforce.io >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-12-27 07:54:56 +00:00
Nikita Pivkin
4cdff0e573
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from v1.116.0 to v1.134.0 ( #5822 )
2023-12-26 12:09:43 +00:00
dependabot[bot]
be969d4136
chore(deps): bump github.com/containerd/containerd from 1.7.7 to 1.7.11 ( #5809 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-25 06:13:16 +00:00
dependabot[bot]
81748f5ad0
chore(deps): bump golang.org/x/crypto from 0.15.0 to 0.17.0 ( #5805 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-19 07:59:21 +00:00
Nikita Pivkin
ba825b2ae1
chore(deps): bump trivy-iac to v0.7.1 ( #5797 )
2023-12-18 12:31:07 +00:00
Juan Ariza Toledano
abf227e06e
fix(bitnami): use a different comparer for detecting vulnerabilities ( #5633 )
...
Signed-off-by: juan131 <jariza@vmware.com >
2023-12-17 10:27:19 +00:00
DmitriyLewen
df49ea4a14
refactor(sbom): disable html escaping for CycloneDX ( #5764 )
2023-12-17 09:25:08 +00:00
DmitriyLewen
f25e2df1c0
refactor(purl): use pub from package-url ( #5784 )
2023-12-13 12:07:31 +00:00
DmitriyLewen
b5e3b77f0f
docs(python): add note to using pip freeze for compatible releases ( #5760 )
2023-12-13 09:39:00 +00:00
DmitriyLewen
6cc00c2f0c
fix(report): use OS information for OS packages purl in github template ( #5783 )
2023-12-13 09:37:14 +00:00
DmitriyLewen
c317fe828d
fix(report): fix error if miconfigs are empty ( #5782 )
2023-12-13 09:34:37 +00:00
DmitriyLewen
9b4bcedf0e
refactor(vuln): don't remove VendorSeverity in JSON report ( #5761 )
2023-12-12 12:33:41 +00:00
DmitriyLewen
be5a550491
fix(report): don't mark misconfig passed tests as failed in junit.tpl ( #5767 )
2023-12-12 12:30:26 +00:00
Veronika Priesner
01edbda347
docs(k8s): replace --scanners config with --scanners misconfig in docs ( #5746 )
2023-12-07 12:12:26 +00:00
Dirk Klimpel
eb9741954c
fix(report): update Gitlab template ( #5721 )
2023-12-07 11:13:43 +00:00
Sourav Patnaik
be1c55497f
feat(secret): add support of GitHub fine-grained tokens ( #5740 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-12-07 10:45:22 +00:00
Nikita Pivkin
a5342da067
fix(misconf): add an image misconf to result ( #5731 )
2023-12-06 07:07:31 +00:00
Sourav Patnaik
108a5b05ce
feat(secret): added support of Docker registry credentials ( #5720 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-12-06 07:04:19 +00:00
dependabot[bot]
6080e245ce
chore(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.18.45 to 1.25.11 ( #5717 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-05 09:38:17 +00:00
dependabot[bot]
e27ec3261e
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ecr from 1.21.0 to 1.24.1 ( #5701 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-05 08:52:06 +00:00
dependabot[bot]
f2aa9bf3eb
chore(deps): bump sigstore/cosign-installer from 4a861528be5e691840a69536975ada1d4c30349d to 1fc5bd396d372bee37d608f955b336615edf79c8 ( #5696 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-05 07:18:38 +00:00
dependabot[bot]
6d7e2f8116
chore(deps): bump helm/chart-testing-action from 2.4.0 to 2.6.1 ( #5694 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-05 07:18:17 +00:00
chenk
0ff5f96bb7
feat: filter k8s core components vuln results ( #5713 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-12-05 07:17:51 +00:00
Andrea Scarpino
a54d1e95fd
feat(vuln): remove duplicates in Fixed Version ( #5596 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-12-04 16:29:14 +00:00
Teppei Fukuda
99c04c4383
feat(report): output plugin ( #4863 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-12-04 11:04:43 +00:00
dependabot[bot]
70078b9c0e
chore(deps): bump alpine from 3.18.4 to 3.18.5 ( #5700 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-04 10:37:26 +00:00
dependabot[bot]
49e83a6ad2
chore(deps): bump github.com/google/go-containerregistry from 0.16.1 to 0.17.0 ( #5704 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-04 10:36:06 +00:00
dependabot[bot]
af32cb310a
chore(deps): bump github.com/go-git/go-git/v5 from 5.8.1 to 5.10.1 ( #5699 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-04 10:32:05 +00:00
dependabot[bot]
176627192f
chore(deps): bump actions/github-script from 6 to 7 ( #5697 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-04 10:29:43 +00:00
dependabot[bot]
7ee854767e
chore(deps): bump easimon/maximize-build-space from 8 to 9 ( #5695 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-04 10:28:13 +00:00
Reo Uehara
654147fc60
docs: typo in modules.md ( #5712 )
2023-12-04 10:25:18 +00:00
chenk
256957523a
feat: Add flag to configure node-collector image ref ( #5710 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-12-04 10:25:12 +00:00
dependabot[bot]
c0610097a6
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azcore from 1.7.1 to 1.9.0 ( #5702 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-04 09:46:51 +00:00
dependabot[bot]
aedbd85d6e
chore(deps): bump github.com/alicebob/miniredis/v2 from 2.30.4 to 2.31.0 ( #5698 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-04 03:38:34 +00:00
dependabot[bot]
e018b9c423
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azidentity from 1.3.1 to 1.4.0 ( #5706 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-04 03:37:58 +00:00
simar7
b5874e3ad3
feat(misconf): Add --misconfig-scanners option ( #5670 )
2023-11-29 23:59:17 +00:00
Teppei Fukuda
075d8f6286
chore: bump Go to 1.21 ( #5662 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-28 04:01:54 +00:00
yuriShafet
16b757d180
feat: Packagesprops support ( #5605 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-11-28 01:23:47 +00:00
simar7
372efc9ec7
chore(deps): Bump up trivy misconf deps ( #5656 )
2023-11-28 00:47:23 +00:00
Anais Urlichs
edad5f6902
docs: update adopters discussion template ( #5632 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2023-11-27 01:29:32 +00:00
Kyle Davies
ed9d34030d
docs: terraform tutorial links updated to point to correct loc ( #5661 )
2023-11-27 01:29:22 +00:00
DmitriyLewen
8ff574e3f7
fix(secret): add sec and space to secret prefix for aws-secret-access-key ( #5647 )
2023-11-26 05:12:06 +00:00
DmitriyLewen
ad977a4256
fix(nodejs): support protocols for dependency section in yarn.lock files ( #5612 )
2023-11-22 01:44:45 +00:00
DmitriyLewen
b1dc60b885
fix(secret): exclude upper case before secret for alibaba-access-key-id ( #5618 )
2023-11-22 01:43:59 +00:00
Felix Yan
65351d4f2a
docs: Update Arch Linux package URL in installation.md ( #5619 )
2023-11-22 01:23:56 +00:00
Teppei Fukuda
c866f1c4e9
chore: add prefix to image errors ( #5601 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-20 12:38:45 +00:00
Tom Janson
ed0022b915
docs(vuln): fix link anchor ( #5606 )
2023-11-20 01:13:27 +00:00
Jeremy Adams
3c81727034
docs: Add Dagger integration section and cleanup Ecosystem CICD docs page ( #5608 )
...
Signed-off-by: Jeremy Adams <jeremy@dagger.io >
2023-11-20 00:54:26 +00:00
chenk
214546427e
fix: k8s friendly error messages kbom non cluster scans ( #5594 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-11-16 06:41:45 +00:00
Sylvain Baubeau
44d0b28ada
feat: set InstalledFiles for DEB and RPM packages ( #5488 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-11-16 06:37:39 +00:00
Teppei Fukuda
ae4bcf6a06
fix(report): use time.Time for CreatedAt ( #5598 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-16 05:42:30 +00:00
Teppei Fukuda
b6fafa04a2
test: retry containerd initialization ( #5597 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-16 04:17:59 +00:00
simar7
13362233c8
feat(misconf): Expose misconf engine debug logs with --debug option ( #5550 )
...
Signed-off-by: Simar <simar@linux.com >
2023-11-16 02:29:38 +00:00
Teppei Fukuda
71051863c6
test: mock VM walker ( #5589 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-16 00:49:38 +00:00
chenk
d9d7f3f190
chore: bump node-collector v0.0.9 ( #5591 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-11-16 00:48:56 +00:00
simar7
e3c28f8ee3
feat(misconf): Add support for --cf-params for CFT ( #5507 )
...
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: nikpivkin <nikita.pivkin@smartforce.io >
2023-11-15 07:04:22 +00:00
Teppei Fukuda
ac0e327492
feat(flag): replace '--slow' with '--parallel' ( #5572 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-15 06:41:13 +00:00
DmitriyLewen
5372067611
fix(report): add escaping for Sarif format ( #5568 )
2023-11-15 04:29:23 +00:00
Teppei Fukuda
a3895298de
chore: show a deprecation notice for --scanners config ( #5587 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-15 04:20:40 +00:00
Y.Horie
f4dd062f58
feat(report): Add CreatedAt to the JSON report. ( #5542 ) ( #5549 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-11-15 04:11:09 +00:00
Teppei Fukuda
d005f5af24
test: mock RPM DB ( #5567 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-15 03:06:49 +00:00
Teppei Fukuda
a96ec35572
feat: add aliases to '--scanners' ( #5558 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-15 00:53:22 +00:00
Teppei Fukuda
950e431f0f
refactor: reintroduce output writer ( #5564 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-14 12:32:23 +00:00
dependabot[bot]
2310f0dd69
chore(deps): bump google.golang.org/grpc from 1.58.2 to 1.58.3 ( #5543 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-14 07:50:00 +00:00
Teppei Fukuda
04b93e9fd6
chore: not load plugins for auto-generating docs ( #5569 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-14 05:37:18 +00:00
Teppei Fukuda
cccaa15ccd
chore: sort supported AWS services ( #5570 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-14 05:35:42 +00:00
chenk
3891e3d5d4
fix: no schedule toleration ( #5562 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-11-14 02:42:40 +00:00
DmitriyLewen
138feb024c
fix(cli): set correct scanners for k8s target ( #5561 )
2023-11-13 07:24:22 +00:00
DmitriyLewen
cb241a8007
fix(sbom): add FilesAnalyzed and PackageVerificationCode fields for SPDX ( #5533 )
2023-11-09 09:25:27 +00:00
simar7
e7f6a5c805
refactor(misconf): Update refactored dependencies ( #5245 )
...
Signed-off-by: Simar <simar@linux.com >
2023-11-09 02:24:52 +00:00
very-doge-wow
2f5afa5f29
feat(secret): add built-in rule for JWT tokens ( #5480 )
2023-11-09 01:34:52 +00:00
chenk
91fc8dac92
fix: trivy k8s parse ecr image with arn ( #5537 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-11-09 01:05:45 +00:00
chenk
05df24477e
fix: fail k8s resource scanning ( #5529 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-11-08 05:39:53 +00:00
DmitriyLewen
a1b47441a5
refactor(misconf): don't remove Highlighted in json format ( #5531 )
2023-11-07 23:40:42 +00:00
Tom Janson
7712f8f216
docs(k8s): fix link in kubernetes.md ( #5524 )
2023-11-07 01:18:44 +00:00
Tom Janson
043fbfcd38
docs(k8s): fix whitespace in list syntax ( #5525 )
2023-11-07 00:38:39 +00:00
DmitriyLewen
d6df5fbcda
docs: add info that license scanning supports file-patterns flag ( #5484 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2023-11-06 04:55:08 +00:00
Matheus Moraes
156d4cc605
docs: add Zora integration into Ecosystem session ( #5490 )
2023-11-06 04:54:48 +00:00
DmitriyLewen
772d1d08f8
fix(sbom): Use UUID as BomRef for packages with empty purl ( #5448 )
2023-11-06 03:29:13 +00:00
Nikita Pivkin
df47073fa4
ci: use maximize build space for K8s tests ( #5387 )
2023-11-06 03:25:58 +00:00
Sylvain Baubeau
fed4710188
fix: correct error mismatch causing race in fast walks ( #5516 )
2023-11-06 02:31:12 +00:00
chenk
46f1b9e7dc
docs: k8s vulnerability scanning ( #5515 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-11-06 02:30:07 +00:00
dependabot[bot]
fdb3a15b2d
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/sts from 1.23.2 to 1.25.0 ( #5506 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-03 23:58:20 +00:00
dependabot[bot]
d0d956fdc1
chore(deps): bump github.com/owenrumney/go-sarif/v2 from 2.2.2 to 2.3.0 ( #5493 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-11-03 01:38:04 +00:00
DmitriyLewen
68b0797e5b
docs: remove glad for java datasources ( #5508 )
2023-11-03 01:37:35 +00:00
dependabot[bot]
474167c47e
chore(deps): bump github.com/testcontainers/testcontainers-go/modules/localstack from 0.21.0 to 0.26.0 ( #5475 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-11-03 01:36:27 +00:00
Sylvain Baubeau
7299867c21
chore: remove unused logger attribute in amazon detector ( #5476 )
2023-11-02 04:14:54 +00:00
Sylvain Baubeau
8656bd9f77
fix: correct error mismatch causing race in fast walks ( #5482 )
2023-11-02 04:14:16 +00:00
dependabot[bot]
2e10cd2eba
chore(deps): bump goreleaser/goreleaser-action from 4 to 5 ( #5502 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-02 03:52:43 +00:00
dependabot[bot]
13df746527
chore(deps): bump docker/build-push-action from 4 to 5 ( #5500 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-02 01:55:00 +00:00
dependabot[bot]
b0141cfbaa
chore(deps): bump github.com/package-url/packageurl-go from 0.1.2-0.20230812223828-f8bb31c1f10b to 0.1.2 ( #5491 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-02 01:52:57 +00:00
Nikita Pivkin
520830b51b
fix(server): add licenses to BlobInfo message ( #5382 )
2023-11-02 01:46:32 +00:00
dependabot[bot]
9a6e125c78
chore(deps): bump actions/checkout from 4.1.0 to 4.1.1 ( #5501 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-02 01:09:38 +00:00
dependabot[bot]
6e5927266c
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ecr from 1.17.18 to 1.21.0 ( #5497 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-02 01:09:25 +00:00
chenk
f3de7bc3be
feat: scan vulns on k8s core component apps ( #5418 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-11-01 09:31:48 +00:00
DmitriyLewen
e2fb3dd58f
fix(java): fix infinite loop when relativePath field points to pom.xml being scanned ( #5470 )
2023-10-31 01:47:58 +00:00
dependabot[bot]
3e833be7d8
chore(deps): bump github.com/docker/docker from 24.0.5+incompatible to 24.0.7+incompatible ( #5472 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-31 01:46:24 +00:00
DmitriyLewen
ca50b77a35
fix(sbom): save digests for package/application when scanning SBOM files ( #5432 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-10-28 04:09:36 +00:00
Takahiro Tsuruda
048150d433
docs: fix the broken link ( #5454 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-10-28 04:06:11 +00:00
DmitriyLewen
013d901993
docs: fix error when installing PyYAML for gh pages ( #5462 )
2023-10-28 03:32:13 +00:00
DmitriyLewen
26b4959541
fix(java): download java-db once ( #5442 )
2023-10-26 01:50:32 +00:00
dependabot[bot]
57fa701a87
chore(deps): bump google.golang.org/grpc from 1.57.0 to 1.57.1 ( #5447 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-26 00:42:55 +00:00
simar7
53c9a7d762
docs(misconf): Update --tf-exclude-downloaded-modules description ( #5419 )
2023-10-24 13:03:02 +00:00
simar7
01c98d1516
feat(misconf): Support --ignore-policy in config scans ( #5359 )
...
Signed-off-by: Simar <simar@linux.com >
2023-10-23 07:32:08 +00:00
yoshinorin
05b3c86a14
docs(misconf): fix broken table for Use container image section ( #5425 )
2023-10-23 06:10:39 +00:00
DmitriyLewen
1a15a3adb1
feat(dart): add graph support ( #5374 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-10-20 09:16:23 +00:00
Teppei Fukuda
f2a12f5f90
refactor: define a new struct for scan targets ( #5397 )
2023-10-20 01:43:15 +00:00
DmitriyLewen
6040d9f43a
fix(sbom): add missed primaryURL and source severity for CycloneDX ( #5399 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-10-19 05:37:32 +00:00
Erick Redwine
e5317c7bc2
fix: correct invalid MD5 hashes for rpms ending with one or more zero bytes ( #5393 )
2023-10-19 03:29:54 +00:00
Sylvain Baubeau
9fba79f0b6
chore(deps): move to aws-sdk-go-v2 ( #5381 )
2023-10-18 14:21:56 +00:00
Nikita Pivkin
00f2059e5d
docs: remove --scanners none ( #5384 )
2023-10-17 02:34:30 +00:00
mehrdadbn9
57a1022318
docs: Update container_image.md #5182 ( #5193 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2023-10-16 06:22:33 +00:00
AliDatadog
5b2b4ea380
feat(report): Add InstalledFiles field to Package ( #4706 )
...
Co-authored-by: Sylvain Baubeau <lebauce@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-10-16 06:15:23 +00:00
Teppei Fukuda
cbbd1ce1f0
feat(k8s): add support for vulnerability detection ( #5268 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Signed-off-by: chenk <hen.keinan@gmail.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
Co-authored-by: chenk <hen.keinan@gmail.com >
2023-10-14 12:32:55 +00:00
DmitriyLewen
24a0d92145
fix(python): override BOM in requirements.txt files ( #5375 )
2023-10-14 08:37:32 +00:00
Itay Shakury
0c3e2f08b7
docs: add kbom documentation ( #5363 )
2023-10-13 09:00:28 +00:00
DmitriyLewen
6c12f04286
test: use maximize build space for VM tests ( #5362 )
2023-10-13 01:42:57 +00:00
dependabot[bot]
c4134224a2
chore(deps): bump golang.org/x/net from 0.15.0 to 0.17.0 ( #5365 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-12 15:45:22 +00:00
DmitriyLewen
20ab7033b8
fix(report): add escaping quotes in misconfig Title for asff template ( #5351 )
2023-10-11 07:38:07 +00:00
DmitriyLewen
91841f59ba
ci: add workflow to check Go versions of dependencies ( #5340 )
2023-10-09 11:04:09 +00:00
simar7
57ba05c766
chore(deps): Upgrade defsec to v0.93.1 ( #5348 )
2023-10-08 12:40:21 +00:00
dependabot[bot]
fef3ed4358
chore(deps): bump alpine from 3.18.3 to 3.18.4 ( #5300 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-06 06:07:11 +00:00
Doug Donohoe
ced54aced1
fix: Report error when os.CreateTemp fails (to be consistent with other uses) ( #5342 )
2023-10-05 14:45:45 +00:00
Nikita Pivkin
2798df916b
fix: add config files to FS for post-analyzers ( #5333 )
2023-10-05 12:59:47 +00:00
DmitriyLewen
af485b33fd
fix: fix MIME warnings after updating to Go 1.20 ( #5336 )
2023-10-05 12:58:40 +00:00
Teppei Fukuda
008babfb8b
build: fix a compile error with Go 1.21 ( #5339 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-10-05 10:06:32 +00:00
Alexandr Hacicheant
00d9c4666f
feat: added Metadata into the k8s resource's scan report ( #5322 )
2023-10-05 08:16:50 +00:00
DmitriyLewen
03b6787c44
ci: check only PR's in actions/stale ( #5337 )
2023-10-05 07:36:02 +00:00
Itay Shakury
e6d5889ed4
chore: update adopters template ( #5330 )
2023-10-04 12:13:20 +00:00
Teppei Fukuda
74dbd8a1fd
ci: do not trigger tests on the push event ( #5313 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-10-03 11:10:05 +00:00
j1nka
393bfdc1ac
fix(sbom): use PURL or Group and Name in case of Java ( #5154 )
2023-10-03 11:06:27 +00:00
Anais Urlichs
76eb8a57b6
docs: add buildkite repository to ecosystem page ( #5316 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2023-10-03 09:02:52 +00:00
dependabot[bot]
6c74ee11f0
chore(deps): bump docker/setup-qemu-action from 2 to 3 ( #5290 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-03 09:01:37 +00:00
dependabot[bot]
6119878de1
chore(deps): bump docker/setup-buildx-action from 2 to 3 ( #5292 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-03 08:25:12 +00:00
dependabot[bot]
a346587b8d
chore(deps): bump actions/cache from 3.3.1 to 3.3.2 ( #5293 )
...
Bumps [actions/cache](https://github.com/actions/cache ) from 3.3.1 to 3.3.2.
- [Release notes](https://github.com/actions/cache/releases )
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md )
- [Commits](https://github.com/actions/cache/compare/v3.3.1...v3.3.2 )
---
updated-dependencies:
- dependency-name: actions/cache
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 15:54:49 +00:00
dependabot[bot]
7e613cc5f7
chore(deps): bump github.com/google/uuid from 1.3.0 to 1.3.1 ( #5286 )
...
Bumps [github.com/google/uuid](https://github.com/google/uuid ) from 1.3.0 to 1.3.1.
- [Release notes](https://github.com/google/uuid/releases )
- [Changelog](https://github.com/google/uuid/blob/master/CHANGELOG.md )
- [Commits](https://github.com/google/uuid/compare/v1.3.0...v1.3.1 )
---
updated-dependencies:
- dependency-name: github.com/google/uuid
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 15:45:32 +00:00
dependabot[bot]
f05bc4be4f
chore(deps): bump github.com/hashicorp/go-getter from 1.7.1 to 1.7.2 ( #5289 )
...
Bumps [github.com/hashicorp/go-getter](https://github.com/hashicorp/go-getter ) from 1.7.1 to 1.7.2.
- [Release notes](https://github.com/hashicorp/go-getter/releases )
- [Changelog](https://github.com/hashicorp/go-getter/blob/main/.goreleaser.yml )
- [Commits](https://github.com/hashicorp/go-getter/compare/v1.7.1...v1.7.2 )
---
updated-dependencies:
- dependency-name: github.com/hashicorp/go-getter
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 15:45:07 +00:00
Teppei Fukuda
3be5e6b242
chore: enable go-critic ( #5302 )
...
* chore: enable gocritic
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* refactor: fix lint issues
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* test: return true for latest versions
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* chore(lint): enforce map and slice styles
Signed-off-by: knqyf263 <knqyf263@gmail.com >
---------
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-10-02 08:33:21 +00:00
dependabot[bot]
f6cd21c873
chore(deps): bump actions/checkout from 3.6.0 to 4.1.0 ( #5288 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 3.6.0 to 4.1.0.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v3.6.0...v4.1.0 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 08:31:07 +00:00
dependabot[bot]
f7b975187d
chore(deps): bump github.com/aws/aws-sdk-go from 1.45.3 to 1.45.19 ( #5287 )
...
Bumps [github.com/aws/aws-sdk-go](https://github.com/aws/aws-sdk-go ) from 1.45.3 to 1.45.19.
- [Release notes](https://github.com/aws/aws-sdk-go/releases )
- [Commits](https://github.com/aws/aws-sdk-go/compare/v1.45.3...v1.45.19 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 07:35:19 +00:00
DmitriyLewen
18d168769c
close java-db client ( #5273 )
2023-10-02 06:56:33 +00:00
dependabot[bot]
eb60e9f3c0
chore(deps): bump docker/login-action from 2 to 3 ( #5291 )
...
Bumps [docker/login-action](https://github.com/docker/login-action ) from 2 to 3.
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](https://github.com/docker/login-action/compare/v2...v3 )
---
updated-dependencies:
- dependency-name: docker/login-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 05:20:14 +00:00
dependabot[bot]
5a92055e1c
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/sts ( #5294 )
...
Bumps [github.com/aws/aws-sdk-go-v2/service/sts](https://github.com/aws/aws-sdk-go-v2 ) from 1.21.5 to 1.22.0.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/service/s3/v1.22.0/CHANGELOG.md )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/efs/v1.21.5...service/s3/v1.22.0 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/service/sts
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 05:19:08 +00:00
dependabot[bot]
46afe65eed
chore(deps): bump github.com/sigstore/rekor from 1.2.1 to 1.3.0 ( #5304 )
...
Bumps [github.com/sigstore/rekor](https://github.com/sigstore/rekor ) from 1.2.1 to 1.3.0.
- [Release notes](https://github.com/sigstore/rekor/releases )
- [Changelog](https://github.com/sigstore/rekor/blob/main/CHANGELOG.md )
- [Commits](https://github.com/sigstore/rekor/compare/v1.2.1...v1.3.0 )
---
updated-dependencies:
- dependency-name: github.com/sigstore/rekor
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 05:18:49 +00:00
dependabot[bot]
0bf2a11a2e
chore(deps): bump github.com/opencontainers/image-spec ( #5295 )
...
Bumps [github.com/opencontainers/image-spec](https://github.com/opencontainers/image-spec ) from 1.1.0-rc4 to 1.1.0-rc5.
- [Release notes](https://github.com/opencontainers/image-spec/releases )
- [Changelog](https://github.com/opencontainers/image-spec/blob/main/RELEASES.md )
- [Commits](https://github.com/opencontainers/image-spec/compare/v1.1.0-rc4...v1.1.0-rc5 )
---
updated-dependencies:
- dependency-name: github.com/opencontainers/image-spec
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 05:18:09 +00:00
Ignacio Íñigo Hernández
23b5fece08
fix(report): removes git::http from uri in sarif ( #5244 )
...
* fix(sarif): removes git::http from uri in sarif
* fix(sarif): removes git::http from uri in sarif
## Description
## Related issues
- Fixes https://github.com/aquasecurity/trivy/issues/5003
## Checklist
- [ ] I've read the [guidelines for contributing](https://aquasecurity.github.io/trivy/latest/community/contribute/pr/ ) to this repository.
- [ ] I've followed the [conventions](https://aquasecurity.github.io/trivy/latest/community/contribute/pr/#title ) in the PR title.
- [ ] I've added tests that prove my fix is effective or that my feature works.
- [ ] I've updated the [documentation](https://github.com/aquasecurity/trivy/blob/main/docs ) with the relevant information (if needed).
- [ ] I've added usage information (if the PR introduces new options)
- [ ] I've included a "before" and "after" example to the description (if the PR is a user interface change).
* fix lint
---------
Co-authored-by: Simar <simar@linux.com >
2023-10-02 05:17:43 +00:00
PranitRout07
4f1d576e5a
Improve the meaning of sentence ( #5301 )
...
Sentence has incomplete meaning .
Go to this link to see the issue: https://aquasecurity.github.io/trivy/v0.45/tutorials/kubernetes/gitops/
2023-10-01 18:13:12 +00:00
dependabot[bot]
6ab2bdfa7c
chore(deps): bump github.com/owenrumney/go-sarif/v2 from 2.2.0 to 2.2.2 ( #5297 )
...
Bumps [github.com/owenrumney/go-sarif/v2](https://github.com/owenrumney/go-sarif ) from 2.2.0 to 2.2.2.
- [Release notes](https://github.com/owenrumney/go-sarif/releases )
- [Changelog](https://github.com/owenrumney/go-sarif/blob/main/.goreleaser.yml )
- [Commits](https://github.com/owenrumney/go-sarif/compare/v2.2.0...v2.2.2 )
---
updated-dependencies:
- dependency-name: github.com/owenrumney/go-sarif/v2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-01 17:43:34 +00:00
dependabot[bot]
4217cffb5a
chore(deps): bump golang.org/x/term from 0.11.0 to 0.12.0 ( #5296 )
...
Bumps [golang.org/x/term](https://github.com/golang/term ) from 0.11.0 to 0.12.0.
- [Commits](https://github.com/golang/term/compare/v0.11.0...v0.12.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/term
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-01 17:30:33 +00:00
DmitriyLewen
1840584703
add app nil check ( #5274 )
2023-10-01 07:36:59 +00:00
Erik McKelvey
c5ae9f265f
typo: in secret.md ( #5281 )
2023-10-01 07:27:47 +00:00
DmitriyLewen
562723f0a7
docs: add info about github format ( #5265 )
...
* docs: add info about github format
* rename `GitHub SBOM` to `GitHub dependency snapshots`
2023-09-28 18:40:45 +00:00
DmitriyLewen
3dd5b1e946
feat(dotnet): add license support for NuGet ( #5217 )
...
* add nuspec files support
* docs: docs, log messages, comments refactoring
* save found licences to use next time
* refactor
* refactor
* fix typo
2023-09-28 08:13:31 +00:00
Itay Shakury
5c18475f37
docs: correctly export variables ( #5260 )
...
missing = in variable definition
2023-09-28 07:15:48 +00:00
simar7
0c08dde015
chore: Add line numbers for lint output ( #5247 )
...
* fix(github): Add line numbers for lint output
* correctional message check
* update messaging
2023-09-28 07:12:47 +00:00
DmitriyLewen
0ccbb4f7fd
chore(cli): disable java-db flags in server mode ( #5263 )
...
* disable java-db flag for server mode
* update docs
2023-09-28 07:10:14 +00:00
Michel Meyer
908a4914c7
feat(db): allow passing registry options ( #5226 )
...
* feat(db): allow passing registry options
Signed-off-by: Michel Meyer <meyer_michel@outlook.com >
* feat(db): pass cli registry options to javaDB
---------
Signed-off-by: Michel Meyer <meyer_michel@outlook.com >
2023-09-27 13:17:11 +00:00
simar7
5b4652d796
chore(deps): Bump up defsec to v0.93.0 ( #5253 )
2023-09-27 06:43:55 +00:00
DmitriyLewen
faf8d49c49
refactor(purl): use TypeApk from purl ( #5232 )
...
* use TypeApk from purl
* refactor: some tweaks
Signed-off-by: knqyf263 <knqyf263@gmail.com >
---------
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-09-26 08:55:23 +00:00
DmitriyLewen
559c0f30b1
chore: enable more linters ( #5228 )
...
* chore: enable more linters
* fix typos
* ci: add `verbose` option in linter action
* ci: remove `verbose` option in linter action
2023-09-26 06:20:54 +00:00
Nikita Pivkin
2baad46189
ci: bump GoReleaser from 1.16.2 to 1.20.0 ( #5236 )
...
* chore: replace brews.tap with brews.repository
* ci: bump GoReleaser from 1.16.2 to 1.20.0
2023-09-25 19:08:53 +00:00
za
df2bff9f5e
Fix typo on ide.md ( #5239 )
...
mange -> manage.
2023-09-25 19:05:22 +00:00
Teppei Fukuda
44656f2853
refactor: use defined types ( #5225 )
...
* refactor: replace string with defined types
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* chore: add gci
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* fix(purl): not confuse trivy type with purl type
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* test: fix cyclonedx fixture
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* fix(template): cast TargetType to string
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* chore: bump TinyGo to v0.29.0
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* test: change license to licence
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* use `analyzer.TypeGoMod` for gomod analyzer
* ignore `licence` for misspell linter
---------
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-09-22 10:44:39 +00:00
Javier Freire Riobó
37af529947
fix(purl): skip local Go packages ( #5190 )
...
* fix(purl): trim a final slash
* fix(purl): skip local Go packages
* fix(purl): a few improvements
2023-09-20 14:19:21 +00:00
Nikita Pivkin
eea3320d83
docs: update info about license scanning in Yarn projects ( #5207 )
2023-09-19 06:24:11 +00:00
DmitriyLewen
2e6662060e
ci: auto apply labels ( #5200 )
...
* add label for mage file. Create workflow.
* fix typo
* setup go and aqua tools
* set fetch-depth == 1
2023-09-18 13:51:12 +00:00
DmitriyLewen
49680dc881
fix link ( #5203 )
2023-09-18 08:07:56 +00:00
Paternity Leave
daae88287b
fix(purl): handle rust types ( #5186 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-09-15 20:58:10 +00:00
Paternity Leave
81240cf080
chore: auto-close issues ( #5177 )
...
* chore: auto close issues
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* chore: add state_reason
* docs: add a warning message about issues
Signed-off-by: knqyf263 <knqyf263@gmail.com >
---------
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-09-14 06:19:59 +00:00
dependabot[bot]
bd0accd8a0
chore(deps): bump github.com/spf13/viper from 1.15.0 to 1.16.0 ( #5093 )
...
Bumps [github.com/spf13/viper](https://github.com/spf13/viper ) from 1.15.0 to 1.16.0.
- [Release notes](https://github.com/spf13/viper/releases )
- [Commits](https://github.com/spf13/viper/compare/v1.15.0...v1.16.0 )
---
updated-dependencies:
- dependency-name: github.com/spf13/viper
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-14 06:17:08 +00:00
chenk
ecee79403e
fix(k8s): kbom support addons labels ( #5178 )
...
* feat: kbom support addons label
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kbom support addons label
Signed-off-by: chenk <hen.keinan@gmail.com >
---------
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-09-14 06:12:48 +00:00
Nikita Pivkin
9ebc25d88b
test: validate SPDX with the JSON schema ( #5124 )
...
* test: validate SPDX with the JSON schema
* use the SPDX schema version based on the document version
* additionally validate the document using spdx
2023-09-14 06:10:09 +00:00
chenk
9a49a37737
chore: bump trivy-kubernetes-latest ( #5161 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-09-12 07:21:44 +00:00
Nikita Pivkin
ad1dc6327a
docs: add 'Signature Verification' guide ( #4731 )
...
* add 'Signature Verification' guide
* add gpg signature verification doc
---------
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-09-12 06:57:40 +00:00
k.goto
7c68d4a7ec
docs: add image-scanner-with-trivy for ecosystem ( #5159 )
2023-09-11 09:18:56 +00:00
Katsuya Miyachi
ed49609a73
fix(fs): assign the absolute path to be inspected to ROOTPATH when filesystem ( #5158 )
2023-09-10 15:08:09 +00:00
dependabot[bot]
19539722e0
chore(deps): bump github.com/CycloneDX/cyclonedx-go ( #5102 )
...
Bumps [github.com/CycloneDX/cyclonedx-go](https://github.com/CycloneDX/cyclonedx-go ) from 0.7.2-0.20230625092137-07e2f29defc3 to 0.7.2.
- [Release notes](https://github.com/CycloneDX/cyclonedx-go/releases )
- [Changelog](https://github.com/CycloneDX/cyclonedx-go/blob/master/.goreleaser.yml )
- [Commits](https://github.com/CycloneDX/cyclonedx-go/commits/v0.7.2 )
---
updated-dependencies:
- dependency-name: github.com/CycloneDX/cyclonedx-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-10 12:57:56 +00:00
Srishanth
c7516011b5
Update filtering.md ( #5131 )
2023-09-10 08:52:19 +00:00
dependabot[bot]
ccc6d7cb2c
chore(deps): bump sigstore/cosign-installer ( #5104 )
...
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer ) from a5d81fb6bdbcbb3d239e864d6552820420254494 to 4a861528be5e691840a69536975ada1d4c30349d.
- [Release notes](https://github.com/sigstore/cosign-installer/releases )
- [Commits](a5d81fb6bd...4a861528be )
---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-08 14:04:16 +00:00
dependabot[bot]
48cbf45534
chore(deps): bump github.com/cyphar/filepath-securejoin ( #5143 )
...
Bumps [github.com/cyphar/filepath-securejoin](https://github.com/cyphar/filepath-securejoin ) from 0.2.3 to 0.2.4.
- [Release notes](https://github.com/cyphar/filepath-securejoin/releases )
- [Commits](https://github.com/cyphar/filepath-securejoin/compare/v0.2.3...v0.2.4 )
---
updated-dependencies:
- dependency-name: github.com/cyphar/filepath-securejoin
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-08 13:47:33 +00:00
dependabot[bot]
a9c2c74c55
chore(deps): bump golangci/golangci-lint-action from 3.6.0 to 3.7.0 ( #5103 )
...
Bumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action ) from 3.6.0 to 3.7.0.
- [Release notes](https://github.com/golangci/golangci-lint-action/releases )
- [Commits](https://github.com/golangci/golangci-lint-action/compare/v3.6.0...v3.7.0 )
---
updated-dependencies:
- dependency-name: golangci/golangci-lint-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-07 20:17:29 +00:00
dependabot[bot]
120ac68b5b
chore(deps): bump easimon/maximize-build-space from 7 to 8 ( #5105 )
...
Bumps [easimon/maximize-build-space](https://github.com/easimon/maximize-build-space ) from 7 to 8.
- [Release notes](https://github.com/easimon/maximize-build-space/releases )
- [Changelog](https://github.com/easimon/maximize-build-space/blob/master/CHANGELOG.md )
- [Commits](https://github.com/easimon/maximize-build-space/compare/v7...v8 )
---
updated-dependencies:
- dependency-name: easimon/maximize-build-space
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-07 20:16:13 +00:00
dependabot[bot]
41eaa78ae0
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.273 to 1.45.3 ( #5126 )
...
Bumps [github.com/aws/aws-sdk-go](https://github.com/aws/aws-sdk-go ) from 1.44.273 to 1.45.3.
- [Release notes](https://github.com/aws/aws-sdk-go/releases )
- [Commits](https://github.com/aws/aws-sdk-go/compare/v1.44.273...v1.45.3 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-06 11:09:44 +00:00
Anais Urlichs
932f927555
chaging adopters discussion tempalte ( #5091 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2023-09-05 20:55:25 +00:00
dependabot[bot]
db3133346a
chore(deps): bump github.com/cheggaaa/pb/v3 from 3.1.2 to 3.1.4 ( #5092 )
...
Bumps [github.com/cheggaaa/pb/v3](https://github.com/cheggaaa/pb ) from 3.1.2 to 3.1.4.
- [Commits](https://github.com/cheggaaa/pb/compare/v3.1.2...v3.1.4 )
---
updated-dependencies:
- dependency-name: github.com/cheggaaa/pb/v3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-05 20:50:58 +00:00
dependabot[bot]
8c0b7d619c
chore(deps): bump github.com/hashicorp/golang-lru/v2 from 2.0.2 to 2.0.6 ( #5094 )
...
Bumps [github.com/hashicorp/golang-lru/v2](https://github.com/hashicorp/golang-lru ) from 2.0.2 to 2.0.6.
- [Release notes](https://github.com/hashicorp/golang-lru/releases )
- [Commits](https://github.com/hashicorp/golang-lru/compare/v2.0.2...v2.0.6 )
---
updated-dependencies:
- dependency-name: github.com/hashicorp/golang-lru/v2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-05 07:23:20 +00:00
dependabot[bot]
c61c664c30
chore(deps): bump github.com/aws/aws-sdk-go-v2/config ( #5095 )
...
Bumps [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ) from 1.18.25 to 1.18.38.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.18.25...config/v1.18.38 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-05 07:21:05 +00:00
dependabot[bot]
a99944c1c2
chore(deps): bump github.com/containerd/containerd from 1.7.3 to 1.7.5 ( #5097 )
...
Bumps [github.com/containerd/containerd](https://github.com/containerd/containerd ) from 1.7.3 to 1.7.5.
- [Release notes](https://github.com/containerd/containerd/releases )
- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md )
- [Commits](https://github.com/containerd/containerd/compare/v1.7.3...v1.7.5 )
---
updated-dependencies:
- dependency-name: github.com/containerd/containerd
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-05 07:19:50 +00:00
dependabot[bot]
9fc844ecfc
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azidentity ( #5098 )
...
Bumps [github.com/Azure/azure-sdk-for-go/sdk/azidentity](https://github.com/Azure/azure-sdk-for-go ) from 1.3.0 to 1.3.1.
- [Release notes](https://github.com/Azure/azure-sdk-for-go/releases )
- [Changelog](https://github.com/Azure/azure-sdk-for-go/blob/main/documentation/release.md )
- [Commits](https://github.com/Azure/azure-sdk-for-go/compare/sdk/azcore/v1.3.0...sdk/azcore/v1.3.1 )
---
updated-dependencies:
- dependency-name: github.com/Azure/azure-sdk-for-go/sdk/azidentity
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-05 07:18:15 +00:00
dependabot[bot]
c504f8be44
chore(deps): bump actions/checkout from 3.5.3 to 3.6.0 ( #5106 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 3.5.3 to 3.6.0.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v3.5.3...v3.6.0 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-01 18:42:12 +00:00
Teppei Fukuda
cdab67e7fa
docs: add Bitnami ( #5078 )
...
* docs: add Bitnami
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* docs: add a Debian link
Signed-off-by: knqyf263 <knqyf263@gmail.com >
---------
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-09-01 04:29:05 +00:00
Juan Ariza Toledano
7acc5e8312
feat(docker): add support for scanning Bitnami components ( #5062 )
...
* feat(bitnami): add support for scanning Bitnami components
Signed-off-by: juan131 <jariza@vmware.com >
* chore(deps): bump packageurl-go
TypeBitnami is not included in v0.1.1
* feat(spdx): handle orphan packages
* fix: update Elastic SPDX
Signed-off-by: juan131 <jariza@vmware.com >
* Update pkg/fanal/analyzer/sbom/sbom.go
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
* fix: remove useless else
Signed-off-by: juan131 <jariza@vmware.com >
* call AnalysisResult.Sort()
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* delete app packages
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* fix: set the component path to packages
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* docs: add a comment about continue
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* chore: bump trivy-db
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* docs: add Bitnami
Signed-off-by: knqyf263 <knqyf263@gmail.com >
---------
Signed-off-by: juan131 <jariza@vmware.com >
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
2023-08-31 20:18:05 +00:00
Teppei Fukuda
9628b1cbf3
feat: add support for .trivyignore.yaml ( #5070 )
...
* feat: add support for .trivyignore.yaml
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* add test for trivyignore.yaml
* Add doublestar support
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* go mod tidy
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* update docs
* test: fix
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* fix: load .trivyignore once
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* feat: add a debug log
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* docs: add a table for fields
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* fix: skip empty results
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* revert the change
Signed-off-by: knqyf263 <knqyf263@gmail.com >
---------
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-08-31 11:53:37 +00:00
Nikita Pivkin
4547e27666
fix(terraform): improve detection of terraform files ( #4984 )
...
* fix(terraform): improve detection of terraform files
* update defsec
---------
Co-authored-by: Simar <simar@linux.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-08-31 10:47:06 +00:00
Bishwa Thapa
0c8919e1e4
feat: filter artifacts on --exclude-owned flag ( #5059 )
...
* feat: filter artifacts on --exclude-owned flag
- filter artifacts using trivy-kubernetes library
- upgrade dependencies
- generate docs
* chore: remove shorthand flag for --exclude-owned flag
2023-08-31 10:17:52 +00:00
DmitriyLewen
c04f234fa4
fix(sbom): cyclonedx advisory should omit null value ( #5041 )
...
* return nil for advisories, if len of refs == 0
add marshal test
* add integration test for cyclonedx with vulns
* use existing testcase
* test(pom): add ID for cyclondedx integration golden file
* test(integration): add sorting cyclonedx vulns
2023-08-31 10:16:34 +00:00
Teppei Fukuda
f811ed2d48
build: maximize build space for build tests ( #5072 )
...
* build: maximize build space for build tests
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* only for Linux
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* maximize first
Signed-off-by: knqyf263 <knqyf263@gmail.com >
---------
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-08-31 09:02:18 +00:00
chenk
69ea5bf70e
feat: improve kbom component name ( #5058 )
...
* feat: improve component name - merge
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: improve component name
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: improve component name
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: improve component name
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: improve component name
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: improve component name
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: improve component name
Signed-off-by: chenk <hen.keinan@gmail.com >
---------
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-08-31 07:35:47 +00:00
DmitriyLewen
3715dcb3f4
fix(pom): add licenses for pom artifacts ( #5071 )
2023-08-31 06:41:35 +00:00
simar7
07f7e9853b
chore(deps): Update defsec to v0.92.0 ( #5068 )
...
* chore(deps): Update defsec to v0.92.0
* update tests
* update integration tests
2023-08-30 20:43:08 +00:00
DmitriyLewen
d4ca3cce21
chore: bump Go to 1.20 ( #5067 )
...
* update go.mod, linter, protoc dockerfile
* bump go version in .golangci.yaml
2023-08-30 10:22:33 +00:00
Teppei Fukuda
49fdd584ba
feat: PURL matching with qualifiers in OpenVEX ( #5061 )
...
* feat: PURL match in OpenVEX
* test: fix fixture
* Update docs/docs/supply-chain/vex.md
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
* docs: add a comment about overriding statements
---------
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
2023-08-30 07:48:32 +00:00
DmitriyLewen
4401998ec1
feat(java): add graph support for pom.xml ( #4902 )
...
* add graph support
* update docs
* bump go-dep-parser
* remove replace for go-dep-parser
* update docs
2023-08-30 06:56:41 +00:00
DmitriyLewen
9c211d005d
feat(swift): add vulns for cocoapods ( #5037 )
...
* add vulns for cocoapods, fix purl
* update docs
* remove go-dep-parser replace
* update purl and test
* bump github.com/DmitriyLewen/trivy-db
* remove replace for trivy-db
* remove added sbom tests
* add test for Package() func
* add wrong epoch test
* refactor docs
* add comment to join the module and submodule in purl
* docs: add an example
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-08-29 12:46:49 +00:00
chenk
422fa414e8
fix: support image pull secret for additional workloads ( #5052 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-08-29 06:33:31 +00:00
Jan Mosig
8e933860a3
fix : #5033 Superfluous double quote in html.tpl ( #5036 )
2023-08-28 12:20:02 +00:00
Florian Bufler
9345a98ed1
docs(repo): update trivy repo usage and example ( #5049 )
2023-08-28 08:46:39 +00:00
Leke Ariyo
5d8da70c62
perf: Optimize Dockerfile for reduced layers and size ( #5038 )
...
* Optimize Dockerfile for reduced layers and size
* Optimize Dockerfile for clarity and efficiency without compromising debuggability
2023-08-27 07:52:02 +00:00
Bishwa Thapa
1be9da7aae
feat: scan K8s Resources Kind with --all-namespaces ( #5043 )
2023-08-27 07:38:45 +00:00
guangwu
0e17d0befc
fix: vulnerability typo ( #5044 )
...
Signed-off-by: guoguangwu <guoguangwu@magic-shield.com >
2023-08-27 07:12:11 +00:00
Anais Urlichs
d70fab2318
docs: adding a terraform tutorial to the docs ( #3708 )
...
* adding a terraform tutorial to the docs
* modifying Terraform tutorial
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
* changes to the terraform tutorial in accoradance with the feedback
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
* updates to the terraform tutorial based on PR feedback
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
---------
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2023-08-27 07:08:51 +00:00
Nikita Pivkin
2fa264ac1e
feat(report): add licenses to sarif format ( #4866 )
...
* feat(report): add licenses to sarif format
* update doc
2023-08-23 11:56:08 +00:00
Nikita Pivkin
07ddf47905
feat(misconf): show the resource name in the report ( #4806 )
...
* feat(misconf): show the resource name in the report
* fix typo
* use a loop instead of lo.Map
* add test
2023-08-23 11:54:08 +00:00
Jonathan Lopez Torres
9de360623a
chore: update alpine base images ( #5015 )
2023-08-23 11:53:31 +00:00
DmitriyLewen
ef70d20766
feat: add Package.resolved swift files support ( #4932 )
...
* add Package.resolved files analyzer
* add Swift detector and integration test
* refactor after go-dep-parser changes
* bump go-dep-parser
* remove replaces
* use filePath for Required func
* add ID field
2023-08-23 11:23:50 +00:00
Nikita Pivkin
ec5d8bec0d
feat(nodejs): parse licenses in yarn projects ( #4652 )
...
* feat(nodejs): parse licenses in yarn projects
* close the zip file
* use fsutils.WalkDir
* refactor: extract traverseFunc
* update tests
* update required
* improve required fn
* handle error
* fix required
* fix required
* fix required
* update test
* fix after review
* simplify test data
* fix path
* rename fn
* update docs
* update docs
* simplify required fn
* skip an empty license
* improve required
* improve required
* update golden
* classify license file
* fix path
* fix path
* improve license parsing from cache
* classify the license file from zip
* refactor
* refactor
* fix lint
* fix after review
* fix test
* mv files
* mv files
* fix dbg message
* refactor: use zip.Reader as fs.FS
* refactor: pass io.Reader
* refactor: use fs.Sub
* refactor: add a struct for license traversing
* refactor: use lo.Some
* feat: bump the yarn analyzer version
* go mod tidy
* fix: sort imports
* use multierror
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-08-23 06:35:54 +00:00
chenk
3114c87e60
fix: k8s private registries support ( #5021 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-08-21 12:00:04 +00:00
DmitriyLewen
6d79f55db9
bump github.com/testcontainers/testcontainers-go from 0.21.0 to 0.23.0 ( #5018 )
2023-08-21 09:16:56 +00:00
Nikita Pivkin
9ace59106e
feat(vuln): support last_affected field from osv ( #4944 )
...
* feat(vuln): support last_affected field from osv
* run go mod tidy
* bump trivy-db
2023-08-20 16:08:56 +00:00
Nikita Pivkin
d442176405
feat(server): add version endpoint ( #4869 )
...
* feat(server): add version endpoint
* fix panic and test
* move version.go
* move version variable
* add docs about endpoints
* move testdata
* refactor
* update build command
* refactor
2023-08-20 06:12:31 +00:00
chenk
63cd41d20d
feat: k8s private registries support ( #4987 )
...
* feat: k8s private registries support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: k8s private registries support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: k8s private registries support
Signed-off-by: chenk <hen.keinan@gmail.com >
* fix: add non empty credential update
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: k8s private registries support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: k8s private registries support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: k8s private registries support
Signed-off-by: chenk <hen.keinan@gmail.com >
---------
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-08-20 06:07:30 +00:00
rlubetkin
cb16e23f14
fix(server): add indirect prop to package ( #4974 )
...
* fix(server): add indirect prop to package
* fix(server): fix test
2023-08-17 08:57:20 +00:00
Teppei Fukuda
a4e981b4ec
docs: add coverage ( #4954 )
...
* docs: add coverage
* add more pages
* add dart, dotnet, elixir languages.
* add C, ruby, cocoapods. Update links
* rename headers for dart and elixir
* docs: add Google Distroless and Photon OS
* docs: add IaC
* docs: put vulnerability into a single page
* fixed broken links
* docs: add coverage overview
* update some links
* add note about arch for Rocky linux
* docs: fix typo
* fix typo
* docs: add footnotes
* docs: add a link to coverage in the license section
* docs: add a conversion table
* docs: get aligned
---------
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-08-17 08:00:34 +00:00
DmitriyLewen
6f03c79405
feat(c): add location for lock file dependencies. ( #4994 )
...
* add location for conan lock files
* bump go-dep-parser
* go mod tidy
2023-08-16 11:34:03 +00:00
Anais Urlichs
c74870500a
docs: adding blog post on ec2 ( #4813 )
...
* adding blog post on ec2
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
* update title of section
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
* changing the location of the article to be under Vulnerabilities
---------
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2023-08-13 07:40:08 +00:00
DmitriyLewen
4e1316c37f
revert 32bit bins ( #4977 )
2023-08-13 07:32:08 +00:00
dependabot[bot]
fc959fc57f
chore(deps): bump github.com/xlab/treeprint from 1.1.0 to 1.2.0 ( #4917 )
...
Bumps [github.com/xlab/treeprint](https://github.com/xlab/treeprint ) from 1.1.0 to 1.2.0.
- [Release notes](https://github.com/xlab/treeprint/releases )
- [Commits](https://github.com/xlab/treeprint/compare/v1.1.0...v1.2.0 )
---
updated-dependencies:
- dependency-name: github.com/xlab/treeprint
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-10 08:21:41 +00:00
DmitriyLewen
f105279989
fix(report): return severity colors in table format ( #4969 )
...
* use xio.NopCloser to compare with os.Stdout
* fmt of import
2023-08-10 03:58:42 +00:00
DmitriyLewen
bc2b0ca6c3
build: maximize available disk space for release ( #4937 )
...
* remove unneeded bins and archives
* use jlumbroso/free-disk-space
* remove repeating step
* use maximize-build-space
* build: remove unused step
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-08-09 18:18:15 +00:00
simar7
9493c6f087
test(cli): Fix assertion helptext ( #4966 )
2023-08-09 09:07:45 +00:00
simar7
b0359de664
chore(deps): Bump defsec to v0.91.1 ( #4965 )
2023-08-09 09:07:13 +00:00
Teppei Fukuda
d3a34e409c
test: validate CycloneDX with the JSON schema ( #4956 )
...
* test: validate CycloneDX with the JSON schema
* fix(sbom): move licenses to `name` field in Cyclonedx format (#4941 )
* use license.Name instead of Expression
* update tests
* test: add uuid package
* test: compare UUID
---------
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
2023-08-08 12:51:10 +00:00
Nikita Pivkin
798ef1b64a
fix(server): add licenses to the Result message ( #4955 )
2023-08-08 07:21:59 +00:00
Nikita Pivkin
e8cf281471
fix(aws): resolve endpoint if endpoint is passed ( #4925 )
...
* fix(aws): resolve endpoint to get identity if endpoint is passed
* resolve endpoint for ami and ebs
* return an error if aws region is missing
2023-08-08 07:19:40 +00:00
DmitriyLewen
f18b0db583
fix(sbom): move licenses to name field in Cyclonedx format ( #4941 )
...
* use license.Name instead of Expression
* update tests
2023-08-06 12:50:35 +00:00
DmitriyLewen
a79670156f
add only uniq deps in dependsOn ( #4943 )
2023-08-06 11:39:39 +00:00
Nikita Pivkin
b544e0dea7
use testify instead of gotest.tools ( #4946 )
2023-08-06 11:33:16 +00:00
Nikita Pivkin
067a0fcb9c
fix(nodejs): do not detect lock file in node_modules as an app ( #4949 )
...
* fix(npm): do not detect lock file in node_modules as an app
* refactor: add x/path.Contains
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-08-06 08:59:18 +00:00
DmitriyLewen
e6d7705a51
bump go-dep-parser ( #4936 )
2023-08-06 08:07:30 +00:00
dependabot[bot]
c584dc1768
chore(deps): bump github.com/openvex/go-vex from 0.2.0 to 0.2.1 ( #4914 )
...
Bumps [github.com/openvex/go-vex](https://github.com/openvex/go-vex ) from 0.2.0 to 0.2.1.
- [Release notes](https://github.com/openvex/go-vex/releases )
- [Commits](https://github.com/openvex/go-vex/compare/v0.2.0...v0.2.1 )
---
updated-dependencies:
- dependency-name: github.com/openvex/go-vex
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-03 13:07:12 +00:00
dependabot[bot]
358d56b6b5
chore(deps): bump helm/kind-action from 1.7.0 to 1.8.0 ( #4909 )
...
Bumps [helm/kind-action](https://github.com/helm/kind-action ) from 1.7.0 to 1.8.0.
- [Release notes](https://github.com/helm/kind-action/releases )
- [Commits](fa81e57adf...dda0770415 )
---
updated-dependencies:
- dependency-name: helm/kind-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-03 06:14:49 +00:00
dependabot[bot]
17f3ea9180
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azcore ( #4912 )
...
Bumps [github.com/Azure/azure-sdk-for-go/sdk/azcore](https://github.com/Azure/azure-sdk-for-go ) from 1.6.0 to 1.7.0.
- [Release notes](https://github.com/Azure/azure-sdk-for-go/releases )
- [Changelog](https://github.com/Azure/azure-sdk-for-go/blob/main/documentation/release.md )
- [Commits](https://github.com/Azure/azure-sdk-for-go/compare/sdk/azcore/v1.6.0...sdk/azcore/v1.7.0 )
---
updated-dependencies:
- dependency-name: github.com/Azure/azure-sdk-for-go/sdk/azcore
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-03 06:13:41 +00:00
Nikita Pivkin
39ccbf7b58
test(aws): move part of unit tests to integration ( #4884 )
...
* test(aws): move part of unit tests to integration
* fix typo
* fix test
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-08-02 15:48:52 +00:00
Will Yardley
6d3ae3bcf2
docs(cli): update help string for file and dir skipping ( #4872 )
...
* docs(cli): update help string for file and dir skipping
- Update the contextual help messages
- Add some additional examples (and clarify YAML file configuration) for
globbing
- Update docs
- Fix broken link in skipping docs
See also #3754
Signed-off-by: William Yardley <wyardley@users.noreply.github.com >
* docs: revert
---------
Signed-off-by: William Yardley <wyardley@users.noreply.github.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-08-02 12:33:59 +00:00
dependabot[bot]
7d7a1ef54a
chore(deps): bump sigstore/cosign-installer ( #4910 )
...
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer ) from ef0e9691595ea19ec990a46b1a591dcafe568f34 to a5d81fb6bdbcbb3d239e864d6552820420254494.
- [Release notes](https://github.com/sigstore/cosign-installer/releases )
- [Commits](ef0e969159...a5d81fb6bd )
---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-02 11:54:14 +00:00
dependabot[bot]
fc7495017d
chore(deps): bump github.com/sosedoff/gitkit from 0.3.0 to 0.4.0 ( #4916 )
...
Bumps [github.com/sosedoff/gitkit](https://github.com/sosedoff/gitkit ) from 0.3.0 to 0.4.0.
- [Commits](https://github.com/sosedoff/gitkit/compare/v0.3.0...v0.4.0 )
---
updated-dependencies:
- dependency-name: github.com/sosedoff/gitkit
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-02 11:41:38 +00:00
dependabot[bot]
b2a68bc06d
chore(deps): bump k8s.io/api from 0.27.3 to 0.27.4 ( #4918 )
...
Bumps [k8s.io/api](https://github.com/kubernetes/api ) from 0.27.3 to 0.27.4.
- [Commits](https://github.com/kubernetes/api/compare/v0.27.3...v0.27.4 )
---
updated-dependencies:
- dependency-name: k8s.io/api
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-02 11:37:31 +00:00
dependabot[bot]
e5c0c15b6e
chore(deps): bump github.com/secure-systems-lab/go-securesystemslib ( #4919 )
...
Bumps [github.com/secure-systems-lab/go-securesystemslib](https://github.com/secure-systems-lab/go-securesystemslib ) from 0.6.0 to 0.7.0.
- [Release notes](https://github.com/secure-systems-lab/go-securesystemslib/releases )
- [Commits](https://github.com/secure-systems-lab/go-securesystemslib/compare/v0.6.0...v0.7.0 )
---
updated-dependencies:
- dependency-name: github.com/secure-systems-lab/go-securesystemslib
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-02 11:37:09 +00:00
dependabot[bot]
da37803d59
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/sts ( #4913 )
...
Bumps [github.com/aws/aws-sdk-go-v2/service/sts](https://github.com/aws/aws-sdk-go-v2 ) from 1.19.0 to 1.21.0.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/CHANGELOG.md )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.19.0...service/s3/v1.21.0 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/service/sts
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-02 11:31:47 +00:00
dependabot[bot]
9744e6498d
chore(deps): bump github.com/magefile/mage from 1.14.0 to 1.15.0 ( #4915 )
...
Bumps [github.com/magefile/mage](https://github.com/magefile/mage ) from 1.14.0 to 1.15.0.
- [Release notes](https://github.com/magefile/mage/releases )
- [Changelog](https://github.com/magefile/mage/blob/master/.goreleaser.yml )
- [Commits](https://github.com/magefile/mage/compare/v1.14.0...v1.15.0 )
---
updated-dependencies:
- dependency-name: github.com/magefile/mage
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-02 10:52:46 +00:00
Teppei Fukuda
99eebc6703
docs: update the discussion template ( #4928 )
2023-08-02 10:51:51 +00:00
Teppei Fukuda
d19c7d9f29
feat(repo): support local repositories ( #4890 )
...
* feat(repo): support local repositories
* fix tests
* test: fix client/server tests
* docs: update
* test: add fs tests
* test: do not update golden files if overridden
* docs: remove a comment about fs deprecation
2023-07-31 11:27:36 +00:00
DmitriyLewen
3c19761875
bump go-dep-parser ( #4893 )
2023-07-31 11:08:25 +00:00
Nikita Pivkin
e1c2a8c804
fix(misconf): add missing fields to proto ( #4861 )
...
* fix(misconf): add missing fields to proto
* mark deleted fields as reserved
2023-07-30 11:15:36 +00:00
Nikita Pivkin
8b8e0e83d1
fix: remove trivy-db package replacement ( #4877 )
...
* fix: remove trivy-db package replacement
* fix: remove trivy-db package replacement
2023-07-30 07:37:14 +00:00
Nikita Pivkin
f9efe44fd3
chore(test): bump the integration test timeout to 15m ( #4880 )
2023-07-30 07:34:48 +00:00
simar7
7271d682fb
chore(deps): Update defsec to v0.91.0 ( #4886 )
...
* chore(deps): Update defsec to v0.91.0
* update tests
Signed-off-by: Simar <simar@linux.com >
---------
Signed-off-by: Simar <simar@linux.com >
2023-07-30 07:31:34 +00:00
Teppei Fukuda
c3bc67c89a
chore: update CODEOWNERS ( #4871 )
...
* Update CODEOWNERS
* Add simar7
2023-07-27 07:05:15 +00:00
Teppei Fukuda
232ba823e1
feat(vuln): support vulnerability status ( #4867 )
...
* feat: support vulnerability status
* feat: show status in table
* don't add `fixed` status in debian/redhat
* update test golden files
* add Status in rpc
* update docs
* update ignore-status example
* add ignore-status in integration test
* docs: add the explanation for statuses
---------
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-07-26 11:55:03 +00:00
simar7
11618c9408
feat(misconf): Support custom URLs for policy bundle ( #4834 )
...
* feat(misconf): Support custom URLs for policy bundle
This PR adds support for custom policy bundles to be specified
with a flag `--policy-bundle-url` as an option to Trivy.
Fixes: https://github.com/aquasecurity/trivy/issues/4672
Signed-off-by: Simar <simar@linux.com >
* update docs
Signed-off-by: Simar <simar@linux.com >
* rename flag to `--policy-bundle-repository`
Signed-off-by: Simar <simar@linux.com >
* fix field
* rebase and update docs
Signed-off-by: Simar <simar@linux.com >
* set policyBundleRepo on client
Signed-off-by: Simar <simar@linux.com >
---------
Signed-off-by: Simar <simar@linux.com >
2023-07-26 08:45:49 +00:00
Teppei Fukuda
07075696d1
refactor: replace with sortable packages ( #4858 )
2023-07-24 07:09:14 +00:00
Damian E
fbe1c9eb1f
docs: correct license scanning sample command ( #4855 )
2023-07-24 05:02:55 +00:00
Teppei Fukuda
20c2246a61
fix(report): close the file ( #4842 )
...
* fix(report): close the file
* refactor: add the format type
* fix: return errors in version printing
* fix: lint issues
* fix: do not fail on bogus cache dir
---------
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-07-23 13:37:18 +00:00
DmitriyLewen
24a3e547d9
feat(nodejs): add support for include-dev-deps flag for yarn ( #4812 )
...
* add support for include-dev-deps flag
* remove go.mod replace
* refactor
* bump go-dep-parser
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-07-23 13:07:49 +00:00
simar7
a7bd7bb65f
feat(misconf): Add support for independently enabling libraries ( #4070 )
...
* feat(misconf): Add support for independently enabling libraries
Implements: https://github.com/aquasecurity/trivy/issues/4181
Signed-off-by: Simar <simar@linux.com >
* update tests
Signed-off-by: Simar <simar@linux.com >
* fix lint
Signed-off-by: Simar <simar@linux.com >
* fix tests
Signed-off-by: Simar <simar@linux.com >
* update defsec
Signed-off-by: Simar <simar@linux.com >
* fix test
Signed-off-by: Simar <simar@linux.com >
---------
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-07-23 09:44:59 +00:00
DmitriyLewen
4aa9ea0961
feat(secret): add secret config file for cache calculation ( #4837 )
...
* move parse secret config to initScannerConfig + add secret to cache key
* add calc cache test
* just read config file and add to cache
* refactor comments
* refactor
2023-07-23 08:26:22 +00:00
Sogo Kato
5d349d8147
Fix a link in gitlab-ci.md ( #4850 )
2023-07-23 08:20:29 +00:00
Nikita Pivkin
a61531c1f7
fix(flag): use globalstar to skip directories ( #4854 )
2023-07-23 06:11:46 +00:00
DmitriyLewen
78cc20937d
chore(deps): bump github.com/docker/docker from v23.0.5+incompatible to v23.0.7-0.20230714215826-f00e7af96042+incompatible ( #4849 )
...
* use 1.19.10 version for integration tests
* fix go-version field
* revert test workflow changes
* bump docker/docker
2023-07-21 09:00:35 +00:00
afdesk
93996041b2
fix(license): using common way for splitting licenses ( #4434 )
...
* fix(license): using common way for splitting licenses
* add test cases
* TEST new regex
* extract function
* fix version detection
---------
Co-authored-by: Nikita Pivkin <nikita.pivkin@smartforce.io >
2023-07-19 08:05:43 +00:00
AliDatadog
3e2416d77c
fix(containerd): Use img platform in exporter instead of strict host platform ( #4477 )
...
* match with img platform instead of host platform
* client matching pull spec
* use default platform
* pull with platforms default strict
* use withplatform to pull and add debug log
* looks like we are trying to scan a i386 image
* revert changes on test, use the right platform match
* try with Config.Platform
* use spect.platform
* fix function usage
* try another way to retrieve the platform
* fix compilation
* read platforms from config manifest
* use platform from RegistryOptions if available, otherwise get the actual platform
* goimport
* put platform in containerd client
* fix panic
* use DefaultStrict as default
2023-07-19 07:54:24 +00:00
DmitriyLewen
ce77bb46c3
remove govulndb ( #4783 )
2023-07-19 07:24:35 +00:00
Nikita Pivkin
c05caae43f
fix(java): inherit licenses from parents ( #4817 )
2023-07-19 06:51:58 +00:00
Teppei Fukuda
aca11b95d0
refactor: add allowed values for CLI flags ( #4800 )
...
* refactor: rename Value to Default
* refactor: support allowed values for CLI flags
* docs: auto-generate
* test: fix
* test: add tests for flags
2023-07-17 13:13:23 +00:00
DmitriyLewen
4cecd17ea5
add example regex to allow rules ( #4827 )
2023-07-17 12:36:22 +00:00
simar7
4bc8d29c15
feat(misconf): Support custom data for rego policies for cloud ( #4745 )
...
* feat(misconf): Support custom data for cloud policies
Signed-off-by: Simar <simar@linux.com >
* use policyfs
Signed-off-by: Simar <simar@linux.com >
* refactor to reduce cyclomatic complexity
Signed-off-by: Simar <simar@linux.com >
* bump defsec
* update docs
Signed-off-by: Simar <simar@linux.com >
* update test assertion
Signed-off-by: Simar <simar@linux.com >
* update test
Need this as OPA is currently broken on Windows
https://github.com/open-policy-agent/opa/issues/4521
Signed-off-by: Simar <simar@linux.com >
* fix data path
* fix(mapfs): convert volume names into dirs
* revert creating temp dirs
---------
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2023-07-17 12:34:20 +00:00
Anais Urlichs
88243a0ad6
docs: correcting the trivy k8s tutorial ( #4815 )
...
* correcting the trivy k8s tutorial
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
* docs: fix
---------
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-07-16 09:06:28 +00:00
Nikita Pivkin
3c7d988d71
feat(cli): add --tf-exclude-downloaded-modules flag ( #4810 )
...
* feat(cli): add --tf-exclude-downloaded-modules flag
* fix typo
* generate docs
2023-07-16 08:56:03 +00:00
DmitriyLewen
fd0fd104f8
fix(sbom): cyclonedx recommendations should include fixed versions for each package ( #4794 )
...
* add all fixed versions to recommendations
* fix tests
2023-07-13 11:16:11 +00:00
Nikita Pivkin
d0d543b881
feat(misconf): enable --policy flag to accept directory and files both ( #4777 )
...
* feat(misconf): enable --policy flag to accept directory and files both
* fix test
* Revert "clarifying a dir path is required for custom policies (#4716 )"
This reverts commit 8a1aa448a1 .
* update doc
* update the flag description
2023-07-13 10:59:21 +00:00
Nikita Pivkin
b43a3e6237
feat(python): add license fields ( #4722 )
...
* bump go-dep-parser
* update tests
* fix testdata
2023-07-13 10:55:36 +00:00
chenk
aef7b148af
fix: support trivy k8s-version on k8s sub-command ( #4786 )
...
* fix: support trivy k8s-version on k8s sub-command
Signed-off-by: chenk <hen.keinan@gmail.com >
* fix: support last applied configuration
Signed-off-by: chenk <hen.keinan@gmail.com >
---------
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-07-13 08:28:09 +00:00
simar7
5d76abadc9
chore(deps): Update defsec to v0.90.3 ( #4793 )
...
* chore(deps): Update defsec to v0.90.2
Signed-off-by: Simar <simar@linux.com >
* go mod tidy
---------
Signed-off-by: Simar <simar@linux.com >
2023-07-07 08:13:56 +00:00
dependabot[bot]
fed446c515
chore(deps): bump google.golang.org/protobuf from 1.30.0 to 1.31.0 ( #4752 )
...
Bumps google.golang.org/protobuf from 1.30.0 to 1.31.0.
---
updated-dependencies:
- dependency-name: google.golang.org/protobuf
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-07 04:56:30 +00:00
dependabot[bot]
df62927e58
chore(deps): bump alpine from 3.18.0 to 3.18.2 ( #4748 )
...
Bumps alpine from 3.18.0 to 3.18.2.
---
updated-dependencies:
- dependency-name: alpine
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-07 04:05:43 +00:00
dependabot[bot]
1b9b9a84f7
chore(deps): bump github.com/alicebob/miniredis/v2 from 2.30.3 to 2.30.4 ( #4758 )
...
Bumps [github.com/alicebob/miniredis/v2](https://github.com/alicebob/miniredis ) from 2.30.3 to 2.30.4.
- [Release notes](https://github.com/alicebob/miniredis/releases )
- [Changelog](https://github.com/alicebob/miniredis/blob/master/CHANGELOG.md )
- [Commits](https://github.com/alicebob/miniredis/compare/v2.30.3...v2.30.4 )
---
updated-dependencies:
- dependency-name: github.com/alicebob/miniredis/v2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-06 13:23:01 +00:00
zunlongzhou
3c16ca821b
docs(image): fix the comment on the soft/hard link ( #4740 )
...
* Update tar.go
The comment before the following w.processFile(filePath, tr, hdr.FileInfo(), analyzeFn) call says: // A symbolic/hard link or regular file will reach here.
But defualt's processing causes the symbolic/hard link to not reach the processFile function location
* Update tar.go
update tar.go comment
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-07-06 10:49:48 +00:00
DmitriyLewen
e5bee5cccd
check Type when filling pkgs in vulns ( #4776 )
2023-07-06 10:45:52 +00:00
Bill Wang
4b9f310b9c
feat: add support of linux/ppc64le and linux/s390x architectures for Install.sh script ( #4770 )
...
* feat: add support of linux/ppc64le and linux/s390x architectures for Install.sh script #4747
* feat: add support of linux/ppc64le and linux/s390x architectures for Install.sh script #4747
2023-07-06 09:05:37 +00:00
dependabot[bot]
8e7fb7cc84
chore(deps): bump modernc.org/sqlite from 1.20.3 to 1.23.1 ( #4756 )
...
Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite ) from 1.20.3 to 1.23.1.
- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.20.3...v1.23.1 )
---
updated-dependencies:
- dependency-name: modernc.org/sqlite
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-04 19:45:34 +00:00
DmitriyLewen
a9badeaba8
fix(rocky): add architectures support for advisories ( #4691 )
...
* add multi-arch support for rocky linux advisories
* feat: comply with the new signagure
* bump trivy-db
* fix tests
* chore(deps): remove fork replace
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-07-03 08:48:57 +00:00
dependabot[bot]
f8ebccc680
chore(deps): bump github.com/opencontainers/image-spec ( #4751 )
...
Bumps [github.com/opencontainers/image-spec](https://github.com/opencontainers/image-spec ) from 1.1.0-rc3 to 1.1.0-rc4.
- [Release notes](https://github.com/opencontainers/image-spec/releases )
- [Changelog](https://github.com/opencontainers/image-spec/blob/main/RELEASES.md )
- [Commits](https://github.com/opencontainers/image-spec/compare/v1.1.0-rc3...v1.1.0-rc4 )
---
updated-dependencies:
- dependency-name: github.com/opencontainers/image-spec
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-03 07:19:56 +00:00
dependabot[bot]
1c81948e03
chore(deps): bump github.com/package-url/packageurl-go ( #4754 )
...
Bumps [github.com/package-url/packageurl-go](https://github.com/package-url/packageurl-go ) from 0.1.1-0.20220428063043-89078438f170 to 0.1.1.
- [Release notes](https://github.com/package-url/packageurl-go/releases )
- [Commits](https://github.com/package-url/packageurl-go/commits/v0.1.1 )
---
updated-dependencies:
- dependency-name: github.com/package-url/packageurl-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-03 04:06:44 +00:00
dependabot[bot]
497cc10d8e
chore(deps): bump golang.org/x/sync from 0.2.0 to 0.3.0 ( #4750 )
...
Bumps [golang.org/x/sync](https://github.com/golang/sync ) from 0.2.0 to 0.3.0.
- [Commits](https://github.com/golang/sync/compare/v0.2.0...v0.3.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/sync
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-02 14:57:57 +00:00
dependabot[bot]
065f0afa54
chore(deps): bump github.com/tetratelabs/wazero from 1.2.0 to 1.2.1 ( #4755 )
...
Bumps [github.com/tetratelabs/wazero](https://github.com/tetratelabs/wazero ) from 1.2.0 to 1.2.1.
- [Release notes](https://github.com/tetratelabs/wazero/releases )
- [Commits](https://github.com/tetratelabs/wazero/compare/v1.2.0...v1.2.1 )
---
updated-dependencies:
- dependency-name: github.com/tetratelabs/wazero
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-02 14:52:44 +00:00
dependabot[bot]
e2603056dd
chore(deps): bump github.com/testcontainers/testcontainers-go ( #4759 )
...
Bumps [github.com/testcontainers/testcontainers-go](https://github.com/testcontainers/testcontainers-go ) from 0.20.1 to 0.21.0.
- [Release notes](https://github.com/testcontainers/testcontainers-go/releases )
- [Commits](https://github.com/testcontainers/testcontainers-go/compare/v0.20.1...v0.21.0 )
---
updated-dependencies:
- dependency-name: github.com/testcontainers/testcontainers-go
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-02 13:57:46 +00:00
Alexandre
0621402bf7
fix: documentation about reseting trivy image ( #4733 )
2023-07-02 12:29:23 +00:00
Dirk Mueller
798fdbc013
fix(suse): Add openSUSE Leap 15.5 eol date as well ( #4744 )
...
Taken directly from https://en.opensuse.org/Lifetime
2023-07-02 11:22:26 +00:00
Teppei Fukuda
34a89293d5
fix: update Amazon Linux 1 EOL ( #4761 )
2023-07-02 11:00:20 +00:00
simar7
600819248d
chore(deps): Update defsec to v0.90.1 ( #4739 )
...
Fixes: https://github.com/aquasecurity/trivy/issues/4628
Signed-off-by: Simar <simar@linux.com >
2023-06-30 06:48:47 +00:00
Nikita Pivkin
73734eab21
feat(nodejs): support yarn workspaces ( #4664 )
...
* feat(nodejs): add the workspaces field to the package
* fix go.mod
* update go.mod
* compare workspaces by length
2023-06-30 06:40:28 +00:00
DmitriyLewen
22463ababd
feat(cli): add include-dev-deps flag ( #4700 )
...
* add Dev field for Package
* fix integration test
* update docs
* feat(cli): add include-dev flag
* bump go-dep-parser
* update docs
* add integration test
* refactor
* refactor
* fix integration test
* refactor: rename flag to include-dev-deps
* update docs
* update docs
* filter dev deps when scanning packages
* add flag support for server mode
* refactor: remove comment that might confuse
* refactor: move --include-dev-deps to the scanner flag group
* refactor: not return apps
* docs: update
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-06-29 13:15:52 +00:00
Nikita Pivkin
790c8054ec
fix(image): pass the secret scanner option to scan the img config ( #4735 )
2023-06-29 08:37:45 +00:00
chenk
86fec9c4a9
fix: scan job pod it not found on k8s-1.27.x ( #4729 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-06-28 14:38:39 +00:00
Manveer Singh
26bc91160b
feat(docker): add support for mTLS authentication when connecting to registry ( #4649 )
...
* feat: add support for mTLS authentication when connecting to registry
* feat: add support for mTLS authentication when connecting to registry - added error handling
* feat: add support for mTLS authentication when connecting to registry
- code quality improvements
* feat: add support for mTLS authentication when connecting to registry
- code quality improvements
* wrap errors
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-06-28 11:21:26 +00:00
simar7
d699e8c101
chore(deps): Update defsec to v0.90.0 ( #4723 )
...
Signed-off-by: Simar <simar@linux.com >
2023-06-28 08:34:56 +00:00
DmitriyLewen
1777878e83
fix: skip scanning the gpg-pubkey package ( #4720 )
2023-06-28 07:06:08 +00:00
Makhonin Alexey
9be08253a2
Fix http registry oci pull ( #4701 )
...
Signed-off-by: alexey.makhonin <alexey.makhonin@flant.com >
2023-06-26 12:40:40 +00:00
simar7
5d73b47dbc
feat(misconf): Support skipping services ( #4686 )
...
* feat(misconf): Add support for `--skip-service` flag.
Fixes: https://github.com/aquasecurity/trivy/issues/4619
Signed-off-by: Simar <simar@linux.com >
* update docs
Signed-off-by: Simar <simar@linux.com >
* update go mod
* refactor processOptions to reduce cyclo complexity
Signed-off-by: Simar <simar@linux.com >
* fix a bug with multiple skip services
Signed-off-by: Simar <simar@linux.com >
* refactor tests
Signed-off-by: Simar <simar@linux.com >
* use x/slice and x/xerrors
Signed-off-by: Simar <simar@linux.com >
* go mod tidy
* lint
---------
Signed-off-by: Simar <simar@linux.com >
2023-06-26 11:11:59 +00:00
DmitriyLewen
46e784c8a9
docs: fix supported modes for pubspec.lock files ( #4713 )
2023-06-26 11:04:45 +00:00
Teppei Fukuda
0f61a84712
fix(misconf): disable the terraform plan analyzer for other scanners ( #4714 )
2023-06-26 11:03:25 +00:00
Anais Urlichs
8a1aa448a1
clarifying a dir path is required for custom policies ( #4716 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2023-06-26 10:56:57 +00:00
Sandro
fbab9eea3a
chore: update alpine base images ( #4715 )
2023-06-26 10:34:50 +00:00
AliDatadog
f84417bba0
fix last-history-created ( #4697 )
2023-06-26 03:57:54 +00:00
chenk
85c681d443
feat: kbom and cyclonedx v1.5 spec support ( #4708 )
...
* feat: kbom and cyclonedx v1.5 spec support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kbom and cyclonedx v1.5 spec support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kbom and cyclonedx v1.5 spec support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: feat: kbom and cyclonedx 1.5 spec support
Signed-off-by: chenk <hen.keinan@gmail.com >
* fix: unmarshal bom on v1.5 return invalid specification version
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: cyclonedx-1.5 spec support
Signed-off-by: chenk <hen.keinan@gmail.com >
---------
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-06-25 13:47:06 +00:00
Itay Shakury
46748ce6ea
docs: add information about Aqua ( #4590 )
...
* docs: add information about Aqua
* update link
2023-06-25 10:40:45 +00:00
chenk
c6741bddff
fix: k8s escape resource filename on windows os ( #4693 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-06-22 11:16:24 +00:00
Teppei Fukuda
a21acc7e08
ci: ignore merge queue branches ( #4696 )
2023-06-22 11:02:22 +00:00
dependabot[bot]
32a3a3311c
chore(deps): bump actions/checkout from 2.4.0 to 3.5.3 ( #4695 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 2.4.0 to 3.5.3.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v2.4.0...v3.5.3 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-22 10:56:11 +00:00
dependabot[bot]
cbb47dc7c4
chore(deps): bump aquaproj/aqua-installer from 2.1.1 to 2.1.2 ( #4694 )
...
Bumps [aquaproj/aqua-installer](https://github.com/aquaproj/aqua-installer ) from 2.1.1 to 2.1.2.
- [Release notes](https://github.com/aquaproj/aqua-installer/releases )
- [Commits](https://github.com/aquaproj/aqua-installer/compare/v2.1.1...v2.1.2 )
---
updated-dependencies:
- dependency-name: aquaproj/aqua-installer
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-22 10:31:20 +00:00
chenk
e3d10d2512
feat: cyclondx sbom custom property support ( #4688 )
...
* feat: custom property support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: custom property support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: custom property support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: custom property support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: custom property support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: custom property support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: custom property support
Signed-off-by: chenk <hen.keinan@gmail.com >
---------
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-06-22 08:33:27 +00:00
Teppei Fukuda
e1770e046c
ci: do not trigger tests in main ( #4692 )
2023-06-22 08:25:58 +00:00
Dirk Mueller
337c0b70d5
add SUSE Linux Enterprise Server 15 SP5 and update SP4 eol date ( #4690 )
...
all dates are taken from https://www.suse.com/lifecycle#suse-linux-enterprise-server-15
2023-06-22 07:34:59 +00:00
DmitriyLewen
5ccee14304
use group field for jar in cyclonedx ( #4674 )
2023-06-22 07:19:38 +00:00
Nikita Pivkin
96db52c3f6
feat(java): capture licenses from pom.xml ( #4681 )
...
* feat(java): capture licenses from pom.xml
* update doc
2023-06-21 13:12:37 +00:00
Leroy Shirto
3e902a57a9
feat(helm): make sessionAffinity configurable ( #4623 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-06-21 11:14:36 +00:00
Tung Bui (Leo)
904f1cf24e
fix: Show the correct URL of the secret scanning ( #4682 )
2023-06-21 10:57:54 +00:00
Meisam
7d48c5d5d4
document expected file pattern definition format ( #4654 )
2023-06-20 14:02:55 +00:00
guangwu
dcc73e964a
fix: format arg error ( #4642 )
...
* fix: format arg error
* fix: xerrors.Errorf
2023-06-19 10:52:38 +00:00
chenk
35c4262d0b
feat(k8s): cyclonedx kbom support ( #4557 )
...
* feat: cyclonedx kbom support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: cyclonedx kbom support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* chore: update sum db
Signed-off-by: chenk <hen.keinan@gmail.com >
* chore: update sum db
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* chore: update sumdb
Signed-off-by: chenk <hen.keinan@gmail.com >
* chore: update sumdb
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
---------
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-06-19 10:48:26 +00:00
Nikita Pivkin
0e01851e9e
fix(nodejs): remove unused fields for the pnpm lockfile ( #4630 )
...
* refactor(nodejs): remove unused fields for the pnpm lockfile
* run go mod tidy
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-06-19 03:17:31 +00:00
Masahiro331
4d9b444499
fix(vm): update ext4-filesystem parser for parse multi block extents ( #4616 )
...
* chore(deps): update ext4-filesystem parser for parse multi block extents
* test(vm): update integration-vm test fixtures
* test(vm): add gzip decompresser for sparse file
* test(vm): add mage command update golden file for vm integration test
* chore(magefile): [WIP] change test repository
* Revert "chore(magefile): [WIP] change test repository"
This reverts commit c015c8892f .
* fix(test): update fixtures and golden file
* fix(test): revert fixVersion and PkgID
2023-06-18 16:41:55 +00:00
afdesk
c29197ab7d
ci: update build IDs ( #4641 )
2023-06-18 11:24:29 +00:00
Chris Novakovic
d7637adc6b
fix(debian): update EOL for Debian 12 ( #4647 )
...
* fix(debian): update EOL for Debian 12
Debian 12 was released on 2023-06-10 and will be supported for five
years - see https://www.debian.org/News/2023/20230610 .
* Update docs
2023-06-16 04:18:55 +00:00
Teppei Fukuda
ef39eeedf3
chore(deps): bump go-containerregistry ( #4639 )
2023-06-15 09:44:24 +00:00
guangwu
1ce8bb535a
chore: unnecessary use of fmt.Sprintf (S1039) ( #4637 )
2023-06-15 08:36:15 +00:00
Björn Wenzel
bc9513fc57
fix(db): change argument order in Exists query for JavaDB ( #4595 )
2023-06-14 02:26:10 +00:00
simar7
aecd2f0bf0
feat(aws): Add support to see successes in results ( #4427 )
...
Fixes: https://github.com/aquasecurity/trivy/discussions/4417
Signed-off-by: Simar <simar@linux.com >
2023-06-13 17:36:05 +00:00
dependabot[bot]
2cbf402b6a
chore(deps): bump golangci/golangci-lint-action from 3.5.0 to 3.6.0 ( #4613 )
...
Bumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action ) from 3.5.0 to 3.6.0.
- [Release notes](https://github.com/golangci/golangci-lint-action/releases )
- [Commits](https://github.com/golangci/golangci-lint-action/compare/v3.5.0...v3.6.0 )
---
updated-dependencies:
- dependency-name: golangci/golangci-lint-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-12 13:52:43 +00:00
Teppei Fukuda
0099b20e31
ci: do not trigger tests in main ( #4614 )
2023-06-12 13:00:32 +00:00
dependabot[bot]
a597a54fb6
chore(deps): bump sigstore/cosign-installer ( #4609 )
...
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer ) from 204a51a57a74d190b284a0ce69b44bc37201f343 to ef0e9691595ea19ec990a46b1a591dcafe568f34.
- [Release notes](https://github.com/sigstore/cosign-installer/releases )
- [Commits](204a51a57a...ef0e969159 )
---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-12 12:16:20 +00:00
dependabot[bot]
b453fbec37
chore(deps): bump CycloneDX/gh-gomod-generate-sbom from 1 to 2 ( #4608 )
...
Bumps [CycloneDX/gh-gomod-generate-sbom](https://github.com/CycloneDX/gh-gomod-generate-sbom ) from 1 to 2.
- [Release notes](https://github.com/CycloneDX/gh-gomod-generate-sbom/releases )
- [Commits](https://github.com/CycloneDX/gh-gomod-generate-sbom/compare/v1...v2 )
---
updated-dependencies:
- dependency-name: CycloneDX/gh-gomod-generate-sbom
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-06-12 11:40:58 +00:00
Teppei Fukuda
0e876d5aa0
ci: bypass the required status checks ( #4611 )
2023-06-12 14:39:47 +03:00
Teppei Fukuda
a4f27d24a3
ci: support merge queue ( #3652 )
2023-06-12 11:39:08 +03:00
Teppei Fukuda
9e6411e9f5
ci: matrix build for testing ( #4587 )
2023-06-12 10:49:13 +03:00
chenk
ef6538a171
feat: trivy k8s private registry support ( #4567 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-06-12 05:40:25 +03:00
Itay Shakury
139f3e1e32
docs: add general coverage page ( #3859 )
2023-06-11 08:49:29 +03:00
Itay Shakury
479cfdd40e
chore: create SECURITY.md ( #4601 )
2023-06-11 06:16:42 +03:00
afdesk
9a279fa7bb
ci: remove 32bit packages ( #4585 )
2023-06-08 16:52:37 +03:00
Teppei Fukuda
d52b0b7bc0
fix(misconf): deduplicate misconf results ( #4588 )
2023-06-08 15:15:21 +03:00
Amir Ben Nun
9b531fa27b
fix(vm): support sector size of 4096 ( #4564 )
...
Co-authored-by: masahiro331 <m_fujimura@r.recruit.co.jp >
2023-06-08 11:31:13 +03:00
Teppei Fukuda
8ca1bfdd23
fix(misconf): terraform relative paths ( #4571 )
2023-06-08 11:24:52 +03:00
Nikita Pivkin
c20d466044
fix(purl): skip unsupported library type ( #4577 )
2023-06-08 08:45:32 +03:00
Jonathan Lassoff
52cbe79759
fix(terraform): recursively detect all Root Modules ( #4457 )
...
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: Simar <simar@linux.com >
2023-06-08 07:06:00 +03:00
Masahiro331
4a5b915578
fix(vm): support post analyzer for vm command ( #4544 )
2023-06-07 16:16:27 +03:00
Nikita Pivkin
56cdc55f77
fix(nodejs): change the type of the devDependencies field ( #4560 )
2023-06-06 15:51:39 +03:00
Nikita Pivkin
17d753676b
fix(sbom): export empty dependencies in CycloneDX ( #4568 )
2023-06-06 15:49:23 +03:00
Teppei Fukuda
2796abe1ed
refactor: add composite fs for post-analyzers ( #4556 )
2023-06-06 08:19:15 +03:00
dependabot[bot]
22a1573807
chore(deps): bump golangci/golangci-lint-action from 3.4.0 to 3.5.0 ( #4554 )
2023-06-04 16:17:54 +03:00
dependabot[bot]
43586659a1
chore(deps): bump helm/kind-action from 1.5.0 to 1.7.0 ( #4526 )
2023-06-04 14:50:38 +03:00
dependabot[bot]
5081399659
chore(deps): bump github.com/BurntSushi/toml from 1.2.1 to 1.3.0 ( #4528 )
2023-06-04 14:48:41 +03:00
dependabot[bot]
e1a38128ab
chore(deps): bump github.com/alicebob/miniredis/v2 from 2.30.2 to 2.30.3 ( #4529 )
2023-06-04 11:19:53 +03:00
dependabot[bot]
283eef6372
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 ( #4536 )
2023-06-04 11:13:44 +03:00
dependabot[bot]
bbd7b98741
chore(deps): bump github.com/tetratelabs/wazero from 1.0.0 to 1.2.0 ( #4549 )
2023-06-04 11:12:49 +03:00
dependabot[bot]
11c81bf2f6
chore(deps): bump github.com/spf13/cast from 1.5.0 to 1.5.1 ( #4532 )
2023-06-04 11:11:32 +03:00
dependabot[bot]
2d8d63e61a
chore(deps): bump github.com/testcontainers/testcontainers-go ( #4537 )
2023-06-04 09:27:43 +03:00
dependabot[bot]
a46839b1ce
chore(deps): bump github.com/go-git/go-git/v5 from 5.6.1 to 5.7.0 ( #4530 )
2023-06-04 09:25:43 +03:00
dependabot[bot]
19715f5de8
chore(deps): bump github.com/aws/aws-sdk-go-v2/config ( #4534 )
2023-06-04 09:25:04 +03:00
dependabot[bot]
854b63940a
chore(deps): bump github.com/sigstore/rekor from 1.2.0 to 1.2.1 ( #4533 )
2023-06-02 09:36:08 +03:00
dependabot[bot]
59e1a86643
chore(deps): bump alpine from 3.17.3 to 3.18.0 ( #4525 )
2023-06-02 09:34:44 +03:00
Teppei Fukuda
9ef01133c8
feat: add SBOM analyzer ( #4210 )
...
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-06-02 09:34:07 +03:00
DmitriyLewen
dadd1e10c2
fix(sbom): update logic for work with files in spdx format ( #4513 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2023-06-01 12:52:56 +03:00
chenk
1a658210a4
feat: azure workload identity support ( #4489 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-06-01 10:16:23 +03:00
DmitriyLewen
411862c908
feat(ubuntu): add eol date for 18.04 ESM ( #4524 )
2023-06-01 09:48:33 +03:00
simar7
62a1aaf031
fix(misconf): Update required extensions for terraformplan ( #4523 )
...
Signed-off-by: Simar <simar@linux.com >
2023-06-01 07:23:37 +03:00
Teppei Fukuda
48b2e15c23
refactor(cyclonedx): add intermediate representation ( #4490 )
2023-06-01 05:50:47 +03:00
simar7
c15f269a99
fix(misconf): Remove debug print while scanning ( #4521 )
...
Signed-off-by: Simar <simar@linux.com >
2023-06-01 05:28:37 +03:00
DmitriyLewen
b6ee08e55d
fix(java): remove duplicates of jar libs ( #4515 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-05-31 15:09:18 +03:00
DmitriyLewen
d4740401a3
fix(java): fix overwriting project props in pom.xml ( #4498 )
2023-05-31 13:16:28 +03:00
Tung Bui (Leo)
4cf2f94d0d
docs: Update compilation instructions ( #4512 )
2023-05-31 10:47:56 +03:00
DmitriyLewen
18ce1c3363
fix(nodejs): update logic for parsing pnpm lock files ( #4502 )
2023-05-31 08:41:08 +03:00
DmitriyLewen
87eed38c6c
fix(secret): remove aws-account-id rule ( #4494 )
2023-05-31 07:00:20 +03:00
LaurentiuNiculae
b0c591ef66
feat(oci): add support for referencing an input image by digest ( #4470 )
...
Signed-off-by: Laurentiu Niculae <niculae.laurentiu1@gmail.com >
2023-05-31 06:39:42 +03:00
dependabot[bot]
b84b5ecfc2
chore(deps): bump github.com/cloudflare/circl from 1.1.0 to 1.3.3 ( #4338 )
2023-05-30 18:50:09 +03:00
Tej Singh Rana
305255a497
docs: fixed the format ( #4503 )
2023-05-30 16:37:06 +03:00
DmitriyLewen
d586de585e
fix(java): add support of * for exclusions for pom.xml files ( #4501 )
2023-05-30 16:34:54 +03:00
Anais Urlichs
de6eef3b00
feat: adding issue template for documentation ( #4453 )
2023-05-30 12:23:05 +03:00
DmitriyLewen
83a9c4a4cf
docs: switch glad to ghsa for Go ( #4493 )
2023-05-30 09:46:49 +03:00
simar7
537272257b
chore(deps): Update defsec to v0.89.0 ( #4474 )
2023-05-30 06:06:46 +03:00
simar7
6fcd1538d9
feat(misconf): Add terraformplan support ( #4342 )
...
* feat(misconf): Add terraformplan support
Fixes: https://github.com/aquasecurity/trivy/issues/4341
Signed-off-by: Simar <simar@linux.com >
* update defsec
* fix lint
Signed-off-by: Simar <simar@linux.com >
* remove debug prints
Signed-off-by: Simar <simar@linux.com >
* update tests
Signed-off-by: Simar <simar@linux.com >
---------
Signed-off-by: Simar <simar@linux.com >
2023-05-29 14:48:26 -06:00
DmitriyLewen
72e302cf81
feat(debian): add digests for dpkg ( #4445 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-05-28 10:30:58 +03:00
dependabot[bot]
7e99d08a13
chore(deps): bump github.com/sigstore/rekor from 1.1.1 to 1.2.0 ( #4478 )
2023-05-28 06:37:30 +03:00
chenk
12a1789be5
feat(k8s): exclude node scanning by node labels ( #4459 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-05-25 14:52:28 +03:00
DmitriyLewen
919e8c92b2
docs: add info about multi-line mode for regexp from custom secret rules ( #4159 )
2023-05-24 14:59:50 +03:00
Teppei Fukuda
50fe43f14c
feat(cli): convert JSON reports into a different format ( #4452 )
...
Co-authored-by: Aurelien LAJOIE <aurelien.lajoie@kili-technology.com >
2023-05-24 11:45:26 +03:00
DmitriyLewen
09db1d4389
feat(image): add logic to guess base layer for docker-cis scan ( #4344 )
2023-05-24 10:43:09 +03:00
afdesk
3f0721ff6e
fix(cyclonedx): set original names for packages ( #4306 )
2023-05-23 12:35:52 +03:00
Teppei Fukuda
0ef0dadb16
feat: group subcommands ( #4449 )
2023-05-23 08:15:39 +03:00
rlubetkin
3a7717fdeb
feat(cli): add retry to cache operations ( #4189 )
2023-05-22 16:56:18 +03:00
AliDatadog
63cfb2714a
fix(vuln): report architecture for apk packages ( #4247 )
...
Co-authored-by: Sylvain Baubeau <lebauce@gmail.com >
2023-05-22 16:37:00 +03:00
Teppei Fukuda
e1361368a1
refactor: enable cases where return values are not needed in pipeline ( #4443 )
2023-05-22 08:11:24 +03:00
Mike Poindexter
29b5f7e8ec
fix(image): resolve scan deadlock when error occurs in slow mode ( #4336 )
2023-05-21 10:48:06 +03:00
simar7
92ed344e8a
docs(misconf): Update docs for kubernetes file patterns ( #4435 )
...
Signed-off-by: Simar <simar@linux.com >
2023-05-21 10:20:15 +03:00
chenk
16af41be15
test: k8s integration tests ( #4423 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-05-18 22:41:22 +03:00
DmitriyLewen
cab8569cd7
feat(redhat): add package digest for rpm ( #4410 )
2023-05-18 14:30:00 +03:00
simar7
92f9e98d04
feat(misconf): Add --reset-policy-bundle for policy bundle ( #4167 )
2023-05-18 11:54:01 +03:00
guangwu
33fb04763d
fix: typo ( #4431 )
2023-05-18 10:09:26 +03:00
DmitriyLewen
8b162f287f
add user instruction to imgconf ( #4429 )
2023-05-18 08:53:34 +03:00
DmitriyLewen
3b7c9198dd
fix(k8s): add image sources ( #4411 )
2023-05-17 07:01:58 +03:00
simar7
c75d35ff61
docs(scanning): Add versioning banner ( #4415 )
2023-05-17 06:32:17 +03:00
DmitriyLewen
d298415c09
feat(cli): add mage command to update golden integration test files ( #4380 )
2023-05-16 13:58:50 +03:00
chenk
1a56295ff8
feat: node-collector custom namespace support ( #4407 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-05-16 13:41:01 +03:00
DmitriyLewen
864ad10a38
chore(deps): bump owenrumney/go-sarif from v2.1.3 to v2.2.0 ( #4378 )
2023-05-16 09:02:15 +03:00
DmitriyLewen
7a20d96227
refactor(sbom): use multiline json for spdx-json format ( #4404 )
2023-05-16 08:22:07 +03:00
Chris Novakovic
ea5fd75ffe
fix(ubuntu): add EOL date for Ubuntu 23.04 ( #4347 )
2023-05-16 05:21:45 +03:00
guangwu
56a01ec6f7
refactor: code-optimization ( #4214 )
2023-05-15 14:48:09 +03:00
Peter Engelbert
6a0e152657
feat(image): Add image-src flag to specify which runtime(s) to use ( #4047 )
...
Signed-off-by: Peter Engelbert <pmengelbert@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-05-15 14:42:42 +03:00
DmitriyLewen
50c8b418a9
test: skip wrong update of test golden files ( #4379 )
2023-05-15 11:35:50 +03:00
DmitriyLewen
51ca6536c3
refactor: don't return error for package.json without version/name ( #4377 )
2023-05-15 11:30:10 +03:00
guangwu
e5e7ebcdab
docs: cmd error ( #4376 )
2023-05-15 08:58:32 +03:00
DmitriyLewen
6ee4960776
test(cli): add test for config file and env combination ( #2666 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-05-15 08:56:56 +03:00
afdesk
c067b026e0
fix(report): set a correct file location for license scan output ( #4326 )
2023-05-14 15:27:13 +03:00
afdesk
ff6374829a
ci: rpm repository for all versions and aarch64 ( #4077 )
...
Co-authored-by: Franco Gil <45880759+realFranco@users.noreply.github.com >
2023-05-14 14:53:25 +03:00
Eugene Bykov
0009b02bb8
chore(alpine): Update Alpine to 3.18 ( #4351 )
2023-05-14 14:37:35 +03:00
Chris Novakovic
d61ae8cc73
fix(alpine): add EOL date for Alpine 3.18 ( #4308 )
2023-05-12 13:30:11 +03:00
dependabot[bot]
636ce808fe
chore(deps): bump github.com/docker/distribution ( #4337 )
2023-05-12 07:59:23 +03:00
Teppei Fukuda
e859d10eef
feat: allow root break for mapfs ( #4094 )
2023-05-11 14:41:17 +03:00
simar7
a6ef37fa3d
docs(misconf): Remove examples.md ( #4256 )
2023-05-10 20:41:18 +03:00
afdesk
dca8c039ed
fix(ubuntu): update eol dates for Ubuntu ( #4258 )
2023-05-10 18:10:12 +03:00
DmitriyLewen
b003f58b2c
feat(alpine): add digests for apk packages ( #4168 )
2023-05-10 16:37:50 +03:00
Teppei Fukuda
86f0016165
chore: add discussion templates ( #4190 )
2023-05-10 12:06:37 +03:00
simar7
2f318ce97d
fix(terraform): Support tfvars ( #4123 )
2023-05-10 11:18:19 +03:00
Teppei Fukuda
ec3906c24e
chore: separate docs:generate ( #4242 )
2023-05-10 09:08:31 +03:00
dependabot[bot]
37b25d28b2
chore(deps): bump github.com/aws/aws-sdk-go-v2/config ( #4246 )
2023-05-10 09:06:23 +03:00
Teppei Fukuda
45d5edb0d7
refactor: define vulnerability scanner interfaces ( #4117 )
2023-05-09 22:25:08 +03:00
chenk
090a00e717
feat: unified k8s scan resources ( #4188 )
2023-05-09 16:52:02 +03:00
simar7
f2188eb56d
chore(deps): Update defsec to v0.88.1 ( #4178 )
2023-05-09 16:34:29 +03:00
dependabot[bot]
b79850f416
chore(deps): bump github.com/alicebob/miniredis/v2 from 2.30.1 to 2.30.2 ( #4141 )
2023-05-09 16:01:12 +03:00
guangwu
36acdfa8db
chore: trivy bin ignore ( #4212 )
2023-05-09 12:03:47 +03:00
Teppei Fukuda
55fb723a6e
feat(image): enforce image platform ( #4083 )
2023-05-08 21:04:22 +03:00
dependabot[bot]
9c87cb2710
chore(deps): bump github.com/owenrumney/go-sarif/v2 from 2.1.2 to 2.1.3 ( #4143 )
2023-05-08 12:07:30 +03:00
dependabot[bot]
21cf179f6b
chore(deps): bump github.com/docker/docker ( #4144 )
2023-05-07 21:56:16 +03:00
dependabot[bot]
fbf7a77aee
chore(deps): bump github.com/hashicorp/golang-lru/v2 from 2.0.1 to 2.0.2 ( #4146 )
2023-05-07 21:55:24 +03:00
dependabot[bot]
547391c224
chore(deps): bump aquaproj/aqua-installer from 2.0.2 to 2.1.1 ( #4140 )
2023-05-05 12:59:49 +03:00
DmitriyLewen
882bfdd782
fix(ubuntu): fix version selection logic for ubuntu esm ( #4171 )
2023-05-05 12:59:02 +03:00
dependabot[bot]
949cd10c0c
chore(deps): bump github.com/samber/lo from 1.37.0 to 1.38.1 ( #4147 )
2023-05-05 12:56:59 +03:00
dependabot[bot]
93bc162ca5
chore(deps): bump github.com/hashicorp/go-getter from 1.7.0 to 1.7.1 ( #4145 )
2023-05-04 15:06:52 +03:00
dependabot[bot]
57993ef673
chore(deps): bump sigstore/cosign-installer from 3.0.1 to 3.0.3 ( #4138 )
2023-05-04 13:55:10 +03:00
dependabot[bot]
dc4baeb359
chore(deps): bump github.com/testcontainers/testcontainers-go ( #4150 )
2023-05-04 13:53:27 +03:00
second-frank
25d0255dc3
chore: install.sh support for windows ( #4155 )
2023-05-04 13:48:58 +03:00
dependabot[bot]
73e54549f1
chore(deps): bump github.com/sigstore/rekor from 1.1.0 to 1.1.1 ( #4166 )
2023-05-04 13:44:02 +03:00
dependabot[bot]
08de7c613f
chore(deps): bump golang.org/x/crypto from 0.7.0 to 0.8.0 ( #4149 )
2023-05-03 12:23:58 +03:00
Anais Urlichs
ade4730fa7
docs: moving skipping files out of others ( #4154 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2023-05-03 12:23:21 +03:00
Masahiro331
1be1e2e638
fix(spdx): add workaround for no src packages ( #4118 )
2023-04-28 07:16:21 +03:00
Teppei Fukuda
45bc9e0de4
test(golang): rename broken go.mod ( #4129 )
2023-04-28 07:02:59 +03:00
DmitriyLewen
3334e78fa3
feat(sbom): add supplier field ( #4122 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2023-04-27 14:31:49 +03:00
DmitriyLewen
27fb1bfdee
test(misconf): skip downloading of policies for tests #4126
2023-04-27 14:25:31 +03:00
DmitriyLewen
845ae31e5d
refactor: use debug message for post-analyze errors ( #4037 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-27 12:07:35 +03:00
Teppei Fukuda
11a5b91a1a
feat(sbom): add VEX support ( #4053 )
2023-04-27 10:21:06 +03:00
DmitriyLewen
5eab464987
feat(sbom): add primary package purpose field for SPDX ( #4119 )
2023-04-25 14:47:25 +03:00
chenk
a00d00eb94
fix(k8s): fix quiet flag ( #4120 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-04-25 14:46:37 +03:00
DmitriyLewen
9bc326909f
fix(python): parse of pip extras ( #4103 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-24 21:17:56 +03:00
DmitriyLewen
8559841677
feat(java): use full path for nested jars ( #3992 )
2023-04-24 13:45:41 +03:00
Adarsh A
0650e0e1d5
feat(license): add new flag for classifier confidence level ( #4073 )
...
Co-authored-by: Aswath S <aswath.s@thoughtworks.com >
2023-04-24 13:41:08 +03:00
chenk
43b6496274
feat: config and fs compliance support ( #4097 )
2023-04-24 11:49:19 +03:00
dependabot[bot]
9181bc1f70
chore(deps): bump sigstore/cosign-installer from 2.8.1 to 3.0.1 ( #3952 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-04-24 08:43:07 +03:00
Idan Frimark
48e021ea6b
feat(spdx): add support for SPDX 2.3 ( #4058 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-23 23:36:04 +03:00
chenk
107752df65
fix: k8s all-namespaces support ( #4096 )
2023-04-23 20:08:37 +03:00
Teppei Fukuda
bd0c60364a
perf(misconf): replace with post-analyzers ( #4090 )
...
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: Simar <simar@linux.com >
2023-04-23 19:22:46 +03:00
bgoareguer
76662d5dd7
fix(helm): update networking API version detection ( #4106 )
2023-04-23 10:50:40 +03:00
aswath-s-tw
be47b688c7
feat(image): custom docker host option ( #3599 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-20 22:10:51 +03:00
Chris Burns
cc18f92cf3
style: debug flag is incorrect and needs extra - ( #4087 )
2023-04-19 10:02:44 +03:00
Jonathan Lassoff
572a6193e7
docs(vuln): Document inline vulnerability filtering comments ( #4024 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-18 12:02:14 +03:00
Teppei Fukuda
914c6f0921
feat(fs): customize error callback during fs walk ( #4038 )
2023-04-17 16:51:51 +03:00
DmitriyLewen
3f02feeff3
fix(ubuntu): skip copyright files from subfolders ( #4076 )
2023-04-17 14:07:58 +03:00
Teppei Fukuda
57bb77c060
docs: restructure scanners ( #3977 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-04-17 11:54:31 +03:00
DmitriyLewen
b19b56c341
fix: fix file does not exist error for post-analyzers ( #4061 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-17 08:15:44 +03:00
simar7
b43b19ba54
feat(flag): Support globstar for --skip-files and --skip-directories ( #4026 )
...
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-16 13:48:20 +03:00
dependabot[bot]
14805002d3
chore(deps): bump actions/stale from 7 to 8 ( #3955 )
2023-04-16 13:40:12 +03:00
DmitriyLewen
83bb97ab13
fix: return insecure option to download javadb ( #4064 )
2023-04-15 08:26:50 +03:00
DmitriyLewen
79a1ba32d5
fix(nodejs): don't stop parsing when unsupported yarn.lock protocols are found ( #4052 )
2023-04-14 07:35:51 +03:00
afdesk
ff1c43a791
ci: add gpg signing for RPM packages ( #4056 )
2023-04-14 07:28:44 +03:00
chenk
b608b116cc
fix(k8s): current context title ( #4055 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-04-13 17:56:22 +03:00
chenk
2c3b60f4c9
fix(k8s): quit support on k8s progress bar ( #4021 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-04-13 17:30:54 +03:00
afdesk
a6b8642134
chore: add a note about Dockerfile.canary ( #4050 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-13 17:27:28 +03:00
afdesk
90b80662c6
ci: fix path to canary binaries ( #4045 )
2023-04-13 10:27:06 +03:00
AliDatadog
dcefc6bf3c
fix(vuln): report architecture for debian packages ( #4032 )
2023-04-12 15:51:12 +03:00
Dan Luhring
601e25fb2f
feat: add support for Chainguard's commercial distro ( #3641 )
2023-04-12 15:20:52 +03:00
afdesk
0bebec19f0
ci: bump goreleaser for Github Action from 1.4.1 to 1.16.2 ( #3979 )
2023-04-12 15:15:16 +03:00
AliDatadog
707ea94234
fix(vuln): fix error message for remote scanners ( #4031 )
2023-04-11 16:50:45 +03:00
Teppei Fukuda
8e1fe769e4
feat(report): add image metadata to SARIF ( #4020 )
...
* feat(report): add image metadata to SARIF
* test: fix sarif golden
2023-04-11 16:33:25 +03:00
DmitriyLewen
4b36e97dce
docs: fix broken cache link on Installation page ( #3999 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-10 15:38:03 +03:00
Teppei Fukuda
f0df725c5a
fix: lock downloading policies and database ( #4017 )
2023-04-10 15:37:13 +03:00
Teppei Fukuda
009675c825
fix: avoid concurrent access to the global map ( #4014 )
2023-04-10 12:30:08 +03:00
DmitriyLewen
3ed86aa3d0
feat(rust): add Cargo.lock v3 support ( #4012 )
2023-04-10 11:46:43 +03:00
chenk
f31dea4bd6
feat: auth support oci download server subcommand ( #4008 )
2023-04-10 08:26:17 +03:00
dependabot[bot]
d37c50a2b3
chore(deps): bump github.com/docker/docker ( #4009 )
2023-04-09 22:29:13 +03:00
Yousaf Nabi
693d20516b
chore: install.sh support for armv7 ( #3985 )
2023-04-09 22:18:13 +03:00
dependabot[bot]
65d89b99d1
chore(deps): bump github.com/Azure/go-autorest/autorest/adal ( #3961 )
2023-04-09 15:58:06 +03:00
DmitriyLewen
a119ef86ea
fix(rust): fix panic when 'dependencies' field is not used in cargo.toml ( #3997 )
2023-04-09 11:06:57 +03:00
DmitriyLewen
c8283cebde
fix(sbom): fix infinite loop for cyclonedx ( #3998 )
2023-04-09 09:10:02 +03:00
dependabot[bot]
6c8b042548
chore(deps): bump helm/chart-testing-action from 2.3.1 to 2.4.0 ( #3954 )
2023-04-04 16:15:26 +03:00
DmitriyLewen
c42f360f57
fix: use warning for errors from enrichment files for post-analyzers ( #3972 )
2023-04-04 16:11:07 +03:00
dependabot[bot]
20c21caccf
chore(deps): bump github.com/docker/docker ( #3963 )
2023-04-04 14:06:41 +03:00
Rewanth Tammana
54388ffd16
fix(helm): added annotation to psp configurable from values ( #3893 )
...
Signed-off-by: Rewanth Tammana <22347290+rewanthtammana@users.noreply.github.com >
2023-04-03 11:24:43 +03:00
dependabot[bot]
99a2519816
chore(deps): bump github.com/go-git/go-git/v5 from 5.5.2 to 5.6.1 ( #3962 )
2023-04-03 11:23:30 +03:00
afdesk
d113b93139
fix(secret): update built-in rule tests ( #3855 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2023-04-03 10:37:08 +03:00
dependabot[bot]
5ab6d25880
chore(deps): bump github.com/alicebob/miniredis/v2 from 2.23.0 to 2.30.1 ( #3957 )
2023-04-03 10:32:13 +03:00
Teppei Fukuda
0767cb8443
test: rewrite scripts in Go ( #3968 )
2023-04-03 10:31:10 +03:00
simar7
428ee19cae
docs(cli): Improve glob documentation ( #3945 )
...
Signed-off-by: Simar <simar@linux.com >
2023-04-03 07:59:02 +03:00
dependabot[bot]
3e00dc346f
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/sts ( #3959 )
2023-04-03 07:57:54 +03:00
Teppei Fukuda
cf2f0b2d1c
ci: check CLI references ( #3967 )
2023-04-03 07:57:08 +03:00
dependabot[bot]
70f507e1af
chore(deps): bump alpine from 3.17.2 to 3.17.3 ( #3951 )
2023-04-03 06:37:49 +03:00
dependabot[bot]
befabc6b99
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.212 to 1.44.234 ( #3956 )
2023-04-03 06:36:35 +03:00
dependabot[bot]
ee69abb78f
chore(deps): bump github.com/moby/buildkit from 0.11.4 to 0.11.5 ( #3958 )
2023-04-02 19:29:28 +03:00
dependabot[bot]
8901f7be62
chore(deps): bump actions/setup-go from 3 to 4 ( #3953 )
2023-04-02 19:28:40 +03:00
dependabot[bot]
4e6bbbc8cc
chore(deps): bump actions/cache from 3.2.6 to 3.3.1 ( #3950 )
2023-04-02 19:28:10 +03:00
dependabot[bot]
d70f346f53
chore(deps): bump github.com/containerd/containerd from 1.6.19 to 1.7.0 ( #3965 )
2023-04-02 16:27:22 +03:00
dependabot[bot]
3efb2fdeda
chore(deps): bump github.com/sigstore/rekor from 1.0.1 to 1.1.0 ( #3964 )
2023-04-02 10:49:41 +03:00
Krishna Dutt Panchagnula
ed590966a3
docs(cli): added makefile and go file to create docs ( #3930 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2023-04-01 08:43:21 +03:00
Teppei Fukuda
a2f39a34c5
chore: Revert "ci: add gpg signing for RPM packages ( #3612 )" ( #3946 )
...
This reverts commit 67572dff6d .
2023-04-01 08:39:22 +03:00
Teppei Fukuda
5a10631023
chore: ignore gpg key ( #3943 )
2023-04-01 06:39:31 +03:00
afdesk
4072115e5a
feat(cyclonedx): support dependency graph ( #3177 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-01 00:46:30 +03:00
simar7
7cad265b7a
chore(deps): Bump defsec to v0.85.0 ( #3940 )
...
Signed-off-by: Simar <simar@linux.com >
2023-03-31 16:58:01 +03:00
DmitriyLewen
f8b5733112
feat(rust): remove dev deps and find direct deps for Cargo.lock ( #3919 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-30 22:05:34 +03:00
Rо́man
10796a2910
feat(server): redis with public TLS certs support ( #3783 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-30 15:53:21 +03:00
simar7
abff1398c2
feat(flag): Add glob support to --skip-dirs and --skip-files ( #3866 )
2023-03-30 10:48:56 +03:00
Teppei Fukuda
b40f60c405
chore: replace make with mage ( #3932 )
2023-03-30 10:40:24 +03:00
DmitriyLewen
67236f6aac
fix(sbom): add checksum to files ( #3888 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-30 09:24:27 +03:00
dependabot[bot]
00de24b16e
chore(deps): bump github.com/opencontainers/runc from 1.1.4 to 1.1.5 ( #3928 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-30 09:23:39 +03:00
chenk
5976d1fa07
chore: remove unused mount volumes ( #3927 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-03-30 07:33:03 +03:00
Teppei Fukuda
f14bed4532
feat: add auth support for downloading OCI artifacts ( #3915 )
2023-03-30 05:53:24 +03:00
DmitriyLewen
1ee05189f0
refactor(purl): use epoch in qualifier ( #3913 )
2023-03-28 13:26:56 +03:00
dependabot[bot]
0000252ce4
chore(deps): bump github.com/in-toto/in-toto-golang from 0.5.0 to 0.7.0 ( #3727 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-28 13:22:47 +03:00
Teppei Fukuda
ca0d972cdb
feat(image): add registry options ( #3906 )
2023-03-28 07:00:04 +03:00
AndreyLevchenko
0336555773
feat(rust): dependency tree and line numbers support for cargo lock file ( #3746 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-26 14:43:45 +03:00
dependabot[bot]
dd9cd9528f
chore(deps): bump google.golang.org/protobuf from 1.29.0 to 1.29.1 ( #3905 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-26 13:20:02 +03:00
DmitriyLewen
edb06826b4
feat(php): add support for location, licenses and graph for composer.lock files ( #3873 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-26 12:02:53 +03:00
Crypt Keeper
c02b15b371
chore(deps): updates wazero to 1.0.0 ( #3904 )
...
Signed-off-by: Adrian Cole <adrian@tetrate.io >
2023-03-26 08:50:38 +03:00
Teppei Fukuda
63ef760c69
feat(image): discover SBOM in OCI referrers ( #3768 )
...
Co-authored-by: saso <sasoakira6114@gmail.com >
2023-03-26 08:27:10 +03:00
DmitriyLewen
3fa703c034
docs: change cache-dir key in config file ( #3897 )
2023-03-24 19:12:14 +03:00
DmitriyLewen
4d78747c40
fix(sbom): use release and epoch for SPDX package version ( #3896 )
2023-03-24 19:11:06 +03:00
afdesk
67572dff6d
ci: add gpg signing for RPM packages ( #3612 )
2023-03-24 06:46:18 +03:00
adamcohen2
e76d5ff98a
docs: Update incorrect comment for skip-update flag ( #3878 )
2023-03-23 07:25:01 +02:00
Teppei Fukuda
011ea60db4
refactor(misconf): simplify policy filesystem ( #3875 )
2023-03-23 06:27:29 +02:00
DmitriyLewen
6445309de4
feat(nodejs): parse package.json alongside yarn.lock ( #3757 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-21 19:13:02 +02:00
DmitriyLewen
6e9c2c36da
fix(spdx): add PkgDownloadLocation field ( #3879 )
2023-03-21 16:11:38 +02:00
DmitriyLewen
18eeea2f62
fix(report): try to guess direct deps for dependency tree ( #3852 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-21 12:55:07 +02:00
DmitriyLewen
02b6914212
chore(amazon): update EOL ( #3876 )
2023-03-21 07:11:56 +02:00
DmitriyLewen
79096e1161
fix(nodejs): improvement logic for package-lock.json v2-v3 ( #3877 )
2023-03-21 07:06:34 +02:00
DmitriyLewen
fc2e80cfe0
feat(amazon): add al2023 support ( #3854 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-20 15:56:16 +02:00
dependabot[bot]
5f8d69d72e
chore(deps): bump github.com/cheggaaa/pb/v3 from 3.1.0 to 3.1.2 ( #3736 )
2023-03-20 14:13:30 +02:00
simar7
7916aafffb
docs(misconf): Add information about selectors ( #3703 )
...
Signed-off-by: Simar <simar@linux.com >
2023-03-20 14:12:35 +02:00
Shubham Palriwala
1b1ed39c7d
docs(cli): update CLI docs with cobra ( #3815 )
2023-03-20 13:48:58 +02:00
chenk
234a360a7a
feat: k8s parallel processing ( #3693 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-20 13:34:38 +02:00
bgoareguer
b864b3b926
docs: add DefectDojo in the Security Management section ( #3871 )
2023-03-20 11:38:26 +02:00
Crypt Keeper
ad34c989de
chore(deps): updates wazero to 1.0.0-rc.2 ( #3853 )
...
Signed-off-by: Adrian Cole <adrian@tetrate.io >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-19 19:56:01 +02:00
Teppei Fukuda
7148de3252
refactor: add pipeline ( #3868 )
2023-03-19 19:55:36 +02:00
DmitriyLewen
927acf9579
feat(cli): add javadb metadata to version info ( #3835 )
2023-03-19 15:51:14 +02:00
simar7
33074cfab3
chore(deps): Move compliance types to defsec ( #3842 )
...
Signed-off-by: Simar <simar@linux.com >
2023-03-19 15:46:06 +02:00
saso
ba9b0410c9
feat(sbom): add support for CycloneDX JSON Attestation of the correct specification ( #3849 )
2023-03-19 15:40:58 +02:00
chenk
a754a04e2b
feat: add node toleration option ( #3823 )
2023-03-19 14:05:57 +02:00
Teppei Fukuda
9e4b57fb43
fix: allow mapfs to open dirs ( #3867 )
2023-03-19 13:33:50 +02:00
DmitriyLewen
09fd299f96
fix(report): update uri only for os class targets ( #3846 )
2023-03-17 10:15:24 +02:00
DmitriyLewen
09e13022c2
feat(nodejs): Add v3 npm lock file support ( #3826 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-15 21:54:59 +02:00
DmitriyLewen
52cbfebcdd
feat(nodejs): parse package.json files alongside package-lock.json ( #2916 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-15 21:54:01 +02:00
simar7
d6a2d6369a
docs(misconf): Fix links to built in policies ( #3841 )
...
Signed-off-by: Simar <simar@linux.com >
2023-03-15 11:47:44 +02:00
dependabot[bot]
a12f58be57
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.86.1 to 1.89.1 ( #3827 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-14 11:17:36 +02:00
DmitriyLewen
ee518350c5
fix(java): skip empty files for jar post analyzer ( #3832 )
2023-03-14 11:15:31 +02:00
DmitriyLewen
3987a679f9
fix(docker): build healthcheck command for line without /bin/sh prefix ( #3831 )
2023-03-14 09:28:36 +02:00
Teppei Fukuda
2bb25e766b
refactor(license): use goyacc for license parser ( #3824 )
2023-03-14 09:27:17 +02:00
dependabot[bot]
00c763bc10
chore(deps): bump github.com/docker/docker from 23.0.0-rc.1+incompatible to 23.0.1+incompatible ( #3586 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-13 17:33:07 +02:00
chenk
cac5881bbb
fix: populate timeout context to node-collector ( #3766 )
2023-03-13 13:10:37 +02:00
chenk
bd9c6e613e
fix: exclude node collector scanning ( #3771 )
2023-03-13 11:40:23 +02:00
Ari Yonaty
20f10673b9
fix: display correct flag in error message when skipping java db update #3808
2023-03-13 00:39:17 +02:00
DmitriyLewen
1fac7bf1ba
fix: disable jar analyzer for scanners other than vuln ( #3810 )
2023-03-13 00:11:25 +02:00
Masahiro331
aaf265881e
fix(sbom): fix incompliant license format for spdx ( #3335 )
2023-03-12 17:21:25 +02:00
DmitriyLewen
f8307635ad
fix(java): the project props take precedence over the parent's props ( #3320 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-09 19:25:52 +02:00
DmitriyLewen
1aa3b7dc28
docs: add canary build info to README.md ( #3799 )
2023-03-09 13:36:04 +02:00
Anais Urlichs
57904c0f97
docs: adding link to gh token generation ( #3784 )
2023-03-08 14:24:02 +02:00
Anais Urlichs
bdccf72338
docs: changing docs in accordance with #3460 ( #3787 )
2023-03-08 14:23:17 +02:00
dependabot[bot]
800473a8bc
chore(deps): bump github.com/moby/buildkit from 0.11.0 to 0.11.4 ( #3789 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-08 11:51:16 +02:00
dependabot[bot]
e6ab389f9e
chore(deps): bump actions/add-to-project from 0.4.0 to 0.4.1 ( #3724 )
2023-03-07 13:35:06 +02:00
DmitriyLewen
6614398ab4
fix(license): disable jar analyzer for licence scan only ( #3780 )
2023-03-07 13:22:23 +02:00
DmitriyLewen
1dc6fee781
bump trivy-issue-action to v0.0.0; skip pkg dir ( #3781 )
2023-03-07 11:52:32 +02:00
DmitriyLewen
3357ed096b
fix: skip checking dirs for required post-analyzers ( #3773 )
2023-03-06 13:29:35 +02:00
afdesk
1064636b3d
docs: add information about plugin format ( #3749 )
2023-03-06 11:27:30 +02:00
DmitriyLewen
60b7ef5a55
fix(sbom): add trivy version to spdx creators tool field ( #3756 )
...
* fix(sbom): add trivy version to spdx creators tool field
* refactor test
2023-03-03 10:41:39 +02:00
simar7
497c955a4b
feat(misconf): Add support to show policy bundle version ( #3743 )
...
Fixes: https://github.com/aquasecurity/trivy/issues/3696
Signed-off-by: Simar <simar@linux.com >
2023-03-02 17:00:45 +02:00
Andrea Scarpino
5d54310d76
fix(python): fix error with optional dependencies in pyproject.toml ( #3741 )
2023-03-02 16:58:03 +02:00
dependabot[bot]
44cf1e2f57
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.210 to 1.44.212 ( #3740 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-02 15:18:51 +02:00
DmitriyLewen
743b4b0d97
add id for package.json files ( #3750 )
2023-03-02 14:25:56 +02:00
dependabot[bot]
6de43855f8
chore(deps): bump github.com/containerd/containerd from 1.6.18 to 1.6.19 ( #3738 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-02 13:20:32 +02:00
dependabot[bot]
9a0ceef166
chore(deps): bump actions/cache from 3.2.4 to 3.2.6 ( #3725 )
2023-03-01 23:14:17 +02:00
dependabot[bot]
0501b46d48
chore(deps): bump github.com/google/go-containerregistry ( #3731 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-01 23:13:31 +02:00
dependabot[bot]
ee3004d292
chore(deps): bump go.etcd.io/bbolt from 1.3.6 to 1.3.7 ( #3732 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-01 20:53:53 +02:00
dependabot[bot]
5c8e604f56
chore(deps): bump alpine from 3.17.1 to 3.17.2 ( #3723 )
2023-03-01 20:53:30 +02:00
Teppei Fukuda
bc0836623c
fix(cli): pass integer to exit-on-eol ( #3716 )
2023-03-01 12:18:11 +02:00
Itay Shakury
23cdac02ee
feat: add kubernetes pss compliance ( #3498 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-01 12:10:34 +02:00
Kalyana Krishna Varanasi
302c8ae24c
feat: Adding --module-dir and --enable-modules ( #3677 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-01 12:09:53 +02:00
Teppei Fukuda
34120f4201
feat: add special IDs for filtering secrets ( #3702 )
2023-03-01 09:51:11 +02:00
simar7
e399ed8439
chore(deps): Update defsec ( #3713 )
...
* chore(deps): Update defsec
* fix tests
2023-03-01 08:10:03 +02:00
simar7
ef7b762e48
docs(misconf): Add guide on input schema ( #3692 )
...
* docs(misconf): Add guide on input schema
* Update docs/docs/misconfiguration/custom/schema.md
Co-authored-by: Itay Shakury <itay@itaysk.com >
* make schema usage more descriptive
* docs: point to the full page
* update docs
Signed-off-by: Simar <simar@linux.com >
---------
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: Itay Shakury <itay@itaysk.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-28 15:55:49 -08:00
Teppei Fukuda
00daebc161
feat(go): support dependency graph and show only direct dependencies in the tree ( #3691 )
2023-02-28 13:24:53 +02:00
chenk
98d1031552
feat: docker multi credential support ( #3631 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-02-28 11:42:37 +02:00
Teppei Fukuda
b791362871
feat: summarize vulnerabilities in compliance reports ( #3651 )
2023-02-28 00:09:00 +02:00
Teppei Fukuda
719fdb1b11
feat(python): parse pyproject.toml alongside poetry.lock ( #3695 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-02-27 20:48:55 +02:00
DmitriyLewen
3ff5699b4b
feat(python): add dependency tree for poetry lock file ( #3665 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-26 16:15:00 +02:00
Masahiro331
33909d9df3
fix(cyclonedx): incompliant affect ref ( #3679 )
2023-02-26 16:04:29 +02:00
Manuel Morejón
d85a3e087b
chore(helm): update skip-db-update environment variable ( #3657 )
...
Signed-off-by: Manuel Morejon <manuel@mmorejon.io >
2023-02-26 14:16:17 +02:00
Masahiro331
551899c24e
fix(spdx): change CreationInfo timestamp format RFC3336Nano to RFC3336 ( #3675 )
2023-02-26 10:11:47 +02:00
Teppei Fukuda
3aaa2cfb75
fix(sbom): export empty dependencies in CycloneDX ( #3664 )
2023-02-25 18:33:59 +02:00
Dmitry Ivankov
9d1300c3e7
docs: java-db air-gap doc tweaks ( #3561 )
...
Downloaded file name is `javadb.tar.gz` rather than `db.tar.gz`.
Also `--skip-update` is deprecated in favor of `--skip-db-update` and `--skip-java-db-update`.
2023-02-24 17:54:29 +02:00
Teppei Fukuda
793cc43d4c
feat(go): license support ( #3683 )
2023-02-24 17:52:35 +02:00
AndreyLevchenko
6a3294e476
feat(ruby): add dependency tree/location support for Gemfile.lock ( #3669 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-23 23:47:28 +02:00
chenk
e9dc21d88a
fix(k8s): k8s label size ( #3678 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-02-23 15:09:27 +02:00
Masahiro331
12976d42df
fix(cyclondx): fix array empty value, null to [] ( #3676 )
2023-02-23 13:35:59 +02:00
Teppei Fukuda
1dc2b349c6
refactor: rewrite gomod analyzer as post-analyzer ( #3674 )
2023-02-23 13:35:08 +02:00
chenk
92eaf636ca
feat: config outdated-api result filtered by k8s version ( #3578 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-22 15:41:37 +02:00
Alexander Lauster
9af436b999
fix: Update to Alpine 3.17.2 ( #3655 )
...
Fix CVE-2023-0286
2023-02-21 19:38:20 +02:00
Teppei Fukuda
88ee68d0c6
feat: add support for virtual files ( #3654 )
2023-02-20 17:20:57 +02:00
Teppei Fukuda
75c96bd968
feat: add post-analyzers ( #3640 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-02-20 13:08:26 +02:00
Edoardo Vacchi
baea3997d2
chore(deps): updates wazero to 1.0.0-pre.9 ( #3653 )
...
Signed-off-by: Edoardo Vacchi <evacchi@users.noreply.github.com >
2023-02-20 13:03:28 +02:00
dependabot[bot]
7ca0db17ea
chore(deps): bump github.com/go-openapi/runtime from 0.24.2 to 0.25.0 ( #3528 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-20 13:01:33 +02:00
dependabot[bot]
866999e454
chore(deps): bump github.com/containerd/containerd from 1.6.15 to 1.6.18 ( #3633 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-20 10:11:01 +02:00
DmitriyLewen
b7bfb9a207
feat(python): add dependency locations for Pipfile.lock ( #3614 )
2023-02-20 09:51:42 +02:00
dependabot[bot]
9badef27ac
chore(deps): bump golang.org/x/net from 0.5.0 to 0.7.0 ( #3648 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-19 15:51:12 +02:00
DmitriyLewen
d856595b8e
fix(java): fix groupID selection by ArtifactID for jar files. ( #3644 )
2023-02-18 09:07:08 +02:00
dependabot[bot]
fe7c26a741
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.63.1 to 1.85.0 ( #3607 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-17 12:44:55 +02:00
Gio Rodriguez
f251dfc5ce
fix(aws): Adding a fix for update-cache flag that is not applied on AWS scans. ( #3619 )
...
* adding a fix for update-cache that was not applied on AWS scans.
* removing unneeded code
---------
Co-authored-by: Gio Rodriguez <giovanni.rodriguez@aquasec.com >
2023-02-16 22:49:20 +02:00
didiermichel
9be8062c10
feat(cli): add command completion ( #3061 )
...
Co-authored-by: congbang-le <lecongbang314@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-15 13:29:03 +02:00
Duy Nguyen
370098dbf4
docs(misconf): update dockerfile link ( #3627 )
2023-02-15 11:54:56 +02:00
Jack Lin
32acd293fd
feat(flag): add exit-on-eosl option ( #3423 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-15 10:51:15 +02:00
dependabot[bot]
aa8e185e03
chore(deps): bump github.com/go-git/go-git/v5 from 5.4.2 to 5.5.2 ( #3533 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-14 16:17:28 +02:00
Alexej Disterhoft
86603bb9c5
fix(cli): make java db repository configurable ( #3595 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-14 15:01:15 +02:00
chenk
7b1e173f51
chore: bump trivy-kubernetes ( #3613 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-02-14 13:23:45 +02:00
Helge Eichelberg
85d5d61bc7
chore(helm): update Trivy from v0.36.1 to v0.37.2 ( #3574 )
...
* chore(helm): update Trivy from v0.36.1 to v0.37.1
Signed-off-by: elchenberg <elchenberg@users.noreply.github.com >
* chore(helm): bump Trivy to v0.37.2
Signed-off-by: elchenberg <elchenberg@users.noreply.github.com >
---------
Signed-off-by: elchenberg <elchenberg@users.noreply.github.com >
2023-02-14 13:10:07 +02:00
dependabot[bot]
2c17260ba8
chore(deps): bump github.com/spf13/viper from 1.14.0 to 1.15.0 ( #3536 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-14 13:09:43 +02:00
Teppei Fukuda
c54f1aa8f0
chore(deps): bump golang/x/mod to v0.8.0 ( #3606 )
2023-02-14 07:02:26 +02:00
dependabot[bot]
625ea58122
chore(deps): bump golang.org/x/crypto from 0.3.0 to 0.5.0 ( #3529 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-13 16:15:12 +02:00
dependabot[bot]
623c7f9432
chore(deps): bump helm.sh/helm/v3 from 3.10.3 to 3.11.1 ( #3580 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-13 16:14:25 +02:00
DmitriyLewen
d291c34f51
ci: quote pros in c++ for semantic pr ( #3605 )
2023-02-13 14:05:35 +02:00
DmitriyLewen
6cac6c917f
fix(image): check proxy settings from env for remote images ( #3604 )
2023-02-13 12:54:38 +02:00
DmitriyLewen
12b563b974
BREAKING: use normalized trivy-java-db ( #3583 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-10 02:16:37 +02:00
DmitriyLewen
72a14c67af
fix(image): add timeout for remote images ( #3582 )
...
* add timeout for remote image
* fix linter error
2023-02-09 14:19:17 +02:00
dependabot[bot]
4c01d73fb7
chore(deps): bump golang.org/x/mod from 0.6.0 to 0.7.0 ( #3532 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-07 08:38:25 +02:00
dependabot[bot]
10dd5d1a95
chore(deps): bump golang.org/x/text from 0.5.0 to 0.6.0 ( #3534 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2023-02-07 06:51:49 +02:00
simar7
439c541fd3
fix(misconf): handle dot files better ( #3550 )
2023-02-05 09:10:10 +09:00
Teppei Fukuda
200e04a767
chore: bump Go to 1.19 ( #3551 )
2023-02-03 15:08:01 +09:00
dependabot[bot]
a533ca87e6
chore(deps): bump alpine from 3.17.0 to 3.17.1 ( #3522 )
2023-02-03 04:21:25 +02:00
dependabot[bot]
4bccbe6e1c
chore(deps): bump docker/build-push-action from 3 to 4 ( #3523 )
2023-02-03 04:20:52 +02:00
dependabot[bot]
d0562085df
chore(deps): bump actions/cache from 3.2.2 to 3.2.4 ( #3524 )
2023-02-03 04:20:15 +02:00
dependabot[bot]
f5e65749b4
chore(deps): bump golangci/golangci-lint-action from 3.3.0 to 3.4.0 ( #3525 )
2023-02-03 04:17:39 +02:00
dependabot[bot]
d3da459d45
chore(deps): bump aquaproj/aqua-installer from 1.2.0 to 2.0.2 ( #3526 )
2023-02-03 04:15:56 +02:00
Teppei Fukuda
7f8868b7d8
fix(sbom): download the Java DB when generating SBOM ( #3539 )
2023-02-01 17:33:09 +02:00
Teppei Fukuda
364379b7b2
fix: use cgo free sqlite driver ( #3521 )
...
* fix: use cgo free sqlite driver
* chore: add CGO_ENABLED=0
* chore(deps): bump go-rpmdb
2023-02-01 17:06:12 +02:00
afdesk
0205475fa9
ci: fix path to dist folder ( #3527 )
2023-02-01 16:44:01 +02:00
Teppei Fukuda
e9d2af9174
fix(image): close layers ( #3517 )
2023-02-01 13:36:48 +02:00
Naimuddin Shaik
b169424089
refactor: db client changed ( #3515 )
...
changed the constructor to accept interface.
2023-02-01 13:15:36 +02:00
DmitriyLewen
7bf1e192ec
feat(java): use trivy-java-db to get GAV ( #3484 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-01 11:48:05 +02:00
Batuhan Apaydın
023e45b896
docs: add note about the limitation in Rekor ( #3494 )
...
Signed-off-by: Batuhan Apaydın <batuhan.apaydin@trendyol.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-01 11:14:47 +02:00
Teppei Fukuda
0fe62a93df
docs: aggregate targets ( #3503 )
2023-02-01 08:48:33 +02:00
Edoardo Vacchi
0373e0822d
deps: updates wazero to 1.0.0-pre.8 ( #3510 )
...
Signed-off-by: Edoardo Vacchi <evacchi@users.noreply.github.com >
2023-02-01 06:48:37 +02:00
DmitriyLewen
a2e21f9b5c
docs: add alma 9 and rocky 9 to supported os ( #3513 )
2023-02-01 06:47:26 +02:00
simar7
7d778b75f7
chore(deps): bump defsec to v0.82.9 ( #3512 )
2023-02-01 04:14:25 +02:00
Itay Shakury
9e9dbea717
chore: add missing target labels ( #3504 )
2023-01-31 17:20:56 +02:00
DmitriyLewen
d99a7b82f7
docs: add java vulnerability page ( #3429 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-31 08:10:24 +02:00
Teppei Fukuda
cb5af0b33b
feat(image): add support for Docker CIS Benchmark ( #3496 )
...
Co-authored-by: chenk <hen.keinan@gmail.com >
2023-01-31 07:31:59 +02:00
Teppei Fukuda
6eec9ac0a4
feat(image): secret scanning on container image config ( #3495 )
2023-01-30 16:50:56 +02:00
simar7
1eca973cbf
chore(deps): Upgrade defsec to v0.82.8 ( #3488 )
...
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-30 09:38:17 +02:00
Teppei Fukuda
fb0d8f3f30
feat(image): scan misconfigurations in image config ( #3437 )
2023-01-30 04:48:29 +02:00
Helge Eichelberg
501d424d1f
chore(helm): update Trivy from v0.30.4 to v0.36.1 ( #3489 )
...
Signed-off-by: elchenberg <elchenberg@users.noreply.github.com >
2023-01-28 07:12:08 +02:00
chenk
475dc17bc8
feat(k8s): add node info resource ( #3482 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-01-25 22:00:05 +02:00
kunlongli
ed173b8295
perf(secret): optimize secret scanning memory usage ( #3453 )
2023-01-25 11:45:09 +02:00
Teppei Fukuda
1b368be367
feat: support aliases in CLI flag, env and config ( #3481 )
2023-01-25 11:33:12 +02:00
chenk
66a83d5cdb
fix(k8s): migrate rbac k8s ( #3459 )
2023-01-25 11:13:41 +02:00
DmitriyLewen
81bee0f11e
feat(java): add implementationVendor and specificationVendor fields to detect GroupID from MANIFEST.MF ( #3480 )
2023-01-24 12:21:19 +02:00
Teppei Fukuda
e1076085d9
refactor: rename security-checks to scanners ( #3467 )
2023-01-23 16:53:06 +02:00
Teppei Fukuda
aaf845d02e
chore: display the troubleshooting URL for the DB denial error ( #3474 )
2023-01-23 16:12:00 +02:00
Corey Wilson
ed5bb0ba92
docs: yaml tabs to spaces, auto create namespace ( #3469 )
2023-01-23 10:51:55 +02:00
Anais Urlichs
3158bfe605
docs: adding show-and-tell template to GH discussions ( #3391 )
2023-01-22 17:34:09 +02:00
Lénaïc Huard
85b6c4aa15
fix: Fix a temporary file leak in case of error ( #3465 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-22 16:12:56 +02:00
Teppei Fukuda
60bddae64c
fix(test): sort cyclonedx components ( #3468 )
2023-01-22 14:21:20 +02:00
Anais Urlichs
e0bb04c915
docs: fixing spelling mistakes ( #3462 )
2023-01-22 14:18:15 +02:00
Teppei Fukuda
c25e826bb5
ci: set paths triggering VM tests in PR ( #3438 )
2023-01-22 11:35:19 +02:00
Raz Cohen
07ddc85a46
docs: typo in --skip-files ( #3454 )
2023-01-18 14:23:56 +02:00
Srinivas Kandukuri
e88507c999
feat(custom-forward): Extended advisory data ( #3444 )
2023-01-17 16:06:27 +02:00
Carl Winbäck
e2dfee208f
docs: fix spelling error ( #3436 )
2023-01-16 14:31:43 +00:00
Teppei Fukuda
c575d6f7de
refactor(image): extend image config analyzer ( #3434 )
2023-01-16 13:48:26 +02:00
Lior Vaisman Argon
036d5a8233
fix(nodejs): add ignore protocols to yarn parser ( #3433 )
2023-01-16 11:27:20 +02:00
DmitriyLewen
e6d7f15762
fix(db): check proxy settings when using insecure flag ( #3435 )
2023-01-16 10:40:27 +02:00
simar7
a1d4427c8b
feat(misconf): Fetch policies from OCI registry ( #3015 )
...
Signed-off-by: Simar <simar@linux.com >
2023-01-15 13:37:04 +02:00
DmitriyLewen
682351a131
ci: downgrade Go to 1.18 and use stable and oldstable go versions for unit tests ( #3413 )
...
* use stable and oldstable go versions for unit tests
* downgrade Go to 1.18
2023-01-15 12:03:15 +02:00
afdesk
ff0c4516db
ci: store URLs to Github Releases in RPM repository ( #3414 )
2023-01-15 11:59:18 +02:00
DmitriyLewen
ee12442b8d
feat(server): add support of skip-db-update flag for hot db update ( #3416 )
2023-01-15 10:28:50 +02:00
DmitriyLewen
2033e05b6b
chore(deps): bump github.com/moby/buildkit from v0.10.6 to v0.11.0 ( #3411 )
2023-01-12 08:45:07 +02:00
Teppei Fukuda
6bc564e887
fix(image): handle wrong empty layer detection ( #3375 )
2023-01-11 20:17:12 +02:00
DmitriyLewen
b3b8d4dd6e
test: fix integration tests for spdx and cycloneDX ( #3412 )
2023-01-11 14:02:10 +02:00
Matthieu Maitre
b88bccae6e
feat(python): Include Conda packages in SBOMs ( #3379 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-10 16:11:17 +02:00
DmitriyLewen
fbd8a13d54
feat: add support pubspec.lock files for dart ( #3344 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-10 13:34:53 +02:00
Kalyana Krishna Varanasi
0f545cfa96
fix(image): parsePlatform is failing with UNAUTHORIZED error ( #3326 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-10 13:26:57 +02:00
DmitriyLewen
76c883dc43
fix(license): change normalize for GPL-3+-WITH-BISON-EXCEPTION ( #3405 )
2023-01-10 09:24:11 +00:00
Jack Lin
a8b671bc29
feat(server): log errors on server side ( #3397 )
2023-01-10 10:21:31 +02:00
Teppei Fukuda
a5919ca363
chore(deps): bump defsec to address helm vulnerabilities ( #3399 )
2023-01-08 15:34:11 +02:00
Itay Shakury
89016da21e
docs: rewrite installation docs and general improvements ( #3368 )
...
improve installation guide, improve overview pages, rename cli section to docs
2023-01-08 15:16:03 +02:00
Itay Shakury
c3759c6d83
chore: update code owners ( #3393 )
2023-01-08 15:14:10 +02:00
Itay Shakury
044fb9761e
chore: test docs separately from code ( #3392 )
2023-01-08 11:10:31 +02:00
Teppei Fukuda
ad2e648b33
docs: use the formula maintained by Homebrew ( #3389 )
2023-01-05 16:25:57 +02:00
Max Usachev
ad25a776cc
docs: add Security Management section with SonarQube plugin
2023-01-05 14:59:47 +02:00
jerbob92
9039df4993
fix(deps): fix errors on yarn.lock files that contain local file reference ( #3384 )
2023-01-05 12:17:11 +02:00
Jack Lin
60cf4fe49f
feat(flag): early fail when the format is invalid ( #3370 )
2023-01-04 13:46:04 +02:00
dependabot[bot]
9470e3cd27
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.136 to 1.44.171 ( #3366 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-03 20:53:50 +02:00
Olivier Jacques
d274d1568a
docs(aws): fix broken links ( #3374 )
2023-01-03 17:59:28 +02:00
dependabot[bot]
2a870f8a82
chore(deps): bump actions/stale from 6 to 7 ( #3360 )
2023-01-03 15:28:29 +02:00
dependabot[bot]
5974023b7f
chore(deps): bump helm/kind-action from 1.4.0 to 1.5.0 ( #3359 )
2023-01-03 15:23:58 +02:00
dependabot[bot]
02aa8c2c50
chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.6.0 to 0.7.0 ( #2974 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
Co-authored-by: masahiro331 <m_fujimura@r.recruit.co.jp >
2023-01-03 15:15:07 +02:00
dependabot[bot]
6e6171fead
chore(deps): bump azure/setup-helm from 3.4 to 3.5 ( #3358 )
2023-01-03 15:04:29 +02:00
dependabot[bot]
066f27792f
chore(deps): bump github.com/moby/buildkit from 0.10.4 to 0.10.6 ( #3173 )
2023-01-03 14:44:40 +02:00
dependabot[bot]
8cc3284106
chore(deps): bump goreleaser/goreleaser-action from 3 to 4 ( #3357 )
2023-01-03 14:19:00 +02:00
dependabot[bot]
8d71346143
chore(deps): bump github.com/containerd/containerd from 1.6.8 to 1.6.14 ( #3367 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-03 12:01:45 +02:00
Crypt Keeper
5b944d20ac
chore(go): updates wazero to v1.0.0-pre.7 ( #3355 )
...
Signed-off-by: Adrian Cole <adrian@tetrate.io >
2023-01-03 11:08:17 +02:00
dependabot[bot]
9c645b99e2
chore(deps): bump golang.org/x/text from 0.4.0 to 0.5.0 ( #3362 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-03 08:45:14 +02:00
dependabot[bot]
e2cd782d3a
chore(deps): bump actions/cache from 3.0.11 to 3.2.2 ( #3356 )
2023-01-02 15:59:36 +02:00
Itay Shakury
4813cf5cfd
docs: improve compliance docs ( #3340 )
2022-12-30 13:55:18 +02:00
Lior Vaisman Argon
025e5099d2
feat(deps): add yarn lock dependency tree ( #3348 )
2022-12-29 19:45:18 +02:00
chenk
4d59a1ef9b
fix: compliance change id and title naming ( #3349 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-29 17:46:50 +02:00
DmitriyLewen
eaa5bcf7d2
feat: add support for mix.lock files for elixir language ( #3328 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-29 15:18:51 +02:00
chenk
a888440922
feat: add k8s cis bench ( #3315 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2022-12-28 20:38:48 +02:00
DmitriyLewen
62b369ee39
test: disable SearchLocalStoreByNameOrDigest test for non-amd64 arch ( #3322 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-28 13:02:25 +02:00
behara
c110c4e028
revert: cache merged layers ( #3334 )
...
This reverts commit 6b4ddaaef2 .
2022-12-28 10:01:01 +02:00
Masahiro331
bc759efdc3
feat(cyclonedx): add recommendation ( #3336 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-27 15:25:27 +02:00
DmitriyLewen
fe3831e0fe
feat(ubuntu): added support ubuntu ESM versions ( #1893 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-27 10:24:28 +02:00
DmitriyLewen
b0cebec324
fix: change logic to build relative paths for skip-dirs and skip-files ( #3331 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-26 17:38:31 +02:00
dependabot[bot]
a66d3fe3f0
chore(deps): bump github.com/hashicorp/golang-lru from 0.5.4 to 2.0.1 ( #3265 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: masahiro331 <m_fujimura@r.recruit.co.jp >
2022-12-25 12:39:26 +02:00
Owen Rumney
5190f9566b
feat: Adding support for Windows testing ( #3037 )
...
Signed-off-by: Owen Rumney <owen.rumney@aquasec.com >
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-22 22:54:18 +02:00
gboer
b00f3c60f6
feat: add support for Alpine 3.17 ( #3319 )
2022-12-19 13:25:29 +02:00
Teppei Fukuda
a70f885113
docs: change PodFile.lock to Podfile.lock ( #3318 )
2022-12-19 13:24:26 +02:00
saso
1ec1fe64e8
fix(sbom): support for the detection of old CycloneDX predicate type ( #3316 )
2022-12-19 11:06:36 +02:00
lsoumille
68eda79357
feat(secret): Use .trivyignore for filtering secret scanning result ( #3312 )
2022-12-18 11:58:34 +02:00
Takeshi Yoneda
b95d435a6a
chore(go): remove experimental FS API usage in Wasm ( #3299 )
...
Signed-off-by: Takeshi Yoneda <takeshi@tetrate.io >
2022-12-18 11:55:53 +02:00
DmitriyLewen
ac6b7c3354
ci: add workflow to add issues to roadmap project ( #3292 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-18 10:32:39 +02:00
gmetaxo
cfabdf9138
fix(vuln): include duplicate vulnerabilities with different package paths in the final report ( #3275 )
...
* Add test for filter with both duplicates and different package paths
* Add package path in key of uniqVulns map
* Add package path to the sorting logic
2022-12-15 19:21:54 +02:00
dependabot[bot]
56e3d8de09
chore(deps): bump github.com/spf13/viper from 1.13.0 to 1.14.0 ( #3250 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-15 16:29:58 +02:00
Masahiro331
bbccb4484a
feat(sbom): better support for third-party SBOMs ( #3262 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-15 16:20:21 +02:00
DmitriyLewen
e879b0697c
docs: add information about languages with support for dependency locations ( #3306 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2022-12-15 15:25:40 +02:00
tockn
e92266f2c8
feat(vm): add region option to vm scan to be able to scan any region's ami and ebs snapshots ( #3284 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2022-12-15 12:21:05 +02:00
dependabot[bot]
01c7fb14bc
chore(deps): bump github.com/Azure/azure-sdk-for-go from 66.0.0+incompatible to 67.1.0+incompatible ( #3251 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-13 19:46:54 +02:00
DmitriyLewen
23d0613879
fix(vuln): change severity vendor priority for ghsa-ids and vulns from govuln ( #3255 )
2022-12-13 17:29:43 +02:00
Itay Shakury
407c2407d1
docs: remove comparisons ( #3289 )
2022-12-13 11:13:56 +02:00
Dan Luhring
93c5d2dc71
feat: add support for Wolfi Linux ( #3215 )
2022-12-12 22:43:44 +02:00
DmitriyLewen
2809794964
ci: add go.mod to canary workflow ( #3288 )
2022-12-12 22:40:14 +02:00
Catminusminus
08b55c3347
feat(python): skip dev dependencies ( #3282 )
...
This commit bumps the go-dep-parser version. This revents Trivy from detecting vulnerabilities in Poetry dev-dependency, so the document is also updated.
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2022-12-12 15:04:48 +02:00
afdesk
52300e6069
chore: update ubuntu version for Github action runnners ( #3257 )
...
* chore: update ubuntu version for Github action runnners
* update the ubuntu version for docs actions
2022-12-12 11:09:46 +02:00
DmitriyLewen
a7ac6acaa2
fix(go): skip dep without Path for go-binaries ( #3254 )
2022-12-12 11:04:57 +02:00
DmitriyLewen
4436a202ff
feat(rust): add ID for cargo pgks ( #3256 )
2022-12-12 07:40:15 +02:00
dependabot[bot]
34d505ad14
chore(deps): bump github.com/samber/lo from 1.33.0 to 1.36.0 ( #3263 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-11 19:21:31 +02:00
dependabot[bot]
ea956026c8
chore(deps): bump github.com/Masterminds/sprig/v3 from 3.2.2 to 3.2.3 ( #3253 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-11 19:16:10 +02:00
DmitriyLewen
aea298b3dc
feat: add support for swift cocoapods lock files ( #2956 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-11 19:15:10 +02:00
Teppei Fukuda
c67fe17b4e
fix(sbom): use proper constants ( #3286 )
2022-12-11 15:56:48 +02:00
dependabot[bot]
f907255672
chore(deps): bump golang.org/x/term from 0.1.0 to 0.3.0 ( #3278 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-11 15:33:28 +02:00
Teppei Fukuda
8f95743502
test(vm): import relevant analyzers ( #3285 )
2022-12-11 15:02:43 +02:00
Pikaqiu
8744534c28
feat: support scan remote repository ( #3131 )
...
Co-authored-by: AMF <work@afdesk.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-11 11:57:04 +02:00
DmitriyLewen
c278d86614
docs: fix typo in fluxcd ( #3268 )
2022-12-08 10:55:14 +02:00
Ari Yonaty
fa2281f723
docs: fix broken "ecosystem" link in readme ( #3280 )
2022-12-08 10:43:23 +02:00
simar7
a3eece4fef
feat(misconf): Add compliance check support ( #3130 )
...
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-07 22:42:59 +02:00
hriprsd
7a6cf5a27c
docs: Adding Concourse resource for trivy ( #3224 )
2022-12-04 16:22:10 +02:00
dependabot[bot]
dd26bd2306
chore(deps): change golang from 1.19.2 to 1.19 ( #3249 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-04 11:03:02 +02:00
Masahiro331
cbba6d101a
fix(sbom): duplicate dependson ( #3261 )
2022-12-04 10:48:02 +02:00
dependabot[bot]
fa2e3ac2c1
chore(deps): bump alpine from 3.16.2 to 3.17.0 ( #3247 )
2022-12-04 10:24:56 +02:00
Crypt Keeper
5c434753ce
chore(go): updates wazero to 1.0.0-pre.4 ( #3242 )
...
Signed-off-by: Adrian Cole <adrian@tetrate.io >
2022-12-04 10:17:37 +02:00
DmitriyLewen
d29b0edcc7
feat(report): add dependency locations to sarif format ( #3210 )
2022-12-01 13:23:58 +02:00
Masahiro331
967e32f4a2
fix(rpm): add rocky to osVendors ( #3241 )
2022-12-01 12:44:21 +02:00
tsanva
947741660b
docs: fix a typo ( #3236 )
2022-11-30 11:56:45 +02:00
DmitriyLewen
97ce61eef0
feat(dotnet): add dependency parsing for nuget lock files ( #3222 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-11-29 16:15:46 +02:00
Max Fröhlich
17e13c4dbd
docs: add pre-commit hook to community tools ( #3203 )
2022-11-29 16:15:17 +02:00
Cyril Jouve
b1a2c4e9c8
feat(helm): pass arbitrary env vars to trivy ( #3208 )
2022-11-29 11:36:45 +02:00
Masahiro331
bd30e983e3
chore(vm): update xfs filesystem parser for change log ( #3230 )
2022-11-27 18:04:10 +02:00
Masahiro331
22d92e4ad6
feat: add virtual machine scan command ( #2910 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-11-27 11:45:00 +02:00
Itay Shakury
531eaa8f06
docs: reorganize index and readme ( #3026 )
2022-11-26 10:44:01 +02:00
afdesk
8569d43a7a
fix: slowSizeThreshold should be less than defaultSizeThreshold ( #3225 )
2022-11-24 15:09:06 +02:00
Tamir Kiviti
604a73d325
feat: Export functions for trivy plugin ( #3204 )
2022-11-22 09:40:09 +02:00
Teppei Fukuda
7594b1f041
feat(image): add support wildcard for platform os ( #3196 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2022-11-21 10:09:32 +02:00
chenk
fd5cafb26d
fix: load compliance report from file system ( #3161 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2022-11-20 15:15:03 +02:00
DmitriyLewen
6ab9380b29
fix(suse): use package name to get advisories ( #3199 )
2022-11-20 14:46:33 +02:00
Irum Malik
4a5d64355c
docs(image): space issues during image scan ( #3190 )
2022-11-20 14:41:59 +02:00
Peter Engelbert
2206e008ea
feat(containerd): scan image by digest ( #3075 )
2022-11-20 14:40:24 +02:00
AndrewCharlesHay
861bc03e2d
fix(vuln): add package name to title ( #3183 )
2022-11-20 14:00:18 +02:00
chenk
f115895d30
fix: present control status instead of compliance percentage in compliance report ( #3181 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2022-11-20 13:46:16 +02:00
afdesk
cc8cef1936
perf(license): remove go-enry/go-license-detector. ( #3187 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-11-17 18:01:57 +02:00
Naimuddin Shaik
a0033f6b61
fix: workdir command as empty layer ( #3087 )
2022-11-17 09:43:01 +02:00
Itay Shakury
cb5744dcaf
docs: reorganize ecosystem section ( #3025 )
2022-11-16 10:06:13 +02:00
DmitriyLewen
1ddd6d30b8
feat(dotnet): add support dependency location for dotnet-core files ( #3095 )
2022-11-16 09:46:28 +02:00
dependabot[bot]
30c8d75674
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.114 to 1.44.136 ( #3174 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-11-15 15:34:31 +02:00
dependabot[bot]
8e7b44f720
chore(deps): bump github.com/testcontainers/testcontainers-go from 0.13.0 to 0.15.0 ( #3109 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2022-11-15 12:40:21 +02:00
DmitriyLewen
dfff371f84
feat(dotnet): add support dependency location for nuget lock files ( #3032 )
2022-11-15 12:38:31 +02:00
Teppei Fukuda
eb571fdc40
chore: update code owners for misconfigurations ( #3176 )
2022-11-14 23:06:36 +02:00
Teppei Fukuda
757178341d
feat: add slow mode ( #3084 )
...
Co-authored-by: AMF <work@afdesk.com >
2022-11-14 15:49:02 +02:00
Chris Adams
01df475852
docs: fix typo in enable-builin-rules mentions ( #3118 )
2022-11-14 14:19:21 +02:00
Tal Kapon
6b3be150f1
feat: Add maintainer field to OS packages ( #3149 )
2022-11-14 14:16:12 +02:00
Nozomi Morimoto
9ebdc51d3a
docs: fix some typo ( #3171 )
2022-11-14 14:15:31 +02:00
dependabot[bot]
42e81ad0a6
chore(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.17.8 to 1.18.0 ( #3175 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-11-13 22:16:50 +02:00
dependabot[bot]
55ec898953
chore(deps): bump github.com/stretchr/testify from 1.8.0 to 1.8.1 ( #3112 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-11-13 18:27:38 +02:00
Emily Berk
0644ceba1b
docs: fix links on Built-in Policies page ( #3124 )
2022-11-13 14:51:09 +02:00
dependabot[bot]
50af7a2f46
chore(deps): bump github.com/go-openapi/runtime from 0.24.1 to 0.24.2 ( #3117 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-11-13 14:46:35 +02:00
dependabot[bot]
c455d14209
chore(deps): bump github.com/samber/lo from 1.28.2 to 1.33.0 ( #3116 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-11-13 14:46:14 +02:00
Serge Dubrovin
8fb9d31617
fix: Perform filepath.Clean first and then filepath.ToSlash for skipFile/skipDirs settings ( #3144 )
2022-11-13 14:22:00 +02:00
Teppei Fukuda
8562b8cf33
chore: use newline for semantic pr ( #3172 )
2022-11-13 13:35:50 +02:00
dependabot[bot]
aff9a3e0d9
chore(deps): bump azure/setup-helm from 3.3 to 3.4 ( #3107 )
2022-11-13 13:04:29 +02:00
dependabot[bot]
001671ed79
chore(deps): bump sigstore/cosign-installer from 2.7.0 to 2.8.1 ( #3106 )
2022-11-13 13:03:35 +02:00
dependabot[bot]
4e7ab4842c
chore(deps): bump amannn/action-semantic-pull-request from 4 to 5 ( #3105 )
2022-11-13 13:03:07 +02:00
dependabot[bot]
a6091a7e43
chore(deps): bump golangci/golangci-lint-action from 3.2.0 to 3.3.0 ( #3104 )
2022-11-13 13:00:37 +02:00
DmitriyLewen
6da148cca8
fix(spdx): rename describes field in spdx ( #3102 )
2022-11-13 12:59:37 +02:00
didiermichel
df9cf88163
chore: handle GOPATH with several paths in make file ( #3092 )
2022-11-13 12:50:14 +02:00
Jonathan Ballet
32fe108c0a
docs(flag): add "rego" configuration file options ( #3165 )
2022-11-13 10:04:20 +02:00
Crypt Keeper
8fcca9c8cf
chore(go): updates wazero to 1.0.0-pre.3 ( #3090 )
...
Signed-off-by: Adrian Cole <adrian@tetrate.io >
2022-11-13 09:53:01 +02:00
dependabot[bot]
02f77bc120
chore(deps): bump actions/cache from 3.0.9 to 3.0.11 ( #3108 )
2022-11-13 09:50:21 +02:00
alfajorcito
aa3ff09ad9
docs(license): fix typo inside quick start ( #3134 )
2022-11-13 09:44:26 +02:00
Itay Shakury
f26b45294d
chore: update codeowners for docs ( #3135 )
2022-11-13 09:42:58 +02:00
chenk
3b6d7d8cb1
fix(cli): exclude --compliance flag from non supported sub-commands ( #3158 )
2022-11-13 09:39:25 +02:00
DmitriyLewen
e9a2549955
fix: remove --security-checks none from image help ( #3156 )
2022-11-13 09:38:25 +02:00
chenk
3aa19122f4
fix: compliance flag description ( #3160 )
2022-11-13 09:30:21 +02:00
BeHe
fc820570b7
docs(k8s): fix a typo ( #3163 )
2022-11-13 09:29:29 +02:00
dependabot[bot]
3a1f05e331
chore(deps): bump golang from 1.19.1 to 1.19.2 ( #3103 )
2022-11-09 20:18:37 +01:00
Teppei Fukuda
7912f585a3
feat(vuln): support dependency graph for RHEL/CentOS ( #3094 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2022-10-31 11:07:41 +02:00
Teppei Fukuda
9468056c0f
feat(vuln): support dependency graph for dpkg and apk ( #3093 )
...
Co-authored-by: Masahiro331 <m_fujimura@r.recruit.co.jp >
2022-10-31 08:54:42 +02:00
Teppei Fukuda
7cc83cc2f6
perf(license): enable license classifier only with "--license-full" ( #3086 )
2022-10-28 20:16:16 +03:00
AndrewCharlesHay
5b975de234
feat(report): add secret scanning to ASFF template ( #2860 )
...
Co-authored-by: AMF <work@afdesk.com >
2022-10-28 08:27:10 +03:00
Peter Engelbert
b6cef12534
feat: Allow override of containerd namespace ( #3060 )
...
Signed-off-by: Peter Engelbert <pmengelbert@gmail.com >
2022-10-27 16:43:55 +03:00
behara
07651480fa
fix(vuln): In alpine use Name as SrcName ( #3079 )
2022-10-27 12:59:28 +03:00
DmitriyLewen
9e649b87b5
fix(secret): Alibaba AccessKey ID ( #3083 )
2022-10-27 12:58:14 +03:00
Teppei Fukuda
af89249dea
refactor(k8s): custom reports ( #3076 )
2022-10-26 00:02:33 +03:00
Aibek
f4e970f374
fix(misconf): Bump in-toto-golang with correct CycloneDX predicate ( #3068 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-10-25 23:41:27 +03:00
Shubham Palriwala
8ae4627941
feat(image): add support for passing architecture and OS ( #3012 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-10-25 22:03:50 +03:00
DmitriyLewen
0501e70375
test: disable containerd integration tests for non-amd64 arch ( #3073 )
2022-10-25 21:05:54 +03:00
bgoareguer
a377c8d04f
feat(server): Add support for client/server mode to rootfs command ( #3021 )
2022-10-25 21:04:29 +03:00
Teppei Fukuda
02a73f0138
feat(vuln): support non-packaged binaries ( #3019 )
2022-10-25 20:02:53 +03:00
chenk
18581f345b
feat: compliance reports ( #2951 )
2022-10-25 19:42:01 +03:00
saso
63b8e4d6a0
fix(flag): disable flag parsing for each plugin command ( #3074 )
2022-10-25 19:02:42 +03:00
DmitriyLewen
cbedd712db
feat(nodejs): add support dependency location for yarn.lock files ( #3016 )
2022-10-25 11:19:21 +03:00
Liam Galvin
b22e37e0c6
chore: Switch github.com/liamg dependencies to github.com/aquasecurity ( #3069 )
2022-10-25 11:17:47 +03:00
Jose Donizetti
9b0e9794cb
feat: add k8s components ( #2589 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-10-24 14:51:02 +03:00
behara
5e25182c98
fix(secret): update the regex for secrets scanning ( #2964 )
...
Co-authored-by: jyothikumar <behara.jyothi-kumar@aquasec.com >
2022-10-24 14:42:54 +03:00
dependabot[bot]
9947e5111c
chore(deps): bump github.com/samber/lo from 1.27.1 to 1.28.2 ( #2979 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2022-10-24 11:30:39 +03:00
Jose Donizetti
d2a15a7377
fix: bump trivy-kubernetes ( #3064 )
2022-10-23 21:07:41 +03:00
Shahar Naveh
f2efc9c554
docs: fix missing 'image' subcommand ( #3051 )
2022-10-21 12:44:12 +03:00
tspearconquest
34653c711b
chore: Patch golang x/text vulnerability ( #3046 )
...
Signed-off-by: Thomas Spear <tspear@conquestcyber.com >
2022-10-21 12:43:50 +03:00
Itay Shakury
e252ea83e0
chore: add licensed project logo ( #3058 )
2022-10-21 07:22:00 +03:00
MaineK00n
439d216634
feat(ubuntu): set Ubuntu 22.10 EOL ( #3054 )
2022-10-20 21:52:44 +03:00
Matias Insaurralde
9f5113a920
refactor(analyzer): use strings.TrimSuffix instead of strings.HasSuffix ( #3028 )
2022-10-20 14:45:33 +03:00
Craig Andrews
c1e24d5344
feat(report): Use understandable value for shortDescription in SARIF reports ( #3009 )
...
Signed-off-by: Craig Andrews <candrews@integralblue.com >
Co-authored-by: AMF <work@afdesk.com >
2022-10-20 12:54:59 +03:00
Sen
212af07e27
docs(misconf): fix typo ( #3043 )
2022-10-20 08:51:37 +03:00
Owen Rumney
68f374ac9a
feat: add support for scanning azure ARM ( #3011 )
...
Signed-off-by: Owen Rumney <owen.rumney@aquasec.com >
2022-10-13 20:24:14 +03:00
Craig Andrews
d35c668f5c
feat(report): add location.message to SARIF output ( #3002 ) ( #3003 )
...
Signed-off-by: Craig Andrews <candrews@integralblue.com >
Co-authored-by: AMF <work@afdesk.com >
2022-10-12 16:07:58 +03:00
dependabot[bot]
2150ffc701
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.95 to 1.44.109 ( #2980 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2022-10-12 15:47:31 +03:00
DmitriyLewen
ca434f7f26
feat(nodejs): add dependency line numbers for npm lock files ( #2932 )
2022-10-12 15:22:34 +03:00
Hirotaka Tagawa / wafuwafu13
a8ff5f06b5
test(fs): add --skip-files, --skip-dirs ( #2984 )
2022-10-12 15:20:56 +03:00
6543
561b2e7566
docs: add Woodpecker CI integrations example ( #2823 )
...
Co-authored-by: Sebastian Crane <seabass-labrax@gmx.com >
2022-10-12 15:01:59 +03:00
dependabot[bot]
4a3583da95
chore(deps): bump github.com/sigstore/rekor from 0.12.0 to 0.12.2 ( #2981 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2022-10-12 13:45:56 +03:00
dependabot[bot]
4be9eebf07
chore(deps): bump github.com/liamg/memoryfs from 1.4.2 to 1.4.3 ( #2976 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2022-10-12 13:44:35 +03:00
dependabot[bot]
a260d35dc1
chore(deps): bump github.com/spf13/viper from 1.12.0 to 1.13.0 ( #2975 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2022-10-12 13:37:20 +03:00
dependabot[bot]
558189f763
chore(deps): bump github.com/caarlos0/env/v6 from 6.10.0 to 6.10.1 ( #2982 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2022-10-12 13:36:30 +03:00
DmitriyLewen
c2eb6ee301
fix(sbom): ref generation if serialNumber is empty when input is cyclonedx file ( #3000 )
2022-10-11 21:25:46 +03:00
DmitriyLewen
68f79526bb
fix(java): don't stop parsing jar file when wrong inner jar is found ( #2989 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-10-11 12:45:44 +03:00
DmitriyLewen
be78da6c40
fix(sbom): use nuget purl type for dotnet-core ( #2990 )
...
* use nuget prefix for dotnet-core
* refactor
2022-10-11 12:23:43 +03:00
saso
92b5a1931e
perf: retrieve rekor entries in bulk ( #2987 )
2022-10-09 10:53:00 +03:00
Liam Galvin
babd7e7526
feat(aws): Custom rego policies for AWS scanning ( #2994 )
2022-10-06 12:51:45 +03:00
AndrewCharlesHay
8ad9b8a939
docs: jq cli formatting ( #2881 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-10-02 10:11:03 +03:00
Kyriakos Georgiou
a78684c340
docs(repo): troubleshooting $TMPDIR customization ( #2985 )
2022-10-02 10:05:09 +03:00
dependabot[bot]
7309ed0a5b
chore(deps): bump actions/cache from 3.0.8 to 3.0.9 ( #2969 )
2022-10-02 10:03:49 +03:00
dependabot[bot]
9515a5ce8b
chore(deps): bump actions/stale from 5 to 6 ( #2970 )
2022-10-02 10:03:26 +03:00
dependabot[bot]
955aff66df
chore(deps): bump sigstore/cosign-installer from 2.5.1 to 2.7.0 ( #2971 )
2022-10-02 10:02:42 +03:00
dependabot[bot]
db56d238fd
chore(deps): bump helm/chart-testing-action from 2.3.0 to 2.3.1 ( #2972 )
2022-10-02 10:02:22 +03:00
dependabot[bot]
05a723246e
chore(deps): bump helm/kind-action from 1.3.0 to 1.4.0 ( #2973 )
2022-10-02 10:01:49 +03:00
afdesk
2c39d4729a
chore: run go fmt ( #2897 )
2022-10-02 09:33:21 +03:00
Crypt Keeper
16a7dc10e0
chore(go): updates wazero to 1.0.0-pre.2 ( #2955 )
...
Signed-off-by: Adrian Cole <adrian@tetrate.io >
2022-10-02 09:29:15 +03:00
chavacava
ce4ba7c99c
fix(aws): Less function for slice sorting always returns false #2967
...
Signed-off-by: Salvador Cavadini <salvadorcavadini+github@gmail.com >
2022-10-02 09:28:27 +03:00
DmitriyLewen
4ffe74643e
fix(java): fix unmarshal pom exclusions ( #2936 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-09-28 19:44:53 +03:00
DmitriyLewen
8b1cee845b
fix(java): use fields of dependency from dependencyManagement from upper pom.xml to parse deps ( #2943 )
2022-09-28 15:32:01 +03:00
chenk
f5cbbb3fde
chore: expat lib and go binary deps vulns ( #2940 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2022-09-28 12:14:29 +03:00
Crypt Keeper
6882bdf561
wasm: Removes accidentally exported memory ( #2950 )
...
Signed-off-by: Adrian Cole <adrian@tetrate.io >
2022-09-28 11:12:46 +03:00
DmitriyLewen
6ea9a61cf3
fix(sbom): fix package name separation for gradle ( #2906 )
2022-09-28 11:11:23 +03:00
DmitriyLewen
3ee4c96f13
docs(readme.md): fix broken integrations link ( #2931 )
2022-09-28 11:03:20 +03:00
Moniseeta
5745961194
fix(image): handle images with single layer in rescan mergedLayers cache ( #2927 )
...
For images with single layer, the layer key was directly being used as merged cache key.
This was posing an issue of data override and any other image having the same layer could get incorrect data.
So, fixed:
1. Even for 1 layer - merged layer key hash will be calculated
2. We will not go with assumption that merged data will have only 1 pkgInfo
3. We are setting a SchemaVersion in blob being generated in ToBlobInfo
2022-09-22 14:46:28 +03:00
DmitriyLewen
e01253d54d
fix(cli): split env values with ',' for slice flags ( #2926 )
2022-09-22 10:11:37 +03:00
Juan Antonio Osorio
0c1a42d4f3
fix(cli): config/helm: also take into account files with .yml ( #2928 )
...
YAML files can also have the `.yml` file extension. So the helm config should take that into account.
Signed-off-by: Juan Antonio Osorio <juan.osoriorobles@eu.equinix.com >
2022-09-21 17:08:13 +01:00
DmitriyLewen
237b8dcd06
fix(flag): add file-patterns flag for config subcommand ( #2925 )
2022-09-21 10:02:58 +03:00
dependabot[bot]
047a0b3d88
chore(deps): bump github.com/open-policy-agent/opa from 0.43.0 to 0.43.1 ( #2902 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2022-09-19 14:55:16 +03:00
Teppei Fukuda
585985edb3
docs: add Rekor SBOM attestation scanning ( #2893 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2022-09-16 15:43:01 +03:00
Teppei Fukuda
d30fa00adc
chore: narrow the owner scope ( #2894 )
2022-09-16 15:42:31 +03:00
afdesk
38c1513af6
fix: remove a patch number from the recommendation link ( #2891 )
2022-09-16 12:23:58 +03:00
saso
ba29ce648c
fix: enable parsing of UUID-only rekor entry ID ( #2887 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-09-16 11:16:41 +03:00
Teppei Fukuda
018eda618b
docs(sbom): add SPDX scanning ( #2885 )
2022-09-16 10:20:40 +03:00
Anais Urlichs
20f1e5991a
docs: restructure docs and add tutorials ( #2883 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-09-15 21:27:58 +03:00
saso
192fd78ca2
feat(sbom): scan sbom attestation in the rekor record ( #2699 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-09-15 20:16:39 +03:00
chenk
597836c3a2
feat(k8s): support outdated-api ( #2877 )
2022-09-15 13:02:16 +03:00
dependabot[bot]
6c7bd67c04
chore(deps): bump github.com/moby/buildkit from 0.10.3 to 0.10.4 ( #2815 )
2022-09-15 11:40:54 +03:00
François Poirotte
41270434fe
fix(c): support revisions in Conan parser ( #2878 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-09-15 11:35:44 +03:00
chenk
b677d7e2e8
feat: dynamic links support for scan results ( #2838 )
2022-09-15 10:42:33 +03:00
dependabot[bot]
8e03bbb422
chore(deps): bump go.uber.org/zap from 1.22.0 to 1.23.0 ( #2818 )
2022-09-15 10:16:47 +03:00
George Rodrigues
27005c7d6a
docs: update archlinux commands ( #2876 )
2022-09-15 10:14:53 +03:00
DmitriyLewen
b6e394dc80
feat(secret): add line from dockerfile where secret was added to secret result ( #2780 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-09-15 10:13:20 +03:00
Masahiro331
9f6680a1fa
feat(sbom): Add unmarshal for spdx ( #2868 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-09-15 08:39:59 +03:00
dependabot[bot]
db0aaf18e6
chore(deps): bump github.com/aws/aws-sdk-go-v2/config ( #2827 )
2022-09-14 17:28:14 +03:00
AndrewCharlesHay
bb3220c3de
fix: revert asff arn and add documentation ( #2852 )
2022-09-14 17:27:46 +03:00
AndrewCharlesHay
c51f2b82e4
docs: batch-import-findings limit ( #2851 )
2022-09-14 17:26:32 +03:00
dependabot[bot]
552732b5d7
chore(deps): bump golang from 1.19.0 to 1.19.1 ( #2872 )
2022-09-14 17:23:51 +03:00
Masahiro331
3165c376e2
feat(sbom): Add marshal for spdx ( #2867 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-09-14 13:36:10 +03:00
Teppei Fukuda
dac2b4a281
build: checkout before setting up Go ( #2873 )
2022-09-14 13:27:27 +03:00
Teppei Fukuda
39f83afefe
chore: bump Go to 1.19 ( #2861 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2022-09-14 11:41:55 +03:00
Carol Valencia
0ce95830c8
docs: azure doc and trivy ( #2869 )
...
Co-authored-by: carolina valencia <krol3@users.noreply.github.com >
2022-09-14 09:20:57 +03:00
Owen Rumney
2f37961661
fix: Scan tarr'd dependencies ( #2857 )
...
Signed-off-by: Owen Rumney <owen.rumney@aquasec.com >
2022-09-12 14:55:38 +03:00
Carol Valencia
db14ef3cb5
chore(helm): helm test with ingress ( #2630 )
...
Co-authored-by: carolina valencia <krol3@users.noreply.github.com >
2022-09-12 12:13:08 +03:00
DmitriyLewen
acb65d565a
feat(report): add secrets to sarif format ( #2820 )
...
Co-authored-by: AMF <work@afdesk.com >
2022-09-12 12:12:13 +03:00
dependabot[bot]
a18cd7c00a
chore(deps): bump azure/setup-helm from 1.1 to 3.3 ( #2807 )
2022-09-12 12:11:02 +03:00
Teppei Fukuda
2de903ca35
refactor: add a new interface for initializing analyzers ( #2835 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2022-09-12 11:46:53 +03:00
dependabot[bot]
63c3b8ed19
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.77 to 1.44.92 ( #2840 )
2022-09-08 09:21:40 +03:00
AndrewCharlesHay
6717665ab0
fix: update ProductArn with account id ( #2782 )
2022-09-08 09:21:05 +03:00
Helge Eichelberg
41a8496716
feat(helm): make cache TTL configurable ( #2798 )
...
Signed-off-by: elchenberg <elchenberg@users.noreply.github.com >
2022-09-08 09:12:18 +03:00
Juan Antonio Osorio
0f1f2c1b29
build(): Sign releaser artifacts, not only container manifests ( #2789 )
2022-09-07 16:56:10 +03:00
Carol Valencia
b389a6f4fc
chore: improve doc about azure devops ( #2795 )
...
Co-authored-by: carolina valencia <krol3@users.noreply.github.com >
2022-09-07 16:52:53 +03:00
dependabot[bot]
9ef9fce589
chore(deps): bump sigstore/cosign-installer from 2.5.0 to 2.5.1 ( #2804 )
2022-09-07 16:48:15 +03:00
dependabot[bot]
7b3225d0d8
chore(deps): bump github.com/aws/aws-sdk-go-v2 from 1.16.11 to 1.16.14 ( #2828 )
2022-09-07 16:47:38 +03:00
dependabot[bot]
37733edc4b
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/sts ( #2825 )
2022-09-07 16:46:01 +03:00
Itay Shakury
44d7e8dde1
docs: don't push patch versions ( #2824 )
2022-09-07 16:40:28 +03:00
DmitriyLewen
4839075c28
feat: add support for conan.lock file ( #2779 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-09-06 21:59:13 +03:00
Teppei Fukuda
6b4ddaaef2
feat: cache merged layers
...
igned-off-by: knqyf263 <knqyf263@gmail.com >
2022-09-06 11:04:00 +03:00
dependabot[bot]
a18f398ac0
chore(deps): bump helm/chart-testing-action from 2.2.1 to 2.3.0 ( #2805 )
2022-09-04 12:32:45 +03:00
dependabot[bot]
4dcce14051
chore(deps): bump actions/cache from 3.0.5 to 3.0.8 ( #2806 )
2022-09-04 12:32:04 +03:00
dependabot[bot]
db4544711a
chore(deps): bump github.com/caarlos0/env/v6 from 6.9.3 to 6.10.0 ( #2811 )
2022-09-04 12:15:53 +03:00
dependabot[bot]
a246d0f280
chore(deps): bump github.com/aquasecurity/table from 1.7.2 to 1.8.0 ( #2810 )
2022-09-04 12:11:31 +03:00
dependabot[bot]
1800017a9a
chore(deps): bump github.com/samber/lo from 1.27.0 to 1.27.1 ( #2808 )
2022-09-04 12:08:54 +03:00
dependabot[bot]
218e41a435
chore(deps): bump github.com/alicebob/miniredis/v2 from 2.22.0 to 2.23.0 ( #2814 )
2022-09-04 12:08:13 +03:00
DmitriyLewen
a000adeed0
feat: add support for gradle.lockfile ( #2759 )
2022-09-01 11:27:36 +03:00
Crypt Keeper
43113bc01f
chore(mod): updates wazero to 1.0.0-pre.1 #2791
...
Signed-off-by: Adrian Cole <adrian@tetrate.io >
2022-09-01 11:09:48 +03:00
jerbob92
5f0bf1445a
feat: move file patterns to a global level to be able to use it on any analyzer ( #2539 )
2022-09-01 11:01:57 +03:00
Alex Samorukov
2580ea1583
Fix url validaton failures ( #2783 )
...
While analyzing failure of the report schema validation i found URL looks like that: `https://ubuntu.com/security/notices/USN-5051-4 (regression only in trusty/esm)`. This causing gitlab to mark report as invalid. Patch provided just using first word of the url word.
2022-08-30 15:57:40 +03:00
DmitriyLewen
2473b2c881
fix(image): add logic to detect empty layers ( #2790 )
...
* add logic to detect empty layers
* add test for createdBy from buildkit
2022-08-30 15:56:14 +03:00
afdesk
9d018d44b9
feat(rust): add dependency graph from Rust binaries ( #2771 )
2022-08-30 15:46:38 +03:00
Teppei Fukuda
db67f16ac6
fix: handle empty OS family ( #2768 )
2022-08-29 08:53:13 +03:00
Jose Donizetti
77616bebae
fix: fix k8s summary report ( #2777 )
...
Signed-off-by: Jose Donizetti <jdbjunior@gmail.com >
2022-08-25 10:43:39 +03:00
DmitriyLewen
fcccfced23
fix: don't skip packages that don't contain vulns, when using --list-all-pkgs flag ( #2767 )
2022-08-25 10:40:03 +03:00
Jose Donizetti
8bc215ccf6
chore: bump trivy-kubernetes ( #2770 )
...
Signed-off-by: Jose Donizetti <jdbjunior@gmail.com >
2022-08-25 09:37:47 +03:00
Ankush K
d8d8e62793
fix(secret): Consider secrets in rpc calls ( #2753 )
2022-08-25 09:36:51 +03:00
DmitriyLewen
b0e89d4c57
fix(java): check depManagement from upper pom's ( #2747 )
2022-08-24 11:22:22 +03:00
afdesk
da6f1b6f25
fix(php): skip composer.lock inside vendor folder ( #2718 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2022-08-23 13:17:09 +03:00
Jose Donizetti
2f2952c658
fix: fix k8s rbac filter ( #2765 )
2022-08-23 11:56:06 +03:00
afdesk
8bc56bf2fc
feat(misconf): skipping misconfigurations by AVD ID ( #2743 )
2022-08-22 11:06:04 +03:00
Alexander Lauster
9c1ce5afe8
chore(deps): Upgrade Alpine to 3.16.2 to fix zlib issue ( #2741 )
2022-08-18 17:05:39 +03:00
Herby Gillot
3cd10b2358
docs: add MacPorts install instructions ( #2727 )
2022-08-17 13:41:55 +03:00
will Farrell
f369bd3e3d
docs: typo ( #2730 )
2022-08-17 10:58:44 +01:00
Liam Galvin
fefe7c4a7b
fix: Correctly handle recoverable AWS scanning errors ( #2726 )
2022-08-16 18:00:44 +03:00
Liam Galvin
9c92e3d185
docs: Remove reference to SecurityAudit policy for AWS scanning ( #2721 )
2022-08-16 16:31:49 +03:00
Liam Galvin
d343d13ac6
fix: upgrade defsec to v0.71.7 for elb scan panic ( #2720 )
2022-08-16 15:00:18 +03:00
DmitriyLewen
917f388852
fix(flag): add error when there are no supported security checks ( #2713 )
2022-08-16 09:57:46 +03:00
Teppei Fukuda
aef02aa174
fix(vuln): continue scanning when no vuln found in the first application ( #2712 )
2022-08-16 08:41:01 +03:00
Teppei Fukuda
ed1fa89117
revert: add new classes for vulnerabilities ( #2701 )
2022-08-15 21:40:29 +03:00
DmitriyLewen
a5d4f7fbd9
feat(secret): detect secrets removed or overwritten in upper layer ( #2611 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-08-15 20:40:54 +03:00
Moulick Aggarwal
ddffb1b451
fix(cli): secret scanning perf link fix ( #2607 )
2022-08-15 16:15:22 +03:00
dependabot[bot]
bc85441f7d
chore(deps): bump github.com/spf13/viper from 1.8.1 to 1.12.0 ( #2650 )
2022-08-15 12:33:41 +03:00
Liam Galvin
b259b25ce4
feat: Add AWS Cloud scanning ( #2493 )
...
* feat: Added AWS Cloud scanning
Co-authored-by: Owen Rumney <owen.rumney@aquasec.com >
2022-08-11 14:59:32 +01:00
saso
f8edda8479
docs: specify the type when verifying an attestation ( #2697 )
2022-08-11 13:17:44 +03:00
saso
687941390e
docs(sbom): improve SBOM docs by adding a description for scanning SBOM attestation ( #2690 )
2022-08-10 15:47:40 +03:00
Ankush K
babfb17465
fix(rpc): scanResponse rpc conversion for custom resources ( #2692 )
2022-08-10 13:45:32 +03:00
Tom Fay
517d2e0109
feat(rust): Add support for cargo-auditable ( #2675 )
2022-08-10 13:43:23 +03:00
Owen Rumney
01123854b4
feat: Support passing value overrides for configuration checks ( #2679 )
2022-08-08 18:22:58 +03:00
saso
317a026616
feat(sbom): add support for scanning a sbom attestation ( #2652 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-08-08 16:27:05 +03:00
DmitriyLewen
390c256c38
chore(image): skip symlinks and hardlinks from tar scan ( #2634 )
2022-08-08 15:57:08 +03:00
Matteo Vitali
63c33bfa43
fix(report): Update junit.tpl ( #2677 )
...
Add explicit name="trivy" in the testsuite element
2022-08-08 15:47:18 +03:00
Masahiro331
de365c8e92
fix(cyclonedx): add nil check to metadata.component ( #2673 )
2022-08-08 15:15:38 +03:00
Lior Vaisman Argon
50db7da947
docs(secret): fix missing and broken links ( #2674 )
2022-08-08 15:14:55 +03:00
Teppei Fukuda
e848e6d009
refactor(cyclonedx): implement json.Unmarshaler ( #2662 )
...
* refactor(cyclonedx): implement json.Unmarshaler
* fix: use pointer
2022-08-04 14:15:33 +03:00
dependabot[bot]
df0b5e40db
chore(deps): bump github.com/aquasecurity/table from 1.6.0 to 1.7.2 ( #2643 )
...
Bumps [github.com/aquasecurity/table](https://github.com/aquasecurity/table ) from 1.6.0 to 1.7.2.
- [Release notes](https://github.com/aquasecurity/table/releases )
- [Commits](https://github.com/aquasecurity/table/compare/v1.6.0...v1.7.2 )
---
updated-dependencies:
- dependency-name: github.com/aquasecurity/table
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2022-08-04 11:44:55 +03:00
dependabot[bot]
006b8a5c29
chore(deps): bump github.com/Azure/go-autorest/autorest ( #2642 )
2022-08-04 11:43:18 +03:00
Magesh Dhasayyan
8d10de8b4f
feat(kubernetes): add option to specify kubeconfig file path ( #2576 )
2022-08-04 10:18:18 +03:00
Axit Patel
169c55c688
docs: follow Debian's "instructions to connect to a third-party repository" ( #2511 )
2022-08-04 10:11:38 +03:00
dependabot[bot]
9b21831440
chore(deps): bump github.com/google/licenseclassifier/v2 ( #2644 )
2022-08-03 15:04:13 +03:00
dependabot[bot]
94db37e541
chore(deps): bump github.com/samber/lo from 1.24.0 to 1.27.0 ( #2645 )
2022-08-03 14:58:40 +03:00
dependabot[bot]
d9838053df
chore(deps): bump github.com/Azure/go-autorest/autorest/adal ( #2647 )
2022-08-03 14:43:51 +03:00
dependabot[bot]
d8a9572930
chore(deps): bump github.com/cheggaaa/pb/v3 from 3.0.8 to 3.1.0 ( #2646 )
2022-08-03 10:46:37 +03:00
dependabot[bot]
3ab3050992
chore(deps): bump sigstore/cosign-installer from 2.4.1 to 2.5.0 ( #2641 )
2022-08-03 10:46:00 +03:00
dependabot[bot]
75984f347b
chore(deps): bump actions/cache from 3.0.4 to 3.0.5 ( #2640 )
2022-08-03 10:44:59 +03:00
dependabot[bot]
525c2530d5
chore(deps): bump alpine from 3.16.0 to 3.16.1 ( #2639 )
2022-08-03 10:44:27 +03:00
dependabot[bot]
5e327e41a6
chore(deps): bump golang from 1.18.3 to 1.18.4 ( #2638 )
2022-08-03 10:44:05 +03:00
dependabot[bot]
469d771a59
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.48 to 1.44.66 ( #2648 )
2022-08-03 10:43:40 +03:00
dependabot[bot]
6bc8c87bc1
chore(deps): bump github.com/open-policy-agent/opa from 0.42.0 to 0.43.0 ( #2649 )
2022-08-03 10:43:17 +03:00
dependabot[bot]
6ab832d099
chore(deps): bump google.golang.org/protobuf from 1.28.0 to 1.28.1 ( #2651 )
2022-08-03 10:40:57 +03:00
MaineK00n
3a10497a6f
feat(alma): set AlmaLinux 9 EOL ( #2653 )
2022-08-03 10:40:07 +03:00
Liam Galvin
55825d760b
fix(misconf): Allow quotes in Dockerfile WORKDIR when detecting relative dirs ( #2636 )
2022-08-01 15:38:04 +03:00
DmitriyLewen
6bb0e4b036
test(misconf): add tests for misconf handler for dockerfiles ( #2621 )
2022-08-01 14:56:53 +03:00
DmitriyLewen
44d53bed48
feat(oracle): set Oracle Linux 9 EOL ( #2635 )
2022-08-01 10:36:30 +03:00
Teppei Fukuda
f396c677a2
BREAKING: add new classes for vulnerabilities ( #2541 )
2022-07-31 10:47:08 +03:00
DmitriyLewen
3cd88abec5
fix(secret): add newline escaping for asymmetric private key ( #2532 )
2022-07-31 10:18:16 +03:00
Ben Bodenmiller
ea91fb91b0
docs: improve formatting ( #2572 )
2022-07-31 10:17:42 +03:00
cebidhem
d0ca610a96
feat(helm): allows users to define an existing secret for tokens ( #2587 )
...
Signed-off-by: cebidhem <cebidhem@pm.me >
2022-07-31 09:56:14 +03:00
DmitriyLewen
d0ba59a44d
docs(mariner): use tdnf in fs usage example ( #2616 )
2022-07-31 09:50:27 +03:00
saso
d7742b6c17
docs: remove unnecessary double quotation marks ( #2609 )
2022-07-31 09:45:00 +03:00
Liam Galvin
27027cf40d
fix: Fix --file-patterns flag ( #2625 )
2022-07-29 21:54:57 +03:00
saso
c2a7ad5c01
feat(report): add support for Cosign vulnerability attestation ( #2567 )
2022-07-27 17:39:35 +03:00
DmitriyLewen
dfb86f41f8
docs(mariner): use v2.0 in examples ( #2602 )
2022-07-27 14:42:09 +03:00
Nate
946ce1672d
feat(report): add secrets template for codequality report ( #2461 )
2022-07-27 10:55:32 +03:00
Teppei Fukuda
f9c17bd2d8
fix: remove the first arg when running as a plugin ( #2595 )
2022-07-26 21:54:43 +03:00
Jose Donizetti
cccfade374
fix: k8s controlplaner scanning ( #2593 )
...
Signed-off-by: Jose Donizetti <jdbjunior@gmail.com >
2022-07-26 16:35:34 +03:00
thiago-gitlab
5a65548662
fix(vuln): GitLab report template ( #2578 )
...
* fix(vuln): GitLab report template
- Upgrade to schema 14.0.6 (https://gitlab.com/gitlab-org/security-products/security-report-schemas/-/blob/v14.0.6/dist/container-scanning-report-format.json ).
- Drop unsupported `confidence` property. Currently optional and will be removed by GitLab in schema 15-0-0.
* docs(vuln): remove note about broken GitLab integration
2022-07-26 15:51:20 +03:00
afdesk
fa8a8ba7dc
fix(server): use a new db worker for hot updates ( #2581 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-07-25 17:26:08 +03:00
DmitriyLewen
769ed554b0
docs: add trivy with download-db-only flag to Air-Gapped Environment ( #2583 )
2022-07-25 16:50:26 +03:00
DmitriyLewen
5f9a963ef6
docs: split commands to download db for different versions of oras ( #2582 )
2022-07-25 15:19:04 +03:00
Alexander Lauster
d93a997800
feat(report): export exitcode for license checks ( #2564 )
...
Also export the exit code for license checks
fixes #2562
2022-07-25 14:26:12 +03:00
afdesk
f9be138aab
fix: cli can use lowercase for severities ( #2565 )
2022-07-25 14:25:16 +03:00
Teppei Fukuda
c7f0bc92ae
fix: allow subcommands with TRIVY_RUN_AS_PLUGIN ( #2577 )
2022-07-25 11:27:47 +03:00
MaineK00n
c2f3731873
fix: add missing types in TypeOSes and TypeLanguages in analyzer ( #2569 )
2022-07-24 17:24:13 +03:00
saso
7b4f2dc72f
fix: enable some features of the wasm runtime ( #2575 )
2022-07-24 08:31:54 +03:00
Denys Mazhar
84677903a6
fix(k8s): no error logged if trivy can't get docker image in kubernetes mode ( #2521 )
...
* Enable k8s logging and increase log level of the image scan errors
* Rework errors reporting
* Rework GetErrors method into printErrors
Print errors during report writing
* Increase log level for scan errors logging
2022-07-21 15:34:47 -03:00
saso
e1e02d785f
docs(sbom): improve sbom attestation documentation ( #2566 )
2022-07-21 17:54:21 +03:00