DmitriyLewen
14c1024b47
refactor: move setting scanners when using compliance reports to flag parsing ( #6619 )
2024-05-03 11:27:37 +00:00
Teppei Fukuda
998f750432
feat: introduce package UIDs for improved vulnerability mapping ( #6583 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-05-03 11:14:34 +00:00
simar7
770b14113c
perf(misconf): Improve cause performance ( #6586 )
...
Signed-off-by: Simar <simar@linux.com >
2024-05-03 05:04:10 +00:00
chenk
3ccb1a0f10
docs: trivy-k8s new experiance remove un-used section ( #6608 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-05-03 04:50:53 +00:00
dependabot[bot]
58cfd1b074
chore(deps): bump github.com/docker/docker from 26.0.1+incompatible to 26.0.2+incompatible ( #6612 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-03 04:05:14 +00:00
Marlon M
715963d754
docs: remove mention of GitLab Gold because it doesn't exist anymore ( #6609 )
2024-05-03 04:03:59 +00:00
simar7
37da98df45
feat(misconf): Use updated terminology for misconfiguration checks ( #6476 )
...
Signed-off-by: Simar <simar@linux.com >
2024-05-02 18:16:17 +00:00
dependabot[bot]
cdee7030ac
chore(deps): bump github.com/aws/aws-sdk-go-v2/feature/s3/manager from 1.15.15 to 1.16.15 ( #6593 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 13:34:52 +00:00
DmitriyLewen
6a2225b425
docs: use generic link from trivy-repo ( #6606 )
2024-05-02 13:34:41 +00:00
chenk
a2a02de7c5
docs: update trivy k8s with new experience ( #6465 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-05-02 12:59:22 +00:00
chenk
e739ab8506
feat: support --skip-images scanning flag ( #6334 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-05-02 11:49:39 +00:00
chenk
c6d5d856ce
BREAKING: add support for k8s disable-node-collector flag ( #6311 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-05-02 11:08:59 +00:00
dependabot[bot]
194a814688
chore(deps): bump github.com/zclconf/go-cty from 1.14.1 to 1.14.4 ( #6601 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 10:50:48 +00:00
dependabot[bot]
03830c50c9
chore(deps): bump github.com/sigstore/rekor from 1.2.2 to 1.3.6 ( #6599 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 10:29:16 +00:00
dependabot[bot]
8e814fa23d
chore(deps): bump google.golang.org/protobuf from 1.33.0 to 1.34.0 ( #6597 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 08:32:24 +00:00
dependabot[bot]
2dc76ba782
chore(deps): bump sigstore/cosign-installer from 3.4.0 to 3.5.0 ( #6588 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 08:31:57 +00:00
dependabot[bot]
c17176ba97
chore(deps): bump github.com/testcontainers/testcontainers-go from 0.28.0 to 0.30.0 ( #6595 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 08:31:02 +00:00
dependabot[bot]
bce70af369
chore(deps): bump github.com/open-policy-agent/opa from 0.62.0 to 0.64.1 ( #6596 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 07:08:01 +00:00
DmitriyLewen
4369a19af7
feat: add ubuntu 23.10 and 24.04 support ( #6573 )
2024-05-02 06:40:11 +00:00
dependabot[bot]
5566548b78
chore(deps): bump azure/setup-helm from 3.5 to 4 ( #6590 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 06:35:05 +00:00
dependabot[bot]
a8af76a471
chore(deps): bump actions/checkout from 4.1.2 to 4.1.4 ( #6587 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 06:27:31 +00:00
dependabot[bot]
c8ed432f28
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ecr from 1.24.6 to 1.27.4 ( #6598 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 06:26:47 +00:00
Teppei Fukuda
551a46efcc
docs(go): add stdlib ( #6580 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-05-02 06:24:30 +00:00
dependabot[bot]
261649b115
chore(deps): bump github.com/containerd/containerd from 1.7.13 to 1.7.16 ( #6592 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 06:01:21 +00:00
dependabot[bot]
acfddd4570
chore(deps): bump github.com/go-openapi/runtime from 0.27.1 to 0.28.0 ( #6600 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-05-02 06:00:50 +00:00
Oscar Alberto Tovar
419e3d2023
feat(go): parse main mod version from build info settings ( #6564 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2024-05-02 05:33:13 +00:00
Teppei Fukuda
f0961d54f6
feat: respect custom exit code from plugin ( #6584 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-05-02 05:07:49 +00:00
Jean-Yves LENHOF
a5d485cf8a
docs: add asdf and mise installation method ( #6063 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-04-30 07:32:14 +00:00
Damian E
29b8faf5fa
feat(vuln): Handle scanning conan v2.x lockfiles ( #6357 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2024-04-29 10:37:25 +00:00
DmitriyLewen
e3bef02018
feat: add support environment.yaml files ( #6569 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-04-29 10:33:53 +00:00
guangwu
916f6c66f8
fix: close plugin.yaml ( #6577 )
...
Signed-off-by: guoguangwu <guoguangwug@gmail.com >
2024-04-29 06:13:03 +00:00
chenk
8e6cd0e917
fix: trivy k8s avoid deleting non-default node collector namespace ( #6559 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-04-27 16:39:47 +00:00
chenk
060d0bb641
BREAKING: support exclude kinds/namespaces and include kinds/namespaces ( #6323 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-04-27 14:30:17 +00:00
Teppei Fukuda
2d090ef2df
feat(go): add main module ( #6574 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-04-27 10:00:14 +00:00
Teppei Fukuda
6343e4fc71
feat: add relationships ( #6563 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-04-27 09:15:12 +00:00
DmitriyLewen
a018ee1f9b
ci: disable Go cache for reusable-release.yaml ( #6572 )
2024-04-27 08:40:32 +00:00
Teppei Fukuda
5da053f302
docs: mention --show-suppressed is available in table ( #6571 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-04-27 07:08:47 +00:00
zhaixiaojuan
3d66cb8d88
chore: fix sqlite to support loong64 ( #6511 )
2024-04-26 10:44:24 +00:00
Yaney
9aca98cca8
fix(debian): sort dpkg info before parsing due to exclude directories ( #6551 )
2024-04-26 07:15:29 +00:00
DmitriyLewen
7811ad0d24
docs: update info about config file ( #6547 )
...
Co-authored-by: simar7 <1254783+simar7@users.noreply.github.com >
2024-04-25 11:30:49 +00:00
Jakob Maležič
fae710db8f
docs: remove RELEASE_VERSION from trivy.repo ( #6546 )
2024-04-24 07:18:39 +00:00
Teppei Fukuda
d2d4022ef3
fix(sbom): change error to warning for multiple OSes ( #6541 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-04-24 06:54:41 +00:00
Teppei Fukuda
164b025413
fix(vuln): skip empty versions ( #6542 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-04-24 06:03:12 +00:00
DmitriyLewen
5dd9bd4701
feat(c): add license support for conan lock files ( #6329 )
2024-04-24 05:29:02 +00:00
fwereade
7c2017fa7a
fix(terraform): Attribute and fileset fixes ( #6544 )
2024-04-23 22:03:43 +00:00
DmitriyLewen
63c9469bdd
refactor: change warning if no vulnerability details are found ( #6230 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-04-22 17:54:26 +00:00
Nikita Pivkin
aa822c260f
refactor(misconf): improve error handling in the Rego scanner ( #6527 )
2024-04-22 15:46:10 +00:00
DmitriyLewen
30cc88fa87
ci: use tmp dir inside Trivy repo dir for GoReleaser ( #6533 )
2024-04-22 12:23:05 +00:00
DmitriyLewen
e32215c99d
feat(go): parse main module of go binary files ( #6530 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2024-04-22 11:58:44 +00:00
dependabot[bot]
d4da83c633
chore(deps): bump golang.org/x/net from 0.21.0 to 0.23.0 ( #6526 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-22 04:38:28 +00:00
Nikita Pivkin
0d7d97d131
refactor(misconf): simplify the retrieval of module annotations ( #6528 )
2024-04-20 03:00:18 +00:00
l-qing
9873cf3b9c
chore(deps): bump github.com/hashicorp/go-getter from 1.7.3 to 1.7.4 ( #6523 )
2024-04-19 07:55:24 +00:00
DmitriyLewen
95c8fd912e
docs(nodejs): add info about supported versions of pnpm lock files ( #6510 )
2024-04-19 07:38:32 +00:00
Nikita Pivkin
12ec0dfe9e
feat(misconf): loading embedded checks as a fallback ( #6502 )
2024-04-19 06:22:31 +00:00
simar7
9b7d7132b7
fix(misconf): Parse JSON k8s manifests properly ( #6490 )
2024-04-19 01:17:43 +00:00
Teppei Fukuda
13e72eca58
refactor: remove parallel walk ( #5180 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-04-17 18:24:18 +00:00
guangwu
a9861994e5
fix: close pom.xml ( #6507 )
...
Signed-off-by: guoguangwu <guoguangwug@gmail.com >
2024-04-17 11:22:52 +00:00
DmitriyLewen
46d5abad42
fix(secret): convert severity for custom rules ( #6500 )
2024-04-16 07:51:03 +00:00
DmitriyLewen
34ab09d559
fix(java): update logic to detect pom.xml file snapshot artifacts from remote repositories ( #6412 )
2024-04-16 07:48:58 +00:00
guangwu
1ba5b59527
fix: typo ( #6283 )
...
Signed-off-by: guoguangwu <guoguangwug@gmail.com >
2024-04-16 02:38:13 +00:00
Saeid Bostandoust
4fab0f8b99
docs(k8s,image): fix command-line syntax issues ( #6403 )
2024-04-16 02:33:46 +00:00
dependabot[bot]
d7709816c3
chore(deps): bump actions/checkout from 4.1.1 to 4.1.2 ( #6435 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-16 02:30:58 +00:00
Nikita Pivkin
4337068208
fix(misconf): avoid panic if the scheme is not valid ( #6496 )
2024-04-15 20:14:34 +00:00
Pete Wagner
d82d6cb731
feat(image): goversion as stdlib ( #6277 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-04-15 18:25:04 +00:00
DmitriyLewen
cfddfb33c1
fix: add color for error inside of log message ( #6493 )
2024-04-15 11:13:54 +00:00
dependabot[bot]
dfcb0f90db
chore(deps): bump actions/add-to-project from 0.4.1 to 1.0.0 ( #6438 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-15 11:06:35 +00:00
Nikita Pivkin
183eaafb4e
docs: fix links to OPA docs ( #6480 )
2024-04-12 19:52:50 +00:00
Teppei Fukuda
94d6e8ced6
refactor: replace zap with slog ( #6466 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: Nikita Pivkin <nikita.pivkin@smartforce.io >
Co-authored-by: simar7 <1254783+simar7@users.noreply.github.com >
2024-04-11 18:59:09 +00:00
Nikita Pivkin
336c47ecc3
docs: update links to IaC schemas ( #6477 )
2024-04-11 02:24:06 +00:00
Teppei Fukuda
06b44738e7
chore: bump Go to 1.22 ( #6075 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: Simar <simar@linux.com >
2024-04-08 10:53:00 +00:00
Nikita Pivkin
a51ceddada
refactor(terraform): sync funcs with Terraform ( #6415 )
2024-04-06 05:10:53 +00:00
Jan-Otto Kröpke
53517d622b
feat(misconf): add helm-api-version and helm-kube-version flag ( #6332 )
...
Co-authored-by: Simar <simar@linux.com >
2024-04-06 05:07:56 +00:00
dependabot[bot]
ad544e97cc
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azidentity from 1.4.0 to 1.5.1 ( #6426 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-04 06:49:05 +00:00
dependabot[bot]
089368d968
chore(deps): bump github.com/go-openapi/strfmt from 0.22.0 to 0.23.0 ( #6452 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-04 06:37:32 +00:00
dependabot[bot]
116356500e
chore(deps): bump github.com/hashicorp/golang-lru/v2 from 2.0.6 to 2.0.7 ( #6430 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-04 06:34:27 +00:00
dependabot[bot]
637da2b178
chore(deps): bump aquaproj/aqua-installer from 2.2.0 to 3.0.0 ( #6437 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-04 06:33:36 +00:00
Nikita Pivkin
13190e92d9
fix(terraform): eval submodules ( #6411 )
...
Co-authored-by: William Reade <william@stacklet.io >
2024-04-04 03:40:40 +00:00
Nikita Pivkin
6bca7c3c79
refactor(terraform): remove unused options ( #6446 )
2024-04-04 00:29:31 +00:00
Nikita Pivkin
8e4279b863
refactor(terraform): remove unused file ( #6445 )
2024-04-04 00:13:25 +00:00
Prajyot Parab
e98c873ed0
chore(deps): bump github.com/testcontainers/testcontainers-go to v0.28.0 ( #6387 )
...
Signed-off-by: Prajyot-Parab <prajyot.parab2@ibm.com >
2024-04-03 16:55:03 +00:00
dependabot[bot]
b1c2eab5aa
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azcore from 1.9.0 to 1.10.0 ( #6427 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-03 16:36:44 +00:00
simar7
1c49a16c65
fix(misconf): Escape template value correctly ( #6292 )
...
Signed-off-by: Simar <simar@linux.com >
2024-04-03 04:30:18 +00:00
Nikita Pivkin
8dd0fcd61b
feat(misconf): add support for wildcard ignores ( #6414 )
2024-04-03 00:43:29 +00:00
Nikita Pivkin
74e4c6e012
fix(cloudformation): resolve DedicatedMasterEnabled parsing issue ( #6439 )
2024-04-02 22:42:46 +00:00
Nikita Pivkin
245c120532
refactor(terraform): remove metrics collection ( #6444 )
2024-04-02 22:41:57 +00:00
Nikita Pivkin
86714bf6bf
feat(cloudformation): add support for logging and endpoint access for EKS ( #6440 )
2024-04-02 22:41:30 +00:00
dependabot[bot]
a75839212c
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.51.1 to 1.53.1 ( #6424 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-02 16:04:23 +00:00
dependabot[bot]
4d00d8b52a
chore(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.27.4 to 1.27.10 ( #6428 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-02 14:32:29 +00:00
dependabot[bot]
3ad2b3e255
chore(deps): bump go.etcd.io/bbolt from 1.3.8 to 1.3.9 ( #6429 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-02 11:23:47 +00:00
DmitriyLewen
8baccd7909
fix(db): check schema version for image name only ( #6410 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-04-02 11:22:43 +00:00
dependabot[bot]
e75a90f2e5
chore(deps): bump github.com/google/wire from 0.5.0 to 0.6.0 ( #6425 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-02 11:20:08 +00:00
dependabot[bot]
6625bd32e0
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.149.1 to 1.155.1 ( #6433 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-02 11:18:50 +00:00
dependabot[bot]
826fe60732
chore(deps): bump actions/cache from 4.0.0 to 4.0.2 ( #6436 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-04-02 11:17:12 +00:00
Jeff Rescignano
f23ed77598
feat(misconf): Support private registries for misconf check bundle ( #6327 )
2024-04-01 05:45:58 +00:00
Nikita Pivkin
df024e88dd
feat(cloudformation): inline ignore support for YAML templates ( #6358 )
2024-03-29 05:23:01 +00:00
Nikita Pivkin
29dee32814
feat(terraform): ignore resources by nested attributes ( #6302 )
2024-03-29 03:55:18 +00:00
Nikita Pivkin
1a67472d2b
perf(helm): load in-memory files ( #6383 )
2024-03-29 03:55:00 +00:00
Nikita Pivkin
09e37b7c67
feat(aws): apply filter options to result ( #6367 )
2024-03-29 01:12:23 +00:00
Nikita Pivkin
87a9aa60d1
feat(aws): quiet flag support ( #6331 )
2024-03-29 01:11:27 +00:00
Nikita Pivkin
712dcd3007
fix(misconf): clear location URI for SARIF ( #6405 )
2024-03-29 01:10:06 +00:00
Nikita Pivkin
625f22b819
test(cloudformation): add CF tests ( #6315 )
2024-03-29 01:08:06 +00:00
Nikita Pivkin
6a2f6fde4f
fix(cloudformation): infer type after resolving a function ( #6406 )
2024-03-28 21:50:36 +00:00
DmitriyLewen
5f69937cc6
fix(sbom): fix error when parent of SPDX Relationships is not a package. ( #6399 )
2024-03-27 07:07:12 +00:00
DmitriyLewen
258d153461
fix(nodejs): merge Indirect, Dev, ExternalReferences fields for same deps from package-lock.json files v2 or later ( #6356 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-03-27 06:08:58 +00:00
DmitriyLewen
ade033a837
docs: add info about support for package license detection in fs/repo modes ( #6381 )
2024-03-27 05:51:09 +00:00
DmitriyLewen
f85c9fac6f
fix(nodejs): add support for parsing workspaces from package.json as an object ( #6231 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2024-03-27 05:46:25 +00:00
DmitriyLewen
9d7f5c948e
fix: use 0600 perms for tmp files for post analyzers ( #6386 )
2024-03-27 05:32:22 +00:00
Nikita Pivkin
f148eb10f2
fix(helm): scan the subcharts once ( #6382 )
2024-03-26 17:10:16 +00:00
Nikita Pivkin
97f95c4ddf
docs(terraform): add file patterns for Terraform Plan ( #6393 )
2024-03-26 17:04:40 +00:00
Nikita Pivkin
abd62ae74e
fix(terraform): сhecking SSE encryption algorithm validity ( #6341 )
2024-03-26 03:31:28 +00:00
DmitriyLewen
7c409fd270
fix(java): parse modules from pom.xml files once ( #6312 )
2024-03-24 09:57:32 +00:00
dependabot[bot]
1b68327b65
chore(deps): bump github.com/docker/docker from 25.0.3+incompatible to 25.0.5+incompatible ( #6364 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-24 09:55:08 +00:00
DmitriyLewen
a2482c14e1
fix(server): add Locations for Packages in client/server mode ( #6366 )
2024-03-24 09:46:56 +00:00
DmitriyLewen
e866bd5b5d
fix(sbom): add check for CreationInfo to nil when detecting SPDX created using Trivy ( #6346 )
2024-03-24 09:45:45 +00:00
DmitriyLewen
1870f28461
fix(report): don't include empty strings in .vulnerabilities[].identifiers[].url when gitlab.tpl is used ( #6348 )
2024-03-24 09:44:40 +00:00
Stefan Mayr
6c81e5505e
chore(ubuntu): Add Ubuntu 22.04 EOL date ( #6371 )
2024-03-24 07:26:49 +00:00
dependabot[bot]
8ec3938e01
chore(deps): bump google.golang.org/protobuf from 1.32.0 to 1.33.0 ( #6321 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-19 01:04:16 +00:00
DmitriyLewen
f6c5d58001
feat(java): add support licenses and graph for gradle lock files ( #6140 )
2024-03-19 00:59:31 +00:00
Teppei Fukuda
c4022d61b3
feat(vex): consider root component for relationships ( #6313 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-03-19 00:51:18 +00:00
DmitriyLewen
317792433e
fix: increase the default buffer size for scanning dpkg status files by 2 times ( #6298 )
2024-03-18 09:42:54 +00:00
Edoardo Vacchi
dd9620ef38
chore: updates wazero to v1.7.0 ( #6301 )
...
Signed-off-by: Edoardo Vacchi <evacchi@users.noreply.github.com >
2024-03-18 09:41:34 +00:00
Ivo Šmíd
eb3ceb323d
feat(sbom): Support license detection for SBOM scan ( #6072 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-03-18 09:34:26 +00:00
Teppei Fukuda
ab74caa87f
refactor(sbom): use intermediate representation for SPDX ( #6310 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-03-18 08:52:11 +00:00
Nikita Pivkin
71da44f7e1
docs(terraform): improve documentation for filtering by inline comments ( #6284 )
2024-03-12 14:49:07 +00:00
Nikita Pivkin
102b6df738
fix(terraform): fix policy document retrieval ( #6276 )
2024-03-12 14:48:16 +00:00
Nikita Pivkin
aa19aaf4e4
refactor(terraform): remove unused custom error ( #6303 )
2024-03-12 14:43:09 +00:00
Teppei Fukuda
8fcef352b3
refactor(sbom): add intermediate representation for BOM ( #6240 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
2024-03-12 06:56:10 +00:00
DmitriyLewen
fb8c516ded
fix(amazon): check only major version of AL to find advisories ( #6295 )
2024-03-11 08:46:25 +00:00
DmitriyLewen
96bd7ac594
fix(db): use schema version as tag only for trivy-db and trivy-java-db registries by default ( #6219 )
2024-03-11 06:57:56 +00:00
DmitriyLewen
12c5bf0805
fix(nodejs): add name validation for package name from package.json ( #6268 )
2024-03-11 05:23:51 +00:00
Matthias Fechner
d6c40ce058
docs: Added install instructions for FreeBSD ( #6293 )
2024-03-11 04:58:12 +00:00
Parvez
9d2057a7c2
feat(image): customer podman host or socket option ( #6256 )
...
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-03-11 04:27:57 +00:00
Edoardo Vacchi
2a9d9bd214
chore(deps): bump wazero from 1.2.1 to 1.6.0 ( #6290 )
...
Signed-off-by: Edoardo Vacchi <evacchi@users.noreply.github.com >
2024-03-11 04:08:09 +00:00
DmitriyLewen
617c3e31bd
feat(java): mark dependencies from maven-invoker-plugin integration tests pom.xml files as Dev ( #6213 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-03-08 10:13:49 +00:00
Damian E
56cedc0d67
fix(license): reorder logic of how python package licenses are acquired ( #6220 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-03-08 06:37:55 +00:00
Nikita Pivkin
d7d7265eb0
test(terraform): skip cached modules ( #6281 )
2024-03-08 00:37:58 +00:00
Chris King
6639911662
feat(secret): Support for detecting Hugging Face Access Tokens ( #6236 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-03-07 14:00:52 +00:00
Nikita Pivkin
337cb75353
fix(cloudformation): support of all SSE algorithms for s3 ( #6270 )
2024-03-07 01:12:04 +00:00
Nikita Pivkin
9361cdb7e2
feat(terraform): Terraform Plan snapshot scanning support ( #6176 )
...
Co-authored-by: Simar <simar@linux.com >
Co-authored-by: simar7 <1254783+simar7@users.noreply.github.com >
2024-03-04 22:37:31 +00:00
dependabot[bot]
ee01e6e2f4
chore(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.26.6 to 1.27.4 ( #6249 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-04 14:33:33 +00:00
guangwu
3d2f583ecd
fix: typo function name and comment optimization ( #6200 )
...
Signed-off-by: guoguangwu <guoguangwu@magic-shield.com >
2024-03-04 14:24:40 +00:00
DmitriyLewen
c4b5ab7881
fix(java): don't ignore runtime scope for pom.xml files ( #6223 )
2024-03-04 14:23:13 +00:00
dependabot[bot]
355c1b583b
chore(deps): bump helm/kind-action from 1.8.0 to 1.9.0 ( #6242 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-04 13:49:43 +00:00
dependabot[bot]
7244ece536
chore(deps): bump golangci/golangci-lint-action from 3.7.0 to 4.0.0 ( #6243 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-04 13:41:39 +00:00
dependabot[bot]
5cd0566843
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.48.1 to 1.51.1 ( #6251 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-04 13:38:30 +00:00
dependabot[bot]
ebb74a5de0
chore(deps): bump github.com/hashicorp/go-uuid from 1.0.1 to 1.0.3 ( #6253 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-04 11:35:03 +00:00
dependabot[bot]
24a8d6aaa8
chore(deps): bump github.com/open-policy-agent/opa from 0.61.0 to 0.62.0 ( #6250 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-04 11:22:55 +00:00
dependabot[bot]
9d0d7ad886
chore(deps): bump github.com/containerd/containerd from 1.7.12 to 1.7.13 ( #6247 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-04 11:18:00 +00:00
dependabot[bot]
e8230e19d7
chore(deps): bump go.uber.org/zap from 1.26.0 to 1.27.0 ( #6246 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-03-04 10:59:18 +00:00
Damian E
04535b554a
fix(license): add FilePath to results to allow for license path filtering via trivyignore file ( #6215 )
...
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-03-04 09:38:51 +00:00
simar7
939e34e37c
chore(deps): Upgrade iac deps ( #6255 )
2024-03-04 09:30:55 +00:00
DmitriyLewen
7cb6c02a4e
feat: add info log message about dev deps suppression ( #6211 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2024-03-04 09:30:30 +00:00
DmitriyLewen
c1d26ec334
test(k8s): use test-db for k8s integration tests ( #6222 )
2024-02-28 16:17:59 +00:00
DmitriyLewen
4f70468bdd
ci: add maximize-build-space for Test job ( #6221 )
2024-02-28 10:06:52 +00:00
Nikita Pivkin
1dfece89d0
fix(terraform): fix root module search ( #6160 )
...
Co-authored-by: simar7 <1254783+simar7@users.noreply.github.com >
2024-02-28 03:31:03 +00:00
DmitriyLewen
e1ea02c7b8
test(parser): squash test data for yarn ( #6203 )
2024-02-27 07:24:22 +00:00
Nikita Pivkin
64926d8423
fix(terraform): do not re-expand dynamic blocks ( #6151 )
2024-02-27 07:02:29 +00:00
Anais Urlichs
eb54bb5da5
docs: update ecosystem page reporting with db app ( #6201 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2024-02-27 02:47:30 +00:00
chenk
dc76c6e4f4
fix: k8s summary separate infra and user finding results ( #6120 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-02-27 02:29:41 +00:00
chenk
1b7e47424b
fix: add context to target finding on k8s table view ( #6099 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-02-26 06:58:47 +00:00
guangwu
876ab84b36
fix: Printf format err ( #6198 )
...
Signed-off-by: guoguangwu <guoguangwu@magic-shield.com >
2024-02-26 06:07:35 +00:00
Teppei Fukuda
eef7c4fb40
refactor: better integration of the parser into Trivy ( #6183 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-02-26 05:55:15 +00:00
dependabot[bot]
069aae59ec
chore(deps): bump helm.sh/helm/v3 from 3.14.1 to 3.14.2 ( #6189 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-23 03:17:15 +00:00
Adam Carruthers
4a9ac6d199
feat(terraform): Add hyphen and non-ASCII support for domain names in credential extraction ( #6108 )
...
Co-authored-by: simar7 <1254783+simar7@users.noreply.github.com >
2024-02-23 00:54:40 +00:00
Juan Ariza Toledano
9c5e5a04ee
fix(vex): CSAF filtering should consider relationships ( #5923 )
...
Signed-off-by: juan131 <jariza@vmware.com >
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2024-02-22 10:23:11 +00:00
Maxime Durand
388f47669d
refactor(report): Replacing source_location in github report when scanning an image ( #5999 )
...
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
2024-02-22 09:56:18 +00:00
Teppei Fukuda
cd3e4bcac2
feat(vuln): ignore vulnerabilities by PURL ( #6178 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-02-22 09:55:13 +00:00
renypaul
ce81c05851
feat(java): add support for fetching packages from repos mentioned in pom.xml ( #6171 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-02-22 09:50:08 +00:00
chenk
cf0f0d00c2
feat(k8s): rancher rke2 version support ( #5988 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-02-22 04:35:47 +00:00
chenk
8a3a113eea
docs: update kbom distribution for scanning ( #6019 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-02-21 16:16:23 +00:00
Teppei Fukuda
19495ba7c2
chore: update CODEOWNERS ( #6173 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-02-21 16:14:12 +00:00
DmitriyLewen
e787e1af01
fix(swift): try to use branch to resolve version ( #6168 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-02-21 14:52:47 +00:00
Nikita Pivkin
327cf88397
fix(terraform): ensure consistent path handling across OS ( #6161 )
2024-02-21 07:19:07 +00:00
DmitriyLewen
82214736a9
fix(java): add only valid libs from pom.properties files from jars ( #6164 )
2024-02-20 06:51:43 +00:00
saso
7694df11fb
fix(sbom): skip executable file analysis if Rekor isn't a specified SBOM source ( #6163 )
2024-02-20 06:44:35 +00:00
Teppei Fukuda
74dc5b6804
chore(deps): merge go-dep-parser into Trivy ( #6094 )
...
Signed-off-by: Arunprasad Rajkumar <arajkuma@redhat.com >
Signed-off-by: guoguangwu <guoguangwu@magic-shield.com >
Signed-off-by: dependabot[bot] <support@github.com >
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: Masahiro <mur4m4s4.331@gmail.com >
Co-authored-by: Tomoya Amachi <tomoya.amachi@gmail.com >
Co-authored-by: Masahiro <lomycisw@gmail.com >
Co-authored-by: Liz Rice <liz@lizrice.com >
Co-authored-by: Johannes <johannes@jitesoft.com >
Co-authored-by: aprp <doelaudi@gmail.com >
Co-authored-by: rahul2393 <rahulyadavsep92@gmail.com >
Co-authored-by: Arunprasad Rajkumar <ar.arunprasad@gmail.com >
Co-authored-by: Emrecan BATI <emrecanbati@gmail.com >
Co-authored-by: sherif84 <12298259+sherif84@users.noreply.github.com >
Co-authored-by: Sherif Fathalla <sfathall@akamai.com >
Co-authored-by: sherif <sherif.mailbox@gmail.com >
Co-authored-by: Sam Lane <samuel.lane@hotmail.com >
Co-authored-by: Ankush K <akhobragade@gmail.com >
Co-authored-by: Ankush K <akhobragade42@gmail.com >
Co-authored-by: Tauseef <tauseefmlk@gmail.com >
Co-authored-by: Daniel <danfaizer@gmail.com >
Co-authored-by: Matthieu MOREL <mmorel-35@users.noreply.github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: afdesk <work@afdesk.com >
Co-authored-by: AndreyLevchenko <levchenko.andrey@gmail.com >
Co-authored-by: Kobus van Schoor <10784365+kobus-v-schoor@users.noreply.github.com >
Co-authored-by: Jan-Otto Kröpke <github@jkroepke.de >
Co-authored-by: jerbob92 <jerbob92@users.noreply.github.com >
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
Co-authored-by: Shira Cohen <97398476+ShiraCohen33@users.noreply.github.com >
Co-authored-by: astevenson-microsoft <78623826+astevenson-microsoft@users.noreply.github.com >
Co-authored-by: Kyriakos Georgiou <kgeorgiou@users.noreply.github.com >
Co-authored-by: mycodeself <mycodeself@users.noreply.github.com >
Co-authored-by: DavidSalame <75929252+davidsalame1@users.noreply.github.com >
Co-authored-by: Tom Fay <tom@teamfay.co.uk >
Co-authored-by: Tom Fay <tomfay@microsoft.com >
Co-authored-by: François Poirotte <fpoirotte@users.noreply.github.com >
Co-authored-by: Guy Ben-Aharon <baguy3@gmail.com >
Co-authored-by: Catminusminus <37803616+Catminusminus@users.noreply.github.com >
Co-authored-by: Lior Vaisman Argon <97836016+VaismanLior@users.noreply.github.com >
Co-authored-by: Matthieu Maitre <mmaitre@microsoft.com >
Co-authored-by: Andrea Scarpino <andrea@scarpino.dev >
Co-authored-by: MorAlon1 <101275199+MorAlon1@users.noreply.github.com >
Co-authored-by: liorj-orca <96177663+liorj-orca@users.noreply.github.com >
Co-authored-by: Nikita Pivkin <100182843+nikpivkin@users.noreply.github.com >
Co-authored-by: guangwu <guoguangwu@magic-shield.com >
Co-authored-by: Nikita Pivkin <nikita.pivkin@smartforce.io >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
Co-authored-by: yuriShafet <5830215+yuriShafet@users.noreply.github.com >
Co-authored-by: Octogonapus <firey45@gmail.com >
2024-02-19 11:16:35 +00:00
DmitriyLewen
32a02a95dd
docs(report): add remark about path to filter licenses using .trivyignore.yaml file ( #6145 )
2024-02-16 09:04:57 +00:00
Mike Thomas
fb79ea7c95
docs: update template path for gitlab-ci tutorial ( #6144 )
2024-02-16 08:58:08 +00:00
Kristina Trotsko
c6844a73f1
feat(report): support for filtering licenses and secrets via rego policy files ( #6004 )
2024-02-16 08:39:03 +00:00
DmitriyLewen
a813506f41
fix(cyclonedx): move root component from scanned cyclonedx file to output cyclonedx file ( #6113 )
2024-02-16 08:36:29 +00:00
simar7
14adbb4464
refactor(deps): Merge defsec into trivy ( #6109 )
...
Signed-off-by: Simar <simar@linux.com >
2024-02-16 08:31:32 +00:00
dependabot[bot]
efe0e0f8f3
chore(deps): bump helm.sh/helm/v3 from 3.14.0 to 3.14.1 ( #6142 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-15 17:24:09 +00:00
Stefan Fleckenstein
73dde32632
docs: add SecObserve in CI/CD and reporting ( #6139 )
2024-02-15 10:12:59 +00:00
DmitriyLewen
aadbad1d78
fix(alpine): exclude empty licenses for apk packages ( #6130 )
2024-02-14 10:57:25 +00:00
Anais Urlichs
14a0981efa
docs: add docs tutorial on custom policies with rego ( #6104 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
Co-authored-by: simar7 <1254783+simar7@users.noreply.github.com >
2024-02-14 08:40:11 +00:00
DmitriyLewen
3ac63887dc
fix(nodejs): use project dir when searching for workspaces for Yarn.lock files ( #6102 )
2024-02-13 13:39:43 +00:00
Teppei Fukuda
3c1601b6cb
feat(vuln): show suppressed vulnerabilities in table ( #6084 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
2024-02-13 12:35:06 +00:00
Teppei Fukuda
c107e1af29
docs: rename governance to principles ( #6107 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-02-12 14:27:35 +00:00
Teppei Fukuda
b26f217172
docs: add governance ( #6090 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-02-12 11:56:49 +00:00
simar7
7bd3b630bb
refactor(deps): Merge trivy-iac into Trivy ( #6005 )
2024-02-12 11:01:27 +00:00
DmitriyLewen
535b5a96d9
feat(java): add dependency location support for gradle files ( #6083 )
2024-02-08 09:43:35 +00:00
dependabot[bot]
428420ee84
chore(deps): bump github.com/aws/aws-sdk-go-v2/feature/s3/manager from 1.15.11 to 1.15.15 ( #6038 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-07 05:34:28 +00:00
DmitriyLewen
7fec991c58
fix(misconf): get user from Config.User ( #6070 )
2024-02-07 05:11:10 +00:00
DmitriyLewen
6ccc0a554b
fix: check unescaped BomRef when matching PkgIdentifier ( #6025 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-02-06 11:09:53 +00:00
Alexander Münch
458c5d95e6
docs: Fix broken link to "pronunciation" ( #6057 )
2024-02-06 11:09:08 +00:00
dependabot[bot]
5c0ff6dad1
chore(deps): bump actions/upload-artifact from 3 to 4 ( #6047 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-06 09:57:41 +00:00
dependabot[bot]
e2bd7f75d5
chore(deps): bump github.com/spf13/viper from 1.16.0 to 1.18.2 ( #6042 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-06 06:47:02 +00:00
dependabot[bot]
f95fbcb672
chore(deps): bump k8s.io/api from 0.29.0 to 0.29.1 ( #6043 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-06 03:37:41 +00:00
DmitriyLewen
7651bf59b2
ci: reduce root-reserve-mb size for maximize-build-space ( #6064 )
2024-02-05 13:09:15 +00:00
dependabot[bot]
fc20dfdd80
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.48.0 to 1.48.1 ( #6041 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-05 03:33:34 +00:00
dependabot[bot]
3bd80e7c28
chore(deps): bump github.com/open-policy-agent/opa from 0.60.0 to 0.61.0 ( #6039 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-05 03:33:05 +00:00
DmitriyLewen
2900a21176
fix: fix cursor usage in Redis Clear function ( #6056 )
2024-02-02 11:55:50 +00:00
dependabot[bot]
85cb9a7639
chore(deps): bump github.com/go-openapi/runtime from 0.26.0 to 0.27.1 ( #6037 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-02 11:52:05 +00:00
DmitriyLewen
4e962c02aa
fix(nodejs): add local packages support for pnpm-lock.yaml files ( #6034 )
2024-02-02 11:19:54 +00:00
dependabot[bot]
aa48a7b865
chore(deps): bump sigstore/cosign-installer from 3.3.0 to 3.4.0 ( #6046 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-02 11:04:16 +00:00
dependabot[bot]
8aabbea2d3
chore(deps): bump github.com/go-openapi/strfmt from 0.21.7 to 0.22.0 ( #6044 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-02 10:56:39 +00:00
dependabot[bot]
ec02a655af
chore(deps): bump actions/cache from 3.3.2 to 4.0.0 ( #6048 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-02 08:55:01 +00:00
DmitriyLewen
27d35baa4a
test: fix flaky TestDockerEngine ( #6054 )
2024-02-02 08:48:51 +00:00
dependabot[bot]
c3a66da9c3
chore(deps): bump github.com/google/go-containerregistry from 0.17.0 to 0.19.0 ( #6040 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-01 17:11:52 +00:00
dependabot[bot]
2000fe24c6
chore(deps): bump easimon/maximize-build-space from 9 to 10 ( #6049 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-01 17:10:37 +00:00
dependabot[bot]
2be642154f
chore(deps): bump alpine from 3.19.0 to 3.19.1 ( #6051 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-01 17:10:02 +00:00
dependabot[bot]
41c0ef642e
chore(deps): bump github.com/moby/buildkit from 0.11.6 to 0.12.5 ( #6028 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2024-02-01 12:13:26 +00:00
DmitriyLewen
729a0512ab
fix(java): recursive check all nested depManagements with import scope for pom.xml files ( #5982 )
2024-02-01 06:19:17 +00:00
dependabot[bot]
884745b5e5
chore(deps): bump github.com/opencontainers/runc from 1.1.5 to 1.1.12 ( #6029 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-02-01 04:00:55 +00:00
Teppei Fukuda
59e54334d1
fix(cli): inconsistent behavior across CLI flags, environment variables, and config files ( #5843 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-02-01 03:25:30 +00:00
Andrey Fedotov
5924c021da
feat(rust): Support workspace.members parsing for Cargo.toml analysis ( #5285 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-29 08:34:43 +00:00
Nikita Pivkin
4df9363890
docs: add note about Bun ( #6001 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-26 10:52:25 +00:00
DmitriyLewen
70dd572ef7
fix(report): use AWS_REGION env for secrets in asff template ( #6011 )
2024-01-26 08:19:27 +00:00
guangwu
13f797f885
fix: check returned error before deferring f.Close() ( #6007 )
...
Signed-off-by: guoguangwu <guoguangwu@magic-shield.com >
2024-01-26 07:57:37 +00:00
DmitriyLewen
adfde63d00
feat(misconf): add support of buildkit instructions when building dockerfile from image config ( #5990 )
2024-01-25 11:22:43 +00:00
Teppei Fukuda
e2eb70ecb8
feat(vuln): enable --vex for all targets ( #5992 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
2024-01-25 10:34:34 +00:00
Nikita Pivkin
f9da021315
docs: update link to data sources ( #6000 )
2024-01-25 10:23:32 +00:00
DmitriyLewen
b4b90cfe20
feat(java): add support for line numbers for pom.xml files ( #5991 )
2024-01-25 07:25:38 +00:00
DmitriyLewen
fb36c4ed09
refactor(sbom): use new metadata.tools struct for CycloneDX ( #5981 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-23 13:59:48 +00:00
Anais Urlichs
f6be42b71d
docs: Update troubleshooting guide with image not found error ( #5983 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-23 08:29:09 +00:00
Anais Urlichs
bb6caea5cb
style: update band logos ( #5968 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2024-01-23 06:45:55 +00:00
simar7
189a46a01c
chore(deps): Update misconfig deps ( #5956 )
2024-01-23 06:44:10 +00:00
Anais Urlichs
91a2547d15
docs: update cosign tutorial and commands, update kyverno policy ( #5929 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
Co-authored-by: saso <sasoakira6114@gmail.com >
2024-01-22 07:44:16 +00:00
Anais Urlichs
a96f66f176
docs: update command to scan go binary ( #5969 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2024-01-19 08:28:46 +00:00
chenk
2212d14432
fix: handle non-parsable images names ( #5965 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-01-19 08:27:35 +00:00
dependabot[bot]
7cad04bdf1
chore(deps): bump aquaproj/aqua-installer from 2.1.2 to 2.2.0 ( #5693 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-17 09:00:37 +00:00
DmitriyLewen
fbc1a83f32
fix(amazon): save system files for pkgs containing amzn in src ( #5951 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-17 06:57:41 +00:00
Devin Trejo
260aa281f4
fix(alpine): Add EOL support for alpine 3.19. ( #5938 )
...
Signed-off-by: Devin Trejo <dtrejo@palantir.com >
2024-01-16 07:59:08 +00:00
Bishwa Thapa
2c9d7c6b50
feat: allow end-users to adjust K8S client QPS and burst ( #5910 )
2024-01-15 19:08:52 +00:00
Nikita Pivkin
ffe2ca7cb5
chore(deps): bump go-ebs-file ( #5934 )
2024-01-15 10:32:24 +00:00
DmitriyLewen
f90d4ee436
fix(nodejs): find licenses for packages with slash ( #5836 )
2024-01-15 07:11:12 +00:00
DmitriyLewen
c75143f5e8
fix(sbom): use group field for pom.xml and nodejs files for CycloneDX reports ( #5922 )
2024-01-15 06:57:46 +00:00
chenk
a3fac90b47
fix: ignore no init containers ( #5939 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2024-01-15 06:14:57 +00:00
Fatih Tokus
b1b4734f55
docs: Fix documentation of ecosystem ( #5940 )
2024-01-15 06:13:27 +00:00
Laurent Commarieu
a2b654945a
docs(misconf): multiple ignores in comment ( #5926 )
2024-01-12 04:36:55 +00:00
DmitriyLewen
ae134a9b38
fix(secret): find aws secrets ending with a comma or dot ( #5921 )
2024-01-11 08:00:33 +00:00
dependabot[bot]
c8c55fe21e
chore(deps): bump github.com/aws/aws-sdk-go-v2/feature/s3/manager from 1.11.90 to 1.15.11 ( #5885 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Simar <simar@linux.com >
2024-01-11 07:30:40 +00:00
mfreeman451
4d2e785ff2
docs: ✨ Updated ecosystem docs with reference to new community app ( #5918 )
2024-01-11 07:25:44 +00:00
DmitriyLewen
7895657c89
fix(java): don't remove excluded deps from upper pom's ( #5838 )
2024-01-10 09:39:52 +00:00
DmitriyLewen
37e7e3eabf
fix(java): check if a version exists when determining GAV by file name for jar files ( #5630 )
2024-01-10 07:22:50 +00:00
Teppei Fukuda
d0c81e23c4
feat(vex): add PURL matching for CSAF VEX ( #5890 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-01-10 06:37:19 +00:00
DmitriyLewen
958e1f11f7
fix(secret): AWS Secret Access Key must include only secrets with aws text. ( #5901 )
2024-01-09 11:51:30 +00:00
DmitriyLewen
56c4e248aa
revert(report): don't escape new line characters for sarif format ( #5897 )
2024-01-09 11:50:35 +00:00
Itay Shakury
92d9b3dbba
docs: improve filter by rego ( #5402 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-09 05:52:03 +00:00
dependabot[bot]
a626cdf334
chore(deps): bump github.com/cloudflare/circl from 1.3.6 to 1.3.7 ( #5892 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-08 17:33:06 +00:00
Fatih Tokus
47b6c2817a
docs: add_scan2html_to_trivy_ecosystem ( #5875 )
2024-01-08 10:33:20 +00:00
yusuke-koyoshi
0ebb6c4682
fix(vm): update ext4-filesystem fix reading groupdescriptor in 32bit mode ( #5888 )
2024-01-08 06:06:37 +00:00
Juan Ariza Toledano
c47ed0d816
feat(vex): Add support for CSAF format ( #5535 )
...
Signed-off-by: juan131 <jariza@vmware.com >
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-06 10:48:39 +00:00
dependabot[bot]
2cdd65dd64
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/sts from 1.26.2 to 1.26.7 ( #5880 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-05 19:38:44 +00:00
dependabot[bot]
cba67d1f06
chore(deps): bump actions/setup-go from 4 to 5 ( #5845 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-05 16:31:44 +00:00
dependabot[bot]
d990e702a2
chore(deps): bump actions/stale from 8 to 9 ( #5846 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-05 12:35:25 +00:00
dependabot[bot]
c72dfbfbb0
chore(deps): bump github.com/open-policy-agent/opa from 0.58.0 to 0.60.0 ( #5853 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-05 12:31:33 +00:00
dependabot[bot]
121898423b
chore(deps): bump sigstore/cosign-installer from 3.2.0 to 3.3.0 ( #5847 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-05 12:31:32 +00:00
dependabot[bot]
682210ac64
chore(deps): bump modernc.org/sqlite from 1.23.1 to 1.28.0 ( #5854 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-04 19:10:54 +00:00
dependabot[bot]
e1a60cc88c
chore(deps): bump alpine from 3.18.5 to 3.19.0 ( #5849 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-04 19:03:00 +00:00
dependabot[bot]
b508414ca2
chore(deps): bump actions/setup-python from 4 to 5 ( #5848 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-04 19:01:57 +00:00
Nikita Pivkin
df3e90af8f
feat(python): parse licenses from dist-info folder ( #4724 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-04 18:20:55 +00:00
dependabot[bot]
fa2e88360b
chore(deps): bump github.com/secure-systems-lab/go-securesystemslib from 0.7.0 to 0.8.0 ( #5852 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-04 09:29:08 +00:00
DmitriyLewen
30eff9c83e
feat(nodejs): add yarn alias support ( #5818 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2024-01-04 05:16:35 +00:00
dependabot[bot]
013df4c6b8
chore(deps): bump github.com/samber/lo from 1.38.1 to 1.39.0 ( #5850 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-04 05:12:39 +00:00
dependabot[bot]
b1489f3485
chore(deps): bump github.com/hashicorp/go-getter from 1.7.2 to 1.7.3 ( #5856 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-03 11:53:52 +00:00
dependabot[bot]
7f2e4223ff
chore(deps): bump google.golang.org/protobuf from 1.31.0 to 1.32.0 ( #5855 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-03 11:43:57 +00:00
Teppei Fukuda
da597c479c
refactor: propagate time through context values ( #5858 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2024-01-03 09:43:45 +00:00
Teppei Fukuda
1607eee77c
refactor: move PkgRef under PkgIdentifier ( #5831 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-12-29 06:52:36 +00:00
DmitriyLewen
b3d516eafe
fix(cyclonedx): fix unmarshal for licenses ( #5828 )
2023-12-29 05:28:13 +00:00
dependabot[bot]
c17b6603db
chore(deps): bump github.com/go-git/go-git/v5 from 5.10.1 to 5.11.0 ( #5830 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-29 05:26:15 +00:00
Juan Ariza Toledano
1f0d6290c3
feat(vuln): include pkg identifier on detected vulnerabilities ( #5439 )
...
Signed-off-by: juan131 <jariza@vmware.com >
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
Co-authored-by: Nikita Pivkin <nikita.pivkin@smartforce.io >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-12-27 07:54:56 +00:00
Nikita Pivkin
4cdff0e573
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from v1.116.0 to v1.134.0 ( #5822 )
2023-12-26 12:09:43 +00:00
dependabot[bot]
be969d4136
chore(deps): bump github.com/containerd/containerd from 1.7.7 to 1.7.11 ( #5809 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-25 06:13:16 +00:00
dependabot[bot]
81748f5ad0
chore(deps): bump golang.org/x/crypto from 0.15.0 to 0.17.0 ( #5805 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-19 07:59:21 +00:00
Nikita Pivkin
ba825b2ae1
chore(deps): bump trivy-iac to v0.7.1 ( #5797 )
2023-12-18 12:31:07 +00:00
Juan Ariza Toledano
abf227e06e
fix(bitnami): use a different comparer for detecting vulnerabilities ( #5633 )
...
Signed-off-by: juan131 <jariza@vmware.com >
2023-12-17 10:27:19 +00:00
DmitriyLewen
df49ea4a14
refactor(sbom): disable html escaping for CycloneDX ( #5764 )
2023-12-17 09:25:08 +00:00
DmitriyLewen
f25e2df1c0
refactor(purl): use pub from package-url ( #5784 )
2023-12-13 12:07:31 +00:00
DmitriyLewen
b5e3b77f0f
docs(python): add note to using pip freeze for compatible releases ( #5760 )
2023-12-13 09:39:00 +00:00
DmitriyLewen
6cc00c2f0c
fix(report): use OS information for OS packages purl in github template ( #5783 )
2023-12-13 09:37:14 +00:00
DmitriyLewen
c317fe828d
fix(report): fix error if miconfigs are empty ( #5782 )
2023-12-13 09:34:37 +00:00
DmitriyLewen
9b4bcedf0e
refactor(vuln): don't remove VendorSeverity in JSON report ( #5761 )
2023-12-12 12:33:41 +00:00
DmitriyLewen
be5a550491
fix(report): don't mark misconfig passed tests as failed in junit.tpl ( #5767 )
2023-12-12 12:30:26 +00:00
Veronika Priesner
01edbda347
docs(k8s): replace --scanners config with --scanners misconfig in docs ( #5746 )
2023-12-07 12:12:26 +00:00
Dirk Klimpel
eb9741954c
fix(report): update Gitlab template ( #5721 )
2023-12-07 11:13:43 +00:00
Sourav Patnaik
be1c55497f
feat(secret): add support of GitHub fine-grained tokens ( #5740 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-12-07 10:45:22 +00:00
Nikita Pivkin
a5342da067
fix(misconf): add an image misconf to result ( #5731 )
2023-12-06 07:07:31 +00:00
Sourav Patnaik
108a5b05ce
feat(secret): added support of Docker registry credentials ( #5720 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-12-06 07:04:19 +00:00
dependabot[bot]
6080e245ce
chore(deps): bump github.com/aws/aws-sdk-go-v2/config from 1.18.45 to 1.25.11 ( #5717 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-05 09:38:17 +00:00
dependabot[bot]
e27ec3261e
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ecr from 1.21.0 to 1.24.1 ( #5701 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-05 08:52:06 +00:00
dependabot[bot]
f2aa9bf3eb
chore(deps): bump sigstore/cosign-installer from 4a861528be5e691840a69536975ada1d4c30349d to 1fc5bd396d372bee37d608f955b336615edf79c8 ( #5696 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-05 07:18:38 +00:00
dependabot[bot]
6d7e2f8116
chore(deps): bump helm/chart-testing-action from 2.4.0 to 2.6.1 ( #5694 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-05 07:18:17 +00:00
chenk
0ff5f96bb7
feat: filter k8s core components vuln results ( #5713 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-12-05 07:17:51 +00:00
Andrea Scarpino
a54d1e95fd
feat(vuln): remove duplicates in Fixed Version ( #5596 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-12-04 16:29:14 +00:00
Teppei Fukuda
99c04c4383
feat(report): output plugin ( #4863 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-12-04 11:04:43 +00:00
dependabot[bot]
70078b9c0e
chore(deps): bump alpine from 3.18.4 to 3.18.5 ( #5700 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-04 10:37:26 +00:00
dependabot[bot]
49e83a6ad2
chore(deps): bump github.com/google/go-containerregistry from 0.16.1 to 0.17.0 ( #5704 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-04 10:36:06 +00:00
dependabot[bot]
af32cb310a
chore(deps): bump github.com/go-git/go-git/v5 from 5.8.1 to 5.10.1 ( #5699 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-04 10:32:05 +00:00
dependabot[bot]
176627192f
chore(deps): bump actions/github-script from 6 to 7 ( #5697 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-04 10:29:43 +00:00
dependabot[bot]
7ee854767e
chore(deps): bump easimon/maximize-build-space from 8 to 9 ( #5695 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-04 10:28:13 +00:00
Reo Uehara
654147fc60
docs: typo in modules.md ( #5712 )
2023-12-04 10:25:18 +00:00
chenk
256957523a
feat: Add flag to configure node-collector image ref ( #5710 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-12-04 10:25:12 +00:00
dependabot[bot]
c0610097a6
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azcore from 1.7.1 to 1.9.0 ( #5702 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-04 09:46:51 +00:00
dependabot[bot]
aedbd85d6e
chore(deps): bump github.com/alicebob/miniredis/v2 from 2.30.4 to 2.31.0 ( #5698 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-04 03:38:34 +00:00
dependabot[bot]
e018b9c423
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azidentity from 1.3.1 to 1.4.0 ( #5706 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-04 03:37:58 +00:00
simar7
b5874e3ad3
feat(misconf): Add --misconfig-scanners option ( #5670 )
2023-11-29 23:59:17 +00:00
Teppei Fukuda
075d8f6286
chore: bump Go to 1.21 ( #5662 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-28 04:01:54 +00:00
yuriShafet
16b757d180
feat: Packagesprops support ( #5605 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-11-28 01:23:47 +00:00
simar7
372efc9ec7
chore(deps): Bump up trivy misconf deps ( #5656 )
2023-11-28 00:47:23 +00:00
Anais Urlichs
edad5f6902
docs: update adopters discussion template ( #5632 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2023-11-27 01:29:32 +00:00
Kyle Davies
ed9d34030d
docs: terraform tutorial links updated to point to correct loc ( #5661 )
2023-11-27 01:29:22 +00:00
DmitriyLewen
8ff574e3f7
fix(secret): add sec and space to secret prefix for aws-secret-access-key ( #5647 )
2023-11-26 05:12:06 +00:00
DmitriyLewen
ad977a4256
fix(nodejs): support protocols for dependency section in yarn.lock files ( #5612 )
2023-11-22 01:44:45 +00:00
DmitriyLewen
b1dc60b885
fix(secret): exclude upper case before secret for alibaba-access-key-id ( #5618 )
2023-11-22 01:43:59 +00:00
Felix Yan
65351d4f2a
docs: Update Arch Linux package URL in installation.md ( #5619 )
2023-11-22 01:23:56 +00:00
Teppei Fukuda
c866f1c4e9
chore: add prefix to image errors ( #5601 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-20 12:38:45 +00:00
Tom Janson
ed0022b915
docs(vuln): fix link anchor ( #5606 )
2023-11-20 01:13:27 +00:00
Jeremy Adams
3c81727034
docs: Add Dagger integration section and cleanup Ecosystem CICD docs page ( #5608 )
...
Signed-off-by: Jeremy Adams <jeremy@dagger.io >
2023-11-20 00:54:26 +00:00
chenk
214546427e
fix: k8s friendly error messages kbom non cluster scans ( #5594 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-11-16 06:41:45 +00:00
Sylvain Baubeau
44d0b28ada
feat: set InstalledFiles for DEB and RPM packages ( #5488 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-11-16 06:37:39 +00:00
Teppei Fukuda
ae4bcf6a06
fix(report): use time.Time for CreatedAt ( #5598 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-16 05:42:30 +00:00
Teppei Fukuda
b6fafa04a2
test: retry containerd initialization ( #5597 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-16 04:17:59 +00:00
simar7
13362233c8
feat(misconf): Expose misconf engine debug logs with --debug option ( #5550 )
...
Signed-off-by: Simar <simar@linux.com >
2023-11-16 02:29:38 +00:00
Teppei Fukuda
71051863c6
test: mock VM walker ( #5589 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-16 00:49:38 +00:00
chenk
d9d7f3f190
chore: bump node-collector v0.0.9 ( #5591 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-11-16 00:48:56 +00:00
simar7
e3c28f8ee3
feat(misconf): Add support for --cf-params for CFT ( #5507 )
...
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: nikpivkin <nikita.pivkin@smartforce.io >
2023-11-15 07:04:22 +00:00
Teppei Fukuda
ac0e327492
feat(flag): replace '--slow' with '--parallel' ( #5572 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-15 06:41:13 +00:00
DmitriyLewen
5372067611
fix(report): add escaping for Sarif format ( #5568 )
2023-11-15 04:29:23 +00:00
Teppei Fukuda
a3895298de
chore: show a deprecation notice for --scanners config ( #5587 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-15 04:20:40 +00:00
Y.Horie
f4dd062f58
feat(report): Add CreatedAt to the JSON report. ( #5542 ) ( #5549 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-11-15 04:11:09 +00:00
Teppei Fukuda
d005f5af24
test: mock RPM DB ( #5567 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-15 03:06:49 +00:00
Teppei Fukuda
a96ec35572
feat: add aliases to '--scanners' ( #5558 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-15 00:53:22 +00:00
Teppei Fukuda
950e431f0f
refactor: reintroduce output writer ( #5564 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-14 12:32:23 +00:00
dependabot[bot]
2310f0dd69
chore(deps): bump google.golang.org/grpc from 1.58.2 to 1.58.3 ( #5543 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-14 07:50:00 +00:00
Teppei Fukuda
04b93e9fd6
chore: not load plugins for auto-generating docs ( #5569 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-14 05:37:18 +00:00
Teppei Fukuda
cccaa15ccd
chore: sort supported AWS services ( #5570 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-11-14 05:35:42 +00:00
chenk
3891e3d5d4
fix: no schedule toleration ( #5562 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-11-14 02:42:40 +00:00
DmitriyLewen
138feb024c
fix(cli): set correct scanners for k8s target ( #5561 )
2023-11-13 07:24:22 +00:00
DmitriyLewen
cb241a8007
fix(sbom): add FilesAnalyzed and PackageVerificationCode fields for SPDX ( #5533 )
2023-11-09 09:25:27 +00:00
simar7
e7f6a5c805
refactor(misconf): Update refactored dependencies ( #5245 )
...
Signed-off-by: Simar <simar@linux.com >
2023-11-09 02:24:52 +00:00
very-doge-wow
2f5afa5f29
feat(secret): add built-in rule for JWT tokens ( #5480 )
2023-11-09 01:34:52 +00:00
chenk
91fc8dac92
fix: trivy k8s parse ecr image with arn ( #5537 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-11-09 01:05:45 +00:00
chenk
05df24477e
fix: fail k8s resource scanning ( #5529 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-11-08 05:39:53 +00:00
DmitriyLewen
a1b47441a5
refactor(misconf): don't remove Highlighted in json format ( #5531 )
2023-11-07 23:40:42 +00:00
Tom Janson
7712f8f216
docs(k8s): fix link in kubernetes.md ( #5524 )
2023-11-07 01:18:44 +00:00
Tom Janson
043fbfcd38
docs(k8s): fix whitespace in list syntax ( #5525 )
2023-11-07 00:38:39 +00:00
DmitriyLewen
d6df5fbcda
docs: add info that license scanning supports file-patterns flag ( #5484 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2023-11-06 04:55:08 +00:00
Matheus Moraes
156d4cc605
docs: add Zora integration into Ecosystem session ( #5490 )
2023-11-06 04:54:48 +00:00
DmitriyLewen
772d1d08f8
fix(sbom): Use UUID as BomRef for packages with empty purl ( #5448 )
2023-11-06 03:29:13 +00:00
Nikita Pivkin
df47073fa4
ci: use maximize build space for K8s tests ( #5387 )
2023-11-06 03:25:58 +00:00
Sylvain Baubeau
fed4710188
fix: correct error mismatch causing race in fast walks ( #5516 )
2023-11-06 02:31:12 +00:00
chenk
46f1b9e7dc
docs: k8s vulnerability scanning ( #5515 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-11-06 02:30:07 +00:00
dependabot[bot]
fdb3a15b2d
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/sts from 1.23.2 to 1.25.0 ( #5506 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-03 23:58:20 +00:00
dependabot[bot]
d0d956fdc1
chore(deps): bump github.com/owenrumney/go-sarif/v2 from 2.2.2 to 2.3.0 ( #5493 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-11-03 01:38:04 +00:00
DmitriyLewen
68b0797e5b
docs: remove glad for java datasources ( #5508 )
2023-11-03 01:37:35 +00:00
dependabot[bot]
474167c47e
chore(deps): bump github.com/testcontainers/testcontainers-go/modules/localstack from 0.21.0 to 0.26.0 ( #5475 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-11-03 01:36:27 +00:00
Sylvain Baubeau
7299867c21
chore: remove unused logger attribute in amazon detector ( #5476 )
2023-11-02 04:14:54 +00:00
Sylvain Baubeau
8656bd9f77
fix: correct error mismatch causing race in fast walks ( #5482 )
2023-11-02 04:14:16 +00:00
dependabot[bot]
2e10cd2eba
chore(deps): bump goreleaser/goreleaser-action from 4 to 5 ( #5502 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-02 03:52:43 +00:00
dependabot[bot]
13df746527
chore(deps): bump docker/build-push-action from 4 to 5 ( #5500 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-02 01:55:00 +00:00
dependabot[bot]
b0141cfbaa
chore(deps): bump github.com/package-url/packageurl-go from 0.1.2-0.20230812223828-f8bb31c1f10b to 0.1.2 ( #5491 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-02 01:52:57 +00:00
Nikita Pivkin
520830b51b
fix(server): add licenses to BlobInfo message ( #5382 )
2023-11-02 01:46:32 +00:00
dependabot[bot]
9a6e125c78
chore(deps): bump actions/checkout from 4.1.0 to 4.1.1 ( #5501 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-02 01:09:38 +00:00
dependabot[bot]
6e5927266c
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ecr from 1.17.18 to 1.21.0 ( #5497 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-02 01:09:25 +00:00
chenk
f3de7bc3be
feat: scan vulns on k8s core component apps ( #5418 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-11-01 09:31:48 +00:00
DmitriyLewen
e2fb3dd58f
fix(java): fix infinite loop when relativePath field points to pom.xml being scanned ( #5470 )
2023-10-31 01:47:58 +00:00
dependabot[bot]
3e833be7d8
chore(deps): bump github.com/docker/docker from 24.0.5+incompatible to 24.0.7+incompatible ( #5472 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-31 01:46:24 +00:00
DmitriyLewen
ca50b77a35
fix(sbom): save digests for package/application when scanning SBOM files ( #5432 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-10-28 04:09:36 +00:00
Takahiro Tsuruda
048150d433
docs: fix the broken link ( #5454 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-10-28 04:06:11 +00:00
DmitriyLewen
013d901993
docs: fix error when installing PyYAML for gh pages ( #5462 )
2023-10-28 03:32:13 +00:00
DmitriyLewen
26b4959541
fix(java): download java-db once ( #5442 )
2023-10-26 01:50:32 +00:00
dependabot[bot]
57fa701a87
chore(deps): bump google.golang.org/grpc from 1.57.0 to 1.57.1 ( #5447 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-26 00:42:55 +00:00
simar7
53c9a7d762
docs(misconf): Update --tf-exclude-downloaded-modules description ( #5419 )
2023-10-24 13:03:02 +00:00
simar7
01c98d1516
feat(misconf): Support --ignore-policy in config scans ( #5359 )
...
Signed-off-by: Simar <simar@linux.com >
2023-10-23 07:32:08 +00:00
yoshinorin
05b3c86a14
docs(misconf): fix broken table for Use container image section ( #5425 )
2023-10-23 06:10:39 +00:00
DmitriyLewen
1a15a3adb1
feat(dart): add graph support ( #5374 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-10-20 09:16:23 +00:00
Teppei Fukuda
f2a12f5f90
refactor: define a new struct for scan targets ( #5397 )
2023-10-20 01:43:15 +00:00
DmitriyLewen
6040d9f43a
fix(sbom): add missed primaryURL and source severity for CycloneDX ( #5399 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-10-19 05:37:32 +00:00
Erick Redwine
e5317c7bc2
fix: correct invalid MD5 hashes for rpms ending with one or more zero bytes ( #5393 )
2023-10-19 03:29:54 +00:00
Sylvain Baubeau
9fba79f0b6
chore(deps): move to aws-sdk-go-v2 ( #5381 )
2023-10-18 14:21:56 +00:00
Nikita Pivkin
00f2059e5d
docs: remove --scanners none ( #5384 )
2023-10-17 02:34:30 +00:00
mehrdadbn9
57a1022318
docs: Update container_image.md #5182 ( #5193 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2023-10-16 06:22:33 +00:00
AliDatadog
5b2b4ea380
feat(report): Add InstalledFiles field to Package ( #4706 )
...
Co-authored-by: Sylvain Baubeau <lebauce@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-10-16 06:15:23 +00:00
Teppei Fukuda
cbbd1ce1f0
feat(k8s): add support for vulnerability detection ( #5268 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Signed-off-by: chenk <hen.keinan@gmail.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
Co-authored-by: chenk <hen.keinan@gmail.com >
2023-10-14 12:32:55 +00:00
DmitriyLewen
24a0d92145
fix(python): override BOM in requirements.txt files ( #5375 )
2023-10-14 08:37:32 +00:00
Itay Shakury
0c3e2f08b7
docs: add kbom documentation ( #5363 )
2023-10-13 09:00:28 +00:00
DmitriyLewen
6c12f04286
test: use maximize build space for VM tests ( #5362 )
2023-10-13 01:42:57 +00:00
dependabot[bot]
c4134224a2
chore(deps): bump golang.org/x/net from 0.15.0 to 0.17.0 ( #5365 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-12 15:45:22 +00:00
DmitriyLewen
20ab7033b8
fix(report): add escaping quotes in misconfig Title for asff template ( #5351 )
2023-10-11 07:38:07 +00:00
DmitriyLewen
91841f59ba
ci: add workflow to check Go versions of dependencies ( #5340 )
2023-10-09 11:04:09 +00:00
simar7
57ba05c766
chore(deps): Upgrade defsec to v0.93.1 ( #5348 )
2023-10-08 12:40:21 +00:00
dependabot[bot]
fef3ed4358
chore(deps): bump alpine from 3.18.3 to 3.18.4 ( #5300 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-06 06:07:11 +00:00
Doug Donohoe
ced54aced1
fix: Report error when os.CreateTemp fails (to be consistent with other uses) ( #5342 )
2023-10-05 14:45:45 +00:00
Nikita Pivkin
2798df916b
fix: add config files to FS for post-analyzers ( #5333 )
2023-10-05 12:59:47 +00:00
DmitriyLewen
af485b33fd
fix: fix MIME warnings after updating to Go 1.20 ( #5336 )
2023-10-05 12:58:40 +00:00
Teppei Fukuda
008babfb8b
build: fix a compile error with Go 1.21 ( #5339 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-10-05 10:06:32 +00:00
Alexandr Hacicheant
00d9c4666f
feat: added Metadata into the k8s resource's scan report ( #5322 )
2023-10-05 08:16:50 +00:00
DmitriyLewen
03b6787c44
ci: check only PR's in actions/stale ( #5337 )
2023-10-05 07:36:02 +00:00
Itay Shakury
e6d5889ed4
chore: update adopters template ( #5330 )
2023-10-04 12:13:20 +00:00
Teppei Fukuda
74dbd8a1fd
ci: do not trigger tests on the push event ( #5313 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-10-03 11:10:05 +00:00
j1nka
393bfdc1ac
fix(sbom): use PURL or Group and Name in case of Java ( #5154 )
2023-10-03 11:06:27 +00:00
Anais Urlichs
76eb8a57b6
docs: add buildkite repository to ecosystem page ( #5316 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2023-10-03 09:02:52 +00:00
dependabot[bot]
6c74ee11f0
chore(deps): bump docker/setup-qemu-action from 2 to 3 ( #5290 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-03 09:01:37 +00:00
dependabot[bot]
6119878de1
chore(deps): bump docker/setup-buildx-action from 2 to 3 ( #5292 )
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-03 08:25:12 +00:00
dependabot[bot]
a346587b8d
chore(deps): bump actions/cache from 3.3.1 to 3.3.2 ( #5293 )
...
Bumps [actions/cache](https://github.com/actions/cache ) from 3.3.1 to 3.3.2.
- [Release notes](https://github.com/actions/cache/releases )
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md )
- [Commits](https://github.com/actions/cache/compare/v3.3.1...v3.3.2 )
---
updated-dependencies:
- dependency-name: actions/cache
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 15:54:49 +00:00
dependabot[bot]
7e613cc5f7
chore(deps): bump github.com/google/uuid from 1.3.0 to 1.3.1 ( #5286 )
...
Bumps [github.com/google/uuid](https://github.com/google/uuid ) from 1.3.0 to 1.3.1.
- [Release notes](https://github.com/google/uuid/releases )
- [Changelog](https://github.com/google/uuid/blob/master/CHANGELOG.md )
- [Commits](https://github.com/google/uuid/compare/v1.3.0...v1.3.1 )
---
updated-dependencies:
- dependency-name: github.com/google/uuid
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 15:45:32 +00:00
dependabot[bot]
f05bc4be4f
chore(deps): bump github.com/hashicorp/go-getter from 1.7.1 to 1.7.2 ( #5289 )
...
Bumps [github.com/hashicorp/go-getter](https://github.com/hashicorp/go-getter ) from 1.7.1 to 1.7.2.
- [Release notes](https://github.com/hashicorp/go-getter/releases )
- [Changelog](https://github.com/hashicorp/go-getter/blob/main/.goreleaser.yml )
- [Commits](https://github.com/hashicorp/go-getter/compare/v1.7.1...v1.7.2 )
---
updated-dependencies:
- dependency-name: github.com/hashicorp/go-getter
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 15:45:07 +00:00
Teppei Fukuda
3be5e6b242
chore: enable go-critic ( #5302 )
...
* chore: enable gocritic
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* refactor: fix lint issues
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* test: return true for latest versions
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* chore(lint): enforce map and slice styles
Signed-off-by: knqyf263 <knqyf263@gmail.com >
---------
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-10-02 08:33:21 +00:00
dependabot[bot]
f6cd21c873
chore(deps): bump actions/checkout from 3.6.0 to 4.1.0 ( #5288 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 3.6.0 to 4.1.0.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v3.6.0...v4.1.0 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 08:31:07 +00:00
dependabot[bot]
f7b975187d
chore(deps): bump github.com/aws/aws-sdk-go from 1.45.3 to 1.45.19 ( #5287 )
...
Bumps [github.com/aws/aws-sdk-go](https://github.com/aws/aws-sdk-go ) from 1.45.3 to 1.45.19.
- [Release notes](https://github.com/aws/aws-sdk-go/releases )
- [Commits](https://github.com/aws/aws-sdk-go/compare/v1.45.3...v1.45.19 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 07:35:19 +00:00
DmitriyLewen
18d168769c
close java-db client ( #5273 )
2023-10-02 06:56:33 +00:00
dependabot[bot]
eb60e9f3c0
chore(deps): bump docker/login-action from 2 to 3 ( #5291 )
...
Bumps [docker/login-action](https://github.com/docker/login-action ) from 2 to 3.
- [Release notes](https://github.com/docker/login-action/releases )
- [Commits](https://github.com/docker/login-action/compare/v2...v3 )
---
updated-dependencies:
- dependency-name: docker/login-action
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 05:20:14 +00:00
dependabot[bot]
5a92055e1c
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/sts ( #5294 )
...
Bumps [github.com/aws/aws-sdk-go-v2/service/sts](https://github.com/aws/aws-sdk-go-v2 ) from 1.21.5 to 1.22.0.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/service/s3/v1.22.0/CHANGELOG.md )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/service/efs/v1.21.5...service/s3/v1.22.0 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/service/sts
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 05:19:08 +00:00
dependabot[bot]
46afe65eed
chore(deps): bump github.com/sigstore/rekor from 1.2.1 to 1.3.0 ( #5304 )
...
Bumps [github.com/sigstore/rekor](https://github.com/sigstore/rekor ) from 1.2.1 to 1.3.0.
- [Release notes](https://github.com/sigstore/rekor/releases )
- [Changelog](https://github.com/sigstore/rekor/blob/main/CHANGELOG.md )
- [Commits](https://github.com/sigstore/rekor/compare/v1.2.1...v1.3.0 )
---
updated-dependencies:
- dependency-name: github.com/sigstore/rekor
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 05:18:49 +00:00
dependabot[bot]
0bf2a11a2e
chore(deps): bump github.com/opencontainers/image-spec ( #5295 )
...
Bumps [github.com/opencontainers/image-spec](https://github.com/opencontainers/image-spec ) from 1.1.0-rc4 to 1.1.0-rc5.
- [Release notes](https://github.com/opencontainers/image-spec/releases )
- [Changelog](https://github.com/opencontainers/image-spec/blob/main/RELEASES.md )
- [Commits](https://github.com/opencontainers/image-spec/compare/v1.1.0-rc4...v1.1.0-rc5 )
---
updated-dependencies:
- dependency-name: github.com/opencontainers/image-spec
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-02 05:18:09 +00:00
Ignacio Íñigo Hernández
23b5fece08
fix(report): removes git::http from uri in sarif ( #5244 )
...
* fix(sarif): removes git::http from uri in sarif
* fix(sarif): removes git::http from uri in sarif
## Description
## Related issues
- Fixes https://github.com/aquasecurity/trivy/issues/5003
## Checklist
- [ ] I've read the [guidelines for contributing](https://aquasecurity.github.io/trivy/latest/community/contribute/pr/ ) to this repository.
- [ ] I've followed the [conventions](https://aquasecurity.github.io/trivy/latest/community/contribute/pr/#title ) in the PR title.
- [ ] I've added tests that prove my fix is effective or that my feature works.
- [ ] I've updated the [documentation](https://github.com/aquasecurity/trivy/blob/main/docs ) with the relevant information (if needed).
- [ ] I've added usage information (if the PR introduces new options)
- [ ] I've included a "before" and "after" example to the description (if the PR is a user interface change).
* fix lint
---------
Co-authored-by: Simar <simar@linux.com >
2023-10-02 05:17:43 +00:00
PranitRout07
4f1d576e5a
Improve the meaning of sentence ( #5301 )
...
Sentence has incomplete meaning .
Go to this link to see the issue: https://aquasecurity.github.io/trivy/v0.45/tutorials/kubernetes/gitops/
2023-10-01 18:13:12 +00:00
dependabot[bot]
6ab2bdfa7c
chore(deps): bump github.com/owenrumney/go-sarif/v2 from 2.2.0 to 2.2.2 ( #5297 )
...
Bumps [github.com/owenrumney/go-sarif/v2](https://github.com/owenrumney/go-sarif ) from 2.2.0 to 2.2.2.
- [Release notes](https://github.com/owenrumney/go-sarif/releases )
- [Changelog](https://github.com/owenrumney/go-sarif/blob/main/.goreleaser.yml )
- [Commits](https://github.com/owenrumney/go-sarif/compare/v2.2.0...v2.2.2 )
---
updated-dependencies:
- dependency-name: github.com/owenrumney/go-sarif/v2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-01 17:43:34 +00:00
dependabot[bot]
4217cffb5a
chore(deps): bump golang.org/x/term from 0.11.0 to 0.12.0 ( #5296 )
...
Bumps [golang.org/x/term](https://github.com/golang/term ) from 0.11.0 to 0.12.0.
- [Commits](https://github.com/golang/term/compare/v0.11.0...v0.12.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/term
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-10-01 17:30:33 +00:00
DmitriyLewen
1840584703
add app nil check ( #5274 )
2023-10-01 07:36:59 +00:00
Erik McKelvey
c5ae9f265f
typo: in secret.md ( #5281 )
2023-10-01 07:27:47 +00:00
DmitriyLewen
562723f0a7
docs: add info about github format ( #5265 )
...
* docs: add info about github format
* rename `GitHub SBOM` to `GitHub dependency snapshots`
2023-09-28 18:40:45 +00:00
DmitriyLewen
3dd5b1e946
feat(dotnet): add license support for NuGet ( #5217 )
...
* add nuspec files support
* docs: docs, log messages, comments refactoring
* save found licences to use next time
* refactor
* refactor
* fix typo
2023-09-28 08:13:31 +00:00
Itay Shakury
5c18475f37
docs: correctly export variables ( #5260 )
...
missing = in variable definition
2023-09-28 07:15:48 +00:00
simar7
0c08dde015
chore: Add line numbers for lint output ( #5247 )
...
* fix(github): Add line numbers for lint output
* correctional message check
* update messaging
2023-09-28 07:12:47 +00:00
DmitriyLewen
0ccbb4f7fd
chore(cli): disable java-db flags in server mode ( #5263 )
...
* disable java-db flag for server mode
* update docs
2023-09-28 07:10:14 +00:00
Michel Meyer
908a4914c7
feat(db): allow passing registry options ( #5226 )
...
* feat(db): allow passing registry options
Signed-off-by: Michel Meyer <meyer_michel@outlook.com >
* feat(db): pass cli registry options to javaDB
---------
Signed-off-by: Michel Meyer <meyer_michel@outlook.com >
2023-09-27 13:17:11 +00:00
simar7
5b4652d796
chore(deps): Bump up defsec to v0.93.0 ( #5253 )
2023-09-27 06:43:55 +00:00
DmitriyLewen
faf8d49c49
refactor(purl): use TypeApk from purl ( #5232 )
...
* use TypeApk from purl
* refactor: some tweaks
Signed-off-by: knqyf263 <knqyf263@gmail.com >
---------
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-09-26 08:55:23 +00:00
DmitriyLewen
559c0f30b1
chore: enable more linters ( #5228 )
...
* chore: enable more linters
* fix typos
* ci: add `verbose` option in linter action
* ci: remove `verbose` option in linter action
2023-09-26 06:20:54 +00:00
Nikita Pivkin
2baad46189
ci: bump GoReleaser from 1.16.2 to 1.20.0 ( #5236 )
...
* chore: replace brews.tap with brews.repository
* ci: bump GoReleaser from 1.16.2 to 1.20.0
2023-09-25 19:08:53 +00:00
za
df2bff9f5e
Fix typo on ide.md ( #5239 )
...
mange -> manage.
2023-09-25 19:05:22 +00:00
Teppei Fukuda
44656f2853
refactor: use defined types ( #5225 )
...
* refactor: replace string with defined types
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* chore: add gci
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* fix(purl): not confuse trivy type with purl type
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* test: fix cyclonedx fixture
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* fix(template): cast TargetType to string
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* chore: bump TinyGo to v0.29.0
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* test: change license to licence
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* use `analyzer.TypeGoMod` for gomod analyzer
* ignore `licence` for misspell linter
---------
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-09-22 10:44:39 +00:00
Javier Freire Riobó
37af529947
fix(purl): skip local Go packages ( #5190 )
...
* fix(purl): trim a final slash
* fix(purl): skip local Go packages
* fix(purl): a few improvements
2023-09-20 14:19:21 +00:00
Nikita Pivkin
eea3320d83
docs: update info about license scanning in Yarn projects ( #5207 )
2023-09-19 06:24:11 +00:00
DmitriyLewen
2e6662060e
ci: auto apply labels ( #5200 )
...
* add label for mage file. Create workflow.
* fix typo
* setup go and aqua tools
* set fetch-depth == 1
2023-09-18 13:51:12 +00:00
DmitriyLewen
49680dc881
fix link ( #5203 )
2023-09-18 08:07:56 +00:00
Paternity Leave
daae88287b
fix(purl): handle rust types ( #5186 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-09-15 20:58:10 +00:00
Paternity Leave
81240cf080
chore: auto-close issues ( #5177 )
...
* chore: auto close issues
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* chore: add state_reason
* docs: add a warning message about issues
Signed-off-by: knqyf263 <knqyf263@gmail.com >
---------
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-09-14 06:19:59 +00:00
dependabot[bot]
bd0accd8a0
chore(deps): bump github.com/spf13/viper from 1.15.0 to 1.16.0 ( #5093 )
...
Bumps [github.com/spf13/viper](https://github.com/spf13/viper ) from 1.15.0 to 1.16.0.
- [Release notes](https://github.com/spf13/viper/releases )
- [Commits](https://github.com/spf13/viper/compare/v1.15.0...v1.16.0 )
---
updated-dependencies:
- dependency-name: github.com/spf13/viper
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-14 06:17:08 +00:00
chenk
ecee79403e
fix(k8s): kbom support addons labels ( #5178 )
...
* feat: kbom support addons label
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kbom support addons label
Signed-off-by: chenk <hen.keinan@gmail.com >
---------
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-09-14 06:12:48 +00:00
Nikita Pivkin
9ebc25d88b
test: validate SPDX with the JSON schema ( #5124 )
...
* test: validate SPDX with the JSON schema
* use the SPDX schema version based on the document version
* additionally validate the document using spdx
2023-09-14 06:10:09 +00:00
chenk
9a49a37737
chore: bump trivy-kubernetes-latest ( #5161 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-09-12 07:21:44 +00:00
Nikita Pivkin
ad1dc6327a
docs: add 'Signature Verification' guide ( #4731 )
...
* add 'Signature Verification' guide
* add gpg signature verification doc
---------
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-09-12 06:57:40 +00:00
k.goto
7c68d4a7ec
docs: add image-scanner-with-trivy for ecosystem ( #5159 )
2023-09-11 09:18:56 +00:00
Katsuya Miyachi
ed49609a73
fix(fs): assign the absolute path to be inspected to ROOTPATH when filesystem ( #5158 )
2023-09-10 15:08:09 +00:00
dependabot[bot]
19539722e0
chore(deps): bump github.com/CycloneDX/cyclonedx-go ( #5102 )
...
Bumps [github.com/CycloneDX/cyclonedx-go](https://github.com/CycloneDX/cyclonedx-go ) from 0.7.2-0.20230625092137-07e2f29defc3 to 0.7.2.
- [Release notes](https://github.com/CycloneDX/cyclonedx-go/releases )
- [Changelog](https://github.com/CycloneDX/cyclonedx-go/blob/master/.goreleaser.yml )
- [Commits](https://github.com/CycloneDX/cyclonedx-go/commits/v0.7.2 )
---
updated-dependencies:
- dependency-name: github.com/CycloneDX/cyclonedx-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-10 12:57:56 +00:00
Srishanth
c7516011b5
Update filtering.md ( #5131 )
2023-09-10 08:52:19 +00:00
dependabot[bot]
ccc6d7cb2c
chore(deps): bump sigstore/cosign-installer ( #5104 )
...
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer ) from a5d81fb6bdbcbb3d239e864d6552820420254494 to 4a861528be5e691840a69536975ada1d4c30349d.
- [Release notes](https://github.com/sigstore/cosign-installer/releases )
- [Commits](a5d81fb6bd...4a861528be )
---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-08 14:04:16 +00:00
dependabot[bot]
48cbf45534
chore(deps): bump github.com/cyphar/filepath-securejoin ( #5143 )
...
Bumps [github.com/cyphar/filepath-securejoin](https://github.com/cyphar/filepath-securejoin ) from 0.2.3 to 0.2.4.
- [Release notes](https://github.com/cyphar/filepath-securejoin/releases )
- [Commits](https://github.com/cyphar/filepath-securejoin/compare/v0.2.3...v0.2.4 )
---
updated-dependencies:
- dependency-name: github.com/cyphar/filepath-securejoin
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-08 13:47:33 +00:00
dependabot[bot]
a9c2c74c55
chore(deps): bump golangci/golangci-lint-action from 3.6.0 to 3.7.0 ( #5103 )
...
Bumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action ) from 3.6.0 to 3.7.0.
- [Release notes](https://github.com/golangci/golangci-lint-action/releases )
- [Commits](https://github.com/golangci/golangci-lint-action/compare/v3.6.0...v3.7.0 )
---
updated-dependencies:
- dependency-name: golangci/golangci-lint-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-07 20:17:29 +00:00
dependabot[bot]
120ac68b5b
chore(deps): bump easimon/maximize-build-space from 7 to 8 ( #5105 )
...
Bumps [easimon/maximize-build-space](https://github.com/easimon/maximize-build-space ) from 7 to 8.
- [Release notes](https://github.com/easimon/maximize-build-space/releases )
- [Changelog](https://github.com/easimon/maximize-build-space/blob/master/CHANGELOG.md )
- [Commits](https://github.com/easimon/maximize-build-space/compare/v7...v8 )
---
updated-dependencies:
- dependency-name: easimon/maximize-build-space
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-07 20:16:13 +00:00
dependabot[bot]
41eaa78ae0
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.273 to 1.45.3 ( #5126 )
...
Bumps [github.com/aws/aws-sdk-go](https://github.com/aws/aws-sdk-go ) from 1.44.273 to 1.45.3.
- [Release notes](https://github.com/aws/aws-sdk-go/releases )
- [Commits](https://github.com/aws/aws-sdk-go/compare/v1.44.273...v1.45.3 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-06 11:09:44 +00:00
Anais Urlichs
932f927555
chaging adopters discussion tempalte ( #5091 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2023-09-05 20:55:25 +00:00
dependabot[bot]
db3133346a
chore(deps): bump github.com/cheggaaa/pb/v3 from 3.1.2 to 3.1.4 ( #5092 )
...
Bumps [github.com/cheggaaa/pb/v3](https://github.com/cheggaaa/pb ) from 3.1.2 to 3.1.4.
- [Commits](https://github.com/cheggaaa/pb/compare/v3.1.2...v3.1.4 )
---
updated-dependencies:
- dependency-name: github.com/cheggaaa/pb/v3
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-05 20:50:58 +00:00
dependabot[bot]
8c0b7d619c
chore(deps): bump github.com/hashicorp/golang-lru/v2 from 2.0.2 to 2.0.6 ( #5094 )
...
Bumps [github.com/hashicorp/golang-lru/v2](https://github.com/hashicorp/golang-lru ) from 2.0.2 to 2.0.6.
- [Release notes](https://github.com/hashicorp/golang-lru/releases )
- [Commits](https://github.com/hashicorp/golang-lru/compare/v2.0.2...v2.0.6 )
---
updated-dependencies:
- dependency-name: github.com/hashicorp/golang-lru/v2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-05 07:23:20 +00:00
dependabot[bot]
c61c664c30
chore(deps): bump github.com/aws/aws-sdk-go-v2/config ( #5095 )
...
Bumps [github.com/aws/aws-sdk-go-v2/config](https://github.com/aws/aws-sdk-go-v2 ) from 1.18.25 to 1.18.38.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/config/v1.18.25...config/v1.18.38 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/config
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-05 07:21:05 +00:00
dependabot[bot]
a99944c1c2
chore(deps): bump github.com/containerd/containerd from 1.7.3 to 1.7.5 ( #5097 )
...
Bumps [github.com/containerd/containerd](https://github.com/containerd/containerd ) from 1.7.3 to 1.7.5.
- [Release notes](https://github.com/containerd/containerd/releases )
- [Changelog](https://github.com/containerd/containerd/blob/main/RELEASES.md )
- [Commits](https://github.com/containerd/containerd/compare/v1.7.3...v1.7.5 )
---
updated-dependencies:
- dependency-name: github.com/containerd/containerd
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-05 07:19:50 +00:00
dependabot[bot]
9fc844ecfc
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azidentity ( #5098 )
...
Bumps [github.com/Azure/azure-sdk-for-go/sdk/azidentity](https://github.com/Azure/azure-sdk-for-go ) from 1.3.0 to 1.3.1.
- [Release notes](https://github.com/Azure/azure-sdk-for-go/releases )
- [Changelog](https://github.com/Azure/azure-sdk-for-go/blob/main/documentation/release.md )
- [Commits](https://github.com/Azure/azure-sdk-for-go/compare/sdk/azcore/v1.3.0...sdk/azcore/v1.3.1 )
---
updated-dependencies:
- dependency-name: github.com/Azure/azure-sdk-for-go/sdk/azidentity
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-05 07:18:15 +00:00
dependabot[bot]
c504f8be44
chore(deps): bump actions/checkout from 3.5.3 to 3.6.0 ( #5106 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 3.5.3 to 3.6.0.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v3.5.3...v3.6.0 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-09-01 18:42:12 +00:00
Teppei Fukuda
cdab67e7fa
docs: add Bitnami ( #5078 )
...
* docs: add Bitnami
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* docs: add a Debian link
Signed-off-by: knqyf263 <knqyf263@gmail.com >
---------
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-09-01 04:29:05 +00:00
Juan Ariza Toledano
7acc5e8312
feat(docker): add support for scanning Bitnami components ( #5062 )
...
* feat(bitnami): add support for scanning Bitnami components
Signed-off-by: juan131 <jariza@vmware.com >
* chore(deps): bump packageurl-go
TypeBitnami is not included in v0.1.1
* feat(spdx): handle orphan packages
* fix: update Elastic SPDX
Signed-off-by: juan131 <jariza@vmware.com >
* Update pkg/fanal/analyzer/sbom/sbom.go
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
* fix: remove useless else
Signed-off-by: juan131 <jariza@vmware.com >
* call AnalysisResult.Sort()
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* delete app packages
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* fix: set the component path to packages
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* docs: add a comment about continue
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* chore: bump trivy-db
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* docs: add Bitnami
Signed-off-by: knqyf263 <knqyf263@gmail.com >
---------
Signed-off-by: juan131 <jariza@vmware.com >
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
2023-08-31 20:18:05 +00:00
Teppei Fukuda
9628b1cbf3
feat: add support for .trivyignore.yaml ( #5070 )
...
* feat: add support for .trivyignore.yaml
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* add test for trivyignore.yaml
* Add doublestar support
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* go mod tidy
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* update docs
* test: fix
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* fix: load .trivyignore once
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* feat: add a debug log
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* docs: add a table for fields
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* fix: skip empty results
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* revert the change
Signed-off-by: knqyf263 <knqyf263@gmail.com >
---------
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-08-31 11:53:37 +00:00
Nikita Pivkin
4547e27666
fix(terraform): improve detection of terraform files ( #4984 )
...
* fix(terraform): improve detection of terraform files
* update defsec
---------
Co-authored-by: Simar <simar@linux.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-08-31 10:47:06 +00:00
Bishwa Thapa
0c8919e1e4
feat: filter artifacts on --exclude-owned flag ( #5059 )
...
* feat: filter artifacts on --exclude-owned flag
- filter artifacts using trivy-kubernetes library
- upgrade dependencies
- generate docs
* chore: remove shorthand flag for --exclude-owned flag
2023-08-31 10:17:52 +00:00
DmitriyLewen
c04f234fa4
fix(sbom): cyclonedx advisory should omit null value ( #5041 )
...
* return nil for advisories, if len of refs == 0
add marshal test
* add integration test for cyclonedx with vulns
* use existing testcase
* test(pom): add ID for cyclondedx integration golden file
* test(integration): add sorting cyclonedx vulns
2023-08-31 10:16:34 +00:00
Teppei Fukuda
f811ed2d48
build: maximize build space for build tests ( #5072 )
...
* build: maximize build space for build tests
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* only for Linux
Signed-off-by: knqyf263 <knqyf263@gmail.com >
* maximize first
Signed-off-by: knqyf263 <knqyf263@gmail.com >
---------
Signed-off-by: knqyf263 <knqyf263@gmail.com >
2023-08-31 09:02:18 +00:00
chenk
69ea5bf70e
feat: improve kbom component name ( #5058 )
...
* feat: improve component name - merge
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: improve component name
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: improve component name
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: improve component name
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: improve component name
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: improve component name
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: improve component name
Signed-off-by: chenk <hen.keinan@gmail.com >
---------
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-08-31 07:35:47 +00:00
DmitriyLewen
3715dcb3f4
fix(pom): add licenses for pom artifacts ( #5071 )
2023-08-31 06:41:35 +00:00
simar7
07f7e9853b
chore(deps): Update defsec to v0.92.0 ( #5068 )
...
* chore(deps): Update defsec to v0.92.0
* update tests
* update integration tests
2023-08-30 20:43:08 +00:00
DmitriyLewen
d4ca3cce21
chore: bump Go to 1.20 ( #5067 )
...
* update go.mod, linter, protoc dockerfile
* bump go version in .golangci.yaml
2023-08-30 10:22:33 +00:00
Teppei Fukuda
49fdd584ba
feat: PURL matching with qualifiers in OpenVEX ( #5061 )
...
* feat: PURL match in OpenVEX
* test: fix fixture
* Update docs/docs/supply-chain/vex.md
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
* docs: add a comment about overriding statements
---------
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
2023-08-30 07:48:32 +00:00
DmitriyLewen
4401998ec1
feat(java): add graph support for pom.xml ( #4902 )
...
* add graph support
* update docs
* bump go-dep-parser
* remove replace for go-dep-parser
* update docs
2023-08-30 06:56:41 +00:00
DmitriyLewen
9c211d005d
feat(swift): add vulns for cocoapods ( #5037 )
...
* add vulns for cocoapods, fix purl
* update docs
* remove go-dep-parser replace
* update purl and test
* bump github.com/DmitriyLewen/trivy-db
* remove replace for trivy-db
* remove added sbom tests
* add test for Package() func
* add wrong epoch test
* refactor docs
* add comment to join the module and submodule in purl
* docs: add an example
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-08-29 12:46:49 +00:00
chenk
422fa414e8
fix: support image pull secret for additional workloads ( #5052 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-08-29 06:33:31 +00:00
Jan Mosig
8e933860a3
fix : #5033 Superfluous double quote in html.tpl ( #5036 )
2023-08-28 12:20:02 +00:00
Florian Bufler
9345a98ed1
docs(repo): update trivy repo usage and example ( #5049 )
2023-08-28 08:46:39 +00:00
Leke Ariyo
5d8da70c62
perf: Optimize Dockerfile for reduced layers and size ( #5038 )
...
* Optimize Dockerfile for reduced layers and size
* Optimize Dockerfile for clarity and efficiency without compromising debuggability
2023-08-27 07:52:02 +00:00
Bishwa Thapa
1be9da7aae
feat: scan K8s Resources Kind with --all-namespaces ( #5043 )
2023-08-27 07:38:45 +00:00
guangwu
0e17d0befc
fix: vulnerability typo ( #5044 )
...
Signed-off-by: guoguangwu <guoguangwu@magic-shield.com >
2023-08-27 07:12:11 +00:00
Anais Urlichs
d70fab2318
docs: adding a terraform tutorial to the docs ( #3708 )
...
* adding a terraform tutorial to the docs
* modifying Terraform tutorial
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
* changes to the terraform tutorial in accoradance with the feedback
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
* updates to the terraform tutorial based on PR feedback
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
---------
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2023-08-27 07:08:51 +00:00
Nikita Pivkin
2fa264ac1e
feat(report): add licenses to sarif format ( #4866 )
...
* feat(report): add licenses to sarif format
* update doc
2023-08-23 11:56:08 +00:00
Nikita Pivkin
07ddf47905
feat(misconf): show the resource name in the report ( #4806 )
...
* feat(misconf): show the resource name in the report
* fix typo
* use a loop instead of lo.Map
* add test
2023-08-23 11:54:08 +00:00
Jonathan Lopez Torres
9de360623a
chore: update alpine base images ( #5015 )
2023-08-23 11:53:31 +00:00
DmitriyLewen
ef70d20766
feat: add Package.resolved swift files support ( #4932 )
...
* add Package.resolved files analyzer
* add Swift detector and integration test
* refactor after go-dep-parser changes
* bump go-dep-parser
* remove replaces
* use filePath for Required func
* add ID field
2023-08-23 11:23:50 +00:00
Nikita Pivkin
ec5d8bec0d
feat(nodejs): parse licenses in yarn projects ( #4652 )
...
* feat(nodejs): parse licenses in yarn projects
* close the zip file
* use fsutils.WalkDir
* refactor: extract traverseFunc
* update tests
* update required
* improve required fn
* handle error
* fix required
* fix required
* fix required
* update test
* fix after review
* simplify test data
* fix path
* rename fn
* update docs
* update docs
* simplify required fn
* skip an empty license
* improve required
* improve required
* update golden
* classify license file
* fix path
* fix path
* improve license parsing from cache
* classify the license file from zip
* refactor
* refactor
* fix lint
* fix after review
* fix test
* mv files
* mv files
* fix dbg message
* refactor: use zip.Reader as fs.FS
* refactor: pass io.Reader
* refactor: use fs.Sub
* refactor: add a struct for license traversing
* refactor: use lo.Some
* feat: bump the yarn analyzer version
* go mod tidy
* fix: sort imports
* use multierror
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-08-23 06:35:54 +00:00
chenk
3114c87e60
fix: k8s private registries support ( #5021 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-08-21 12:00:04 +00:00
DmitriyLewen
6d79f55db9
bump github.com/testcontainers/testcontainers-go from 0.21.0 to 0.23.0 ( #5018 )
2023-08-21 09:16:56 +00:00
Nikita Pivkin
9ace59106e
feat(vuln): support last_affected field from osv ( #4944 )
...
* feat(vuln): support last_affected field from osv
* run go mod tidy
* bump trivy-db
2023-08-20 16:08:56 +00:00
Nikita Pivkin
d442176405
feat(server): add version endpoint ( #4869 )
...
* feat(server): add version endpoint
* fix panic and test
* move version.go
* move version variable
* add docs about endpoints
* move testdata
* refactor
* update build command
* refactor
2023-08-20 06:12:31 +00:00
chenk
63cd41d20d
feat: k8s private registries support ( #4987 )
...
* feat: k8s private registries support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: k8s private registries support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: k8s private registries support
Signed-off-by: chenk <hen.keinan@gmail.com >
* fix: add non empty credential update
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: k8s private registries support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: k8s private registries support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: k8s private registries support
Signed-off-by: chenk <hen.keinan@gmail.com >
---------
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-08-20 06:07:30 +00:00
rlubetkin
cb16e23f14
fix(server): add indirect prop to package ( #4974 )
...
* fix(server): add indirect prop to package
* fix(server): fix test
2023-08-17 08:57:20 +00:00
Teppei Fukuda
a4e981b4ec
docs: add coverage ( #4954 )
...
* docs: add coverage
* add more pages
* add dart, dotnet, elixir languages.
* add C, ruby, cocoapods. Update links
* rename headers for dart and elixir
* docs: add Google Distroless and Photon OS
* docs: add IaC
* docs: put vulnerability into a single page
* fixed broken links
* docs: add coverage overview
* update some links
* add note about arch for Rocky linux
* docs: fix typo
* fix typo
* docs: add footnotes
* docs: add a link to coverage in the license section
* docs: add a conversion table
* docs: get aligned
---------
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-08-17 08:00:34 +00:00
DmitriyLewen
6f03c79405
feat(c): add location for lock file dependencies. ( #4994 )
...
* add location for conan lock files
* bump go-dep-parser
* go mod tidy
2023-08-16 11:34:03 +00:00
Anais Urlichs
c74870500a
docs: adding blog post on ec2 ( #4813 )
...
* adding blog post on ec2
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
* update title of section
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
* changing the location of the article to be under Vulnerabilities
---------
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2023-08-13 07:40:08 +00:00
DmitriyLewen
4e1316c37f
revert 32bit bins ( #4977 )
2023-08-13 07:32:08 +00:00
dependabot[bot]
fc959fc57f
chore(deps): bump github.com/xlab/treeprint from 1.1.0 to 1.2.0 ( #4917 )
...
Bumps [github.com/xlab/treeprint](https://github.com/xlab/treeprint ) from 1.1.0 to 1.2.0.
- [Release notes](https://github.com/xlab/treeprint/releases )
- [Commits](https://github.com/xlab/treeprint/compare/v1.1.0...v1.2.0 )
---
updated-dependencies:
- dependency-name: github.com/xlab/treeprint
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-10 08:21:41 +00:00
DmitriyLewen
f105279989
fix(report): return severity colors in table format ( #4969 )
...
* use xio.NopCloser to compare with os.Stdout
* fmt of import
2023-08-10 03:58:42 +00:00
DmitriyLewen
bc2b0ca6c3
build: maximize available disk space for release ( #4937 )
...
* remove unneeded bins and archives
* use jlumbroso/free-disk-space
* remove repeating step
* use maximize-build-space
* build: remove unused step
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-08-09 18:18:15 +00:00
simar7
9493c6f087
test(cli): Fix assertion helptext ( #4966 )
2023-08-09 09:07:45 +00:00
simar7
b0359de664
chore(deps): Bump defsec to v0.91.1 ( #4965 )
2023-08-09 09:07:13 +00:00
Teppei Fukuda
d3a34e409c
test: validate CycloneDX with the JSON schema ( #4956 )
...
* test: validate CycloneDX with the JSON schema
* fix(sbom): move licenses to `name` field in Cyclonedx format (#4941 )
* use license.Name instead of Expression
* update tests
* test: add uuid package
* test: compare UUID
---------
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
2023-08-08 12:51:10 +00:00
Nikita Pivkin
798ef1b64a
fix(server): add licenses to the Result message ( #4955 )
2023-08-08 07:21:59 +00:00
Nikita Pivkin
e8cf281471
fix(aws): resolve endpoint if endpoint is passed ( #4925 )
...
* fix(aws): resolve endpoint to get identity if endpoint is passed
* resolve endpoint for ami and ebs
* return an error if aws region is missing
2023-08-08 07:19:40 +00:00
DmitriyLewen
f18b0db583
fix(sbom): move licenses to name field in Cyclonedx format ( #4941 )
...
* use license.Name instead of Expression
* update tests
2023-08-06 12:50:35 +00:00
DmitriyLewen
a79670156f
add only uniq deps in dependsOn ( #4943 )
2023-08-06 11:39:39 +00:00
Nikita Pivkin
b544e0dea7
use testify instead of gotest.tools ( #4946 )
2023-08-06 11:33:16 +00:00
Nikita Pivkin
067a0fcb9c
fix(nodejs): do not detect lock file in node_modules as an app ( #4949 )
...
* fix(npm): do not detect lock file in node_modules as an app
* refactor: add x/path.Contains
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-08-06 08:59:18 +00:00
DmitriyLewen
e6d7705a51
bump go-dep-parser ( #4936 )
2023-08-06 08:07:30 +00:00
dependabot[bot]
c584dc1768
chore(deps): bump github.com/openvex/go-vex from 0.2.0 to 0.2.1 ( #4914 )
...
Bumps [github.com/openvex/go-vex](https://github.com/openvex/go-vex ) from 0.2.0 to 0.2.1.
- [Release notes](https://github.com/openvex/go-vex/releases )
- [Commits](https://github.com/openvex/go-vex/compare/v0.2.0...v0.2.1 )
---
updated-dependencies:
- dependency-name: github.com/openvex/go-vex
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-03 13:07:12 +00:00
dependabot[bot]
358d56b6b5
chore(deps): bump helm/kind-action from 1.7.0 to 1.8.0 ( #4909 )
...
Bumps [helm/kind-action](https://github.com/helm/kind-action ) from 1.7.0 to 1.8.0.
- [Release notes](https://github.com/helm/kind-action/releases )
- [Commits](fa81e57adf...dda0770415 )
---
updated-dependencies:
- dependency-name: helm/kind-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-03 06:14:49 +00:00
dependabot[bot]
17f3ea9180
chore(deps): bump github.com/Azure/azure-sdk-for-go/sdk/azcore ( #4912 )
...
Bumps [github.com/Azure/azure-sdk-for-go/sdk/azcore](https://github.com/Azure/azure-sdk-for-go ) from 1.6.0 to 1.7.0.
- [Release notes](https://github.com/Azure/azure-sdk-for-go/releases )
- [Changelog](https://github.com/Azure/azure-sdk-for-go/blob/main/documentation/release.md )
- [Commits](https://github.com/Azure/azure-sdk-for-go/compare/sdk/azcore/v1.6.0...sdk/azcore/v1.7.0 )
---
updated-dependencies:
- dependency-name: github.com/Azure/azure-sdk-for-go/sdk/azcore
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-03 06:13:41 +00:00
Nikita Pivkin
39ccbf7b58
test(aws): move part of unit tests to integration ( #4884 )
...
* test(aws): move part of unit tests to integration
* fix typo
* fix test
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-08-02 15:48:52 +00:00
Will Yardley
6d3ae3bcf2
docs(cli): update help string for file and dir skipping ( #4872 )
...
* docs(cli): update help string for file and dir skipping
- Update the contextual help messages
- Add some additional examples (and clarify YAML file configuration) for
globbing
- Update docs
- Fix broken link in skipping docs
See also #3754
Signed-off-by: William Yardley <wyardley@users.noreply.github.com >
* docs: revert
---------
Signed-off-by: William Yardley <wyardley@users.noreply.github.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-08-02 12:33:59 +00:00
dependabot[bot]
7d7a1ef54a
chore(deps): bump sigstore/cosign-installer ( #4910 )
...
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer ) from ef0e9691595ea19ec990a46b1a591dcafe568f34 to a5d81fb6bdbcbb3d239e864d6552820420254494.
- [Release notes](https://github.com/sigstore/cosign-installer/releases )
- [Commits](ef0e969159...a5d81fb6bd )
---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-02 11:54:14 +00:00
dependabot[bot]
fc7495017d
chore(deps): bump github.com/sosedoff/gitkit from 0.3.0 to 0.4.0 ( #4916 )
...
Bumps [github.com/sosedoff/gitkit](https://github.com/sosedoff/gitkit ) from 0.3.0 to 0.4.0.
- [Commits](https://github.com/sosedoff/gitkit/compare/v0.3.0...v0.4.0 )
---
updated-dependencies:
- dependency-name: github.com/sosedoff/gitkit
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-02 11:41:38 +00:00
dependabot[bot]
b2a68bc06d
chore(deps): bump k8s.io/api from 0.27.3 to 0.27.4 ( #4918 )
...
Bumps [k8s.io/api](https://github.com/kubernetes/api ) from 0.27.3 to 0.27.4.
- [Commits](https://github.com/kubernetes/api/compare/v0.27.3...v0.27.4 )
---
updated-dependencies:
- dependency-name: k8s.io/api
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-02 11:37:31 +00:00
dependabot[bot]
e5c0c15b6e
chore(deps): bump github.com/secure-systems-lab/go-securesystemslib ( #4919 )
...
Bumps [github.com/secure-systems-lab/go-securesystemslib](https://github.com/secure-systems-lab/go-securesystemslib ) from 0.6.0 to 0.7.0.
- [Release notes](https://github.com/secure-systems-lab/go-securesystemslib/releases )
- [Commits](https://github.com/secure-systems-lab/go-securesystemslib/compare/v0.6.0...v0.7.0 )
---
updated-dependencies:
- dependency-name: github.com/secure-systems-lab/go-securesystemslib
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-02 11:37:09 +00:00
dependabot[bot]
da37803d59
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/sts ( #4913 )
...
Bumps [github.com/aws/aws-sdk-go-v2/service/sts](https://github.com/aws/aws-sdk-go-v2 ) from 1.19.0 to 1.21.0.
- [Release notes](https://github.com/aws/aws-sdk-go-v2/releases )
- [Changelog](https://github.com/aws/aws-sdk-go-v2/blob/main/CHANGELOG.md )
- [Commits](https://github.com/aws/aws-sdk-go-v2/compare/v1.19.0...service/s3/v1.21.0 )
---
updated-dependencies:
- dependency-name: github.com/aws/aws-sdk-go-v2/service/sts
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-02 11:31:47 +00:00
dependabot[bot]
9744e6498d
chore(deps): bump github.com/magefile/mage from 1.14.0 to 1.15.0 ( #4915 )
...
Bumps [github.com/magefile/mage](https://github.com/magefile/mage ) from 1.14.0 to 1.15.0.
- [Release notes](https://github.com/magefile/mage/releases )
- [Changelog](https://github.com/magefile/mage/blob/master/.goreleaser.yml )
- [Commits](https://github.com/magefile/mage/compare/v1.14.0...v1.15.0 )
---
updated-dependencies:
- dependency-name: github.com/magefile/mage
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-08-02 10:52:46 +00:00
Teppei Fukuda
99eebc6703
docs: update the discussion template ( #4928 )
2023-08-02 10:51:51 +00:00
Teppei Fukuda
d19c7d9f29
feat(repo): support local repositories ( #4890 )
...
* feat(repo): support local repositories
* fix tests
* test: fix client/server tests
* docs: update
* test: add fs tests
* test: do not update golden files if overridden
* docs: remove a comment about fs deprecation
2023-07-31 11:27:36 +00:00
DmitriyLewen
3c19761875
bump go-dep-parser ( #4893 )
2023-07-31 11:08:25 +00:00
Nikita Pivkin
e1c2a8c804
fix(misconf): add missing fields to proto ( #4861 )
...
* fix(misconf): add missing fields to proto
* mark deleted fields as reserved
2023-07-30 11:15:36 +00:00
Nikita Pivkin
8b8e0e83d1
fix: remove trivy-db package replacement ( #4877 )
...
* fix: remove trivy-db package replacement
* fix: remove trivy-db package replacement
2023-07-30 07:37:14 +00:00
Nikita Pivkin
f9efe44fd3
chore(test): bump the integration test timeout to 15m ( #4880 )
2023-07-30 07:34:48 +00:00
simar7
7271d682fb
chore(deps): Update defsec to v0.91.0 ( #4886 )
...
* chore(deps): Update defsec to v0.91.0
* update tests
Signed-off-by: Simar <simar@linux.com >
---------
Signed-off-by: Simar <simar@linux.com >
2023-07-30 07:31:34 +00:00
Teppei Fukuda
c3bc67c89a
chore: update CODEOWNERS ( #4871 )
...
* Update CODEOWNERS
* Add simar7
2023-07-27 07:05:15 +00:00
Teppei Fukuda
232ba823e1
feat(vuln): support vulnerability status ( #4867 )
...
* feat: support vulnerability status
* feat: show status in table
* don't add `fixed` status in debian/redhat
* update test golden files
* add Status in rpc
* update docs
* update ignore-status example
* add ignore-status in integration test
* docs: add the explanation for statuses
---------
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-07-26 11:55:03 +00:00
simar7
11618c9408
feat(misconf): Support custom URLs for policy bundle ( #4834 )
...
* feat(misconf): Support custom URLs for policy bundle
This PR adds support for custom policy bundles to be specified
with a flag `--policy-bundle-url` as an option to Trivy.
Fixes: https://github.com/aquasecurity/trivy/issues/4672
Signed-off-by: Simar <simar@linux.com >
* update docs
Signed-off-by: Simar <simar@linux.com >
* rename flag to `--policy-bundle-repository`
Signed-off-by: Simar <simar@linux.com >
* fix field
* rebase and update docs
Signed-off-by: Simar <simar@linux.com >
* set policyBundleRepo on client
Signed-off-by: Simar <simar@linux.com >
---------
Signed-off-by: Simar <simar@linux.com >
2023-07-26 08:45:49 +00:00
Teppei Fukuda
07075696d1
refactor: replace with sortable packages ( #4858 )
2023-07-24 07:09:14 +00:00
Damian E
fbe1c9eb1f
docs: correct license scanning sample command ( #4855 )
2023-07-24 05:02:55 +00:00
Teppei Fukuda
20c2246a61
fix(report): close the file ( #4842 )
...
* fix(report): close the file
* refactor: add the format type
* fix: return errors in version printing
* fix: lint issues
* fix: do not fail on bogus cache dir
---------
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-07-23 13:37:18 +00:00
DmitriyLewen
24a3e547d9
feat(nodejs): add support for include-dev-deps flag for yarn ( #4812 )
...
* add support for include-dev-deps flag
* remove go.mod replace
* refactor
* bump go-dep-parser
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-07-23 13:07:49 +00:00
simar7
a7bd7bb65f
feat(misconf): Add support for independently enabling libraries ( #4070 )
...
* feat(misconf): Add support for independently enabling libraries
Implements: https://github.com/aquasecurity/trivy/issues/4181
Signed-off-by: Simar <simar@linux.com >
* update tests
Signed-off-by: Simar <simar@linux.com >
* fix lint
Signed-off-by: Simar <simar@linux.com >
* fix tests
Signed-off-by: Simar <simar@linux.com >
* update defsec
Signed-off-by: Simar <simar@linux.com >
* fix test
Signed-off-by: Simar <simar@linux.com >
---------
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-07-23 09:44:59 +00:00
DmitriyLewen
4aa9ea0961
feat(secret): add secret config file for cache calculation ( #4837 )
...
* move parse secret config to initScannerConfig + add secret to cache key
* add calc cache test
* just read config file and add to cache
* refactor comments
* refactor
2023-07-23 08:26:22 +00:00
Sogo Kato
5d349d8147
Fix a link in gitlab-ci.md ( #4850 )
2023-07-23 08:20:29 +00:00
Nikita Pivkin
a61531c1f7
fix(flag): use globalstar to skip directories ( #4854 )
2023-07-23 06:11:46 +00:00
DmitriyLewen
78cc20937d
chore(deps): bump github.com/docker/docker from v23.0.5+incompatible to v23.0.7-0.20230714215826-f00e7af96042+incompatible ( #4849 )
...
* use 1.19.10 version for integration tests
* fix go-version field
* revert test workflow changes
* bump docker/docker
2023-07-21 09:00:35 +00:00
afdesk
93996041b2
fix(license): using common way for splitting licenses ( #4434 )
...
* fix(license): using common way for splitting licenses
* add test cases
* TEST new regex
* extract function
* fix version detection
---------
Co-authored-by: Nikita Pivkin <nikita.pivkin@smartforce.io >
2023-07-19 08:05:43 +00:00
AliDatadog
3e2416d77c
fix(containerd): Use img platform in exporter instead of strict host platform ( #4477 )
...
* match with img platform instead of host platform
* client matching pull spec
* use default platform
* pull with platforms default strict
* use withplatform to pull and add debug log
* looks like we are trying to scan a i386 image
* revert changes on test, use the right platform match
* try with Config.Platform
* use spect.platform
* fix function usage
* try another way to retrieve the platform
* fix compilation
* read platforms from config manifest
* use platform from RegistryOptions if available, otherwise get the actual platform
* goimport
* put platform in containerd client
* fix panic
* use DefaultStrict as default
2023-07-19 07:54:24 +00:00
DmitriyLewen
ce77bb46c3
remove govulndb ( #4783 )
2023-07-19 07:24:35 +00:00
Nikita Pivkin
c05caae43f
fix(java): inherit licenses from parents ( #4817 )
2023-07-19 06:51:58 +00:00
Teppei Fukuda
aca11b95d0
refactor: add allowed values for CLI flags ( #4800 )
...
* refactor: rename Value to Default
* refactor: support allowed values for CLI flags
* docs: auto-generate
* test: fix
* test: add tests for flags
2023-07-17 13:13:23 +00:00
DmitriyLewen
4cecd17ea5
add example regex to allow rules ( #4827 )
2023-07-17 12:36:22 +00:00
simar7
4bc8d29c15
feat(misconf): Support custom data for rego policies for cloud ( #4745 )
...
* feat(misconf): Support custom data for cloud policies
Signed-off-by: Simar <simar@linux.com >
* use policyfs
Signed-off-by: Simar <simar@linux.com >
* refactor to reduce cyclomatic complexity
Signed-off-by: Simar <simar@linux.com >
* bump defsec
* update docs
Signed-off-by: Simar <simar@linux.com >
* update test assertion
Signed-off-by: Simar <simar@linux.com >
* update test
Need this as OPA is currently broken on Windows
https://github.com/open-policy-agent/opa/issues/4521
Signed-off-by: Simar <simar@linux.com >
* fix data path
* fix(mapfs): convert volume names into dirs
* revert creating temp dirs
---------
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2023-07-17 12:34:20 +00:00
Anais Urlichs
88243a0ad6
docs: correcting the trivy k8s tutorial ( #4815 )
...
* correcting the trivy k8s tutorial
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
* docs: fix
---------
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-07-16 09:06:28 +00:00
Nikita Pivkin
3c7d988d71
feat(cli): add --tf-exclude-downloaded-modules flag ( #4810 )
...
* feat(cli): add --tf-exclude-downloaded-modules flag
* fix typo
* generate docs
2023-07-16 08:56:03 +00:00
DmitriyLewen
fd0fd104f8
fix(sbom): cyclonedx recommendations should include fixed versions for each package ( #4794 )
...
* add all fixed versions to recommendations
* fix tests
2023-07-13 11:16:11 +00:00
Nikita Pivkin
d0d543b881
feat(misconf): enable --policy flag to accept directory and files both ( #4777 )
...
* feat(misconf): enable --policy flag to accept directory and files both
* fix test
* Revert "clarifying a dir path is required for custom policies (#4716 )"
This reverts commit 8a1aa448a1 .
* update doc
* update the flag description
2023-07-13 10:59:21 +00:00
Nikita Pivkin
b43a3e6237
feat(python): add license fields ( #4722 )
...
* bump go-dep-parser
* update tests
* fix testdata
2023-07-13 10:55:36 +00:00
chenk
aef7b148af
fix: support trivy k8s-version on k8s sub-command ( #4786 )
...
* fix: support trivy k8s-version on k8s sub-command
Signed-off-by: chenk <hen.keinan@gmail.com >
* fix: support last applied configuration
Signed-off-by: chenk <hen.keinan@gmail.com >
---------
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-07-13 08:28:09 +00:00
simar7
5d76abadc9
chore(deps): Update defsec to v0.90.3 ( #4793 )
...
* chore(deps): Update defsec to v0.90.2
Signed-off-by: Simar <simar@linux.com >
* go mod tidy
---------
Signed-off-by: Simar <simar@linux.com >
2023-07-07 08:13:56 +00:00
dependabot[bot]
fed446c515
chore(deps): bump google.golang.org/protobuf from 1.30.0 to 1.31.0 ( #4752 )
...
Bumps google.golang.org/protobuf from 1.30.0 to 1.31.0.
---
updated-dependencies:
- dependency-name: google.golang.org/protobuf
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-07 04:56:30 +00:00
dependabot[bot]
df62927e58
chore(deps): bump alpine from 3.18.0 to 3.18.2 ( #4748 )
...
Bumps alpine from 3.18.0 to 3.18.2.
---
updated-dependencies:
- dependency-name: alpine
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-07 04:05:43 +00:00
dependabot[bot]
1b9b9a84f7
chore(deps): bump github.com/alicebob/miniredis/v2 from 2.30.3 to 2.30.4 ( #4758 )
...
Bumps [github.com/alicebob/miniredis/v2](https://github.com/alicebob/miniredis ) from 2.30.3 to 2.30.4.
- [Release notes](https://github.com/alicebob/miniredis/releases )
- [Changelog](https://github.com/alicebob/miniredis/blob/master/CHANGELOG.md )
- [Commits](https://github.com/alicebob/miniredis/compare/v2.30.3...v2.30.4 )
---
updated-dependencies:
- dependency-name: github.com/alicebob/miniredis/v2
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-06 13:23:01 +00:00
zunlongzhou
3c16ca821b
docs(image): fix the comment on the soft/hard link ( #4740 )
...
* Update tar.go
The comment before the following w.processFile(filePath, tr, hdr.FileInfo(), analyzeFn) call says: // A symbolic/hard link or regular file will reach here.
But defualt's processing causes the symbolic/hard link to not reach the processFile function location
* Update tar.go
update tar.go comment
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-07-06 10:49:48 +00:00
DmitriyLewen
e5bee5cccd
check Type when filling pkgs in vulns ( #4776 )
2023-07-06 10:45:52 +00:00
Bill Wang
4b9f310b9c
feat: add support of linux/ppc64le and linux/s390x architectures for Install.sh script ( #4770 )
...
* feat: add support of linux/ppc64le and linux/s390x architectures for Install.sh script #4747
* feat: add support of linux/ppc64le and linux/s390x architectures for Install.sh script #4747
2023-07-06 09:05:37 +00:00
dependabot[bot]
8e7fb7cc84
chore(deps): bump modernc.org/sqlite from 1.20.3 to 1.23.1 ( #4756 )
...
Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite ) from 1.20.3 to 1.23.1.
- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.20.3...v1.23.1 )
---
updated-dependencies:
- dependency-name: modernc.org/sqlite
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-04 19:45:34 +00:00
DmitriyLewen
a9badeaba8
fix(rocky): add architectures support for advisories ( #4691 )
...
* add multi-arch support for rocky linux advisories
* feat: comply with the new signagure
* bump trivy-db
* fix tests
* chore(deps): remove fork replace
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-07-03 08:48:57 +00:00
dependabot[bot]
f8ebccc680
chore(deps): bump github.com/opencontainers/image-spec ( #4751 )
...
Bumps [github.com/opencontainers/image-spec](https://github.com/opencontainers/image-spec ) from 1.1.0-rc3 to 1.1.0-rc4.
- [Release notes](https://github.com/opencontainers/image-spec/releases )
- [Changelog](https://github.com/opencontainers/image-spec/blob/main/RELEASES.md )
- [Commits](https://github.com/opencontainers/image-spec/compare/v1.1.0-rc3...v1.1.0-rc4 )
---
updated-dependencies:
- dependency-name: github.com/opencontainers/image-spec
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-03 07:19:56 +00:00
dependabot[bot]
1c81948e03
chore(deps): bump github.com/package-url/packageurl-go ( #4754 )
...
Bumps [github.com/package-url/packageurl-go](https://github.com/package-url/packageurl-go ) from 0.1.1-0.20220428063043-89078438f170 to 0.1.1.
- [Release notes](https://github.com/package-url/packageurl-go/releases )
- [Commits](https://github.com/package-url/packageurl-go/commits/v0.1.1 )
---
updated-dependencies:
- dependency-name: github.com/package-url/packageurl-go
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-03 04:06:44 +00:00
dependabot[bot]
497cc10d8e
chore(deps): bump golang.org/x/sync from 0.2.0 to 0.3.0 ( #4750 )
...
Bumps [golang.org/x/sync](https://github.com/golang/sync ) from 0.2.0 to 0.3.0.
- [Commits](https://github.com/golang/sync/compare/v0.2.0...v0.3.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/sync
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-02 14:57:57 +00:00
dependabot[bot]
065f0afa54
chore(deps): bump github.com/tetratelabs/wazero from 1.2.0 to 1.2.1 ( #4755 )
...
Bumps [github.com/tetratelabs/wazero](https://github.com/tetratelabs/wazero ) from 1.2.0 to 1.2.1.
- [Release notes](https://github.com/tetratelabs/wazero/releases )
- [Commits](https://github.com/tetratelabs/wazero/compare/v1.2.0...v1.2.1 )
---
updated-dependencies:
- dependency-name: github.com/tetratelabs/wazero
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-02 14:52:44 +00:00
dependabot[bot]
e2603056dd
chore(deps): bump github.com/testcontainers/testcontainers-go ( #4759 )
...
Bumps [github.com/testcontainers/testcontainers-go](https://github.com/testcontainers/testcontainers-go ) from 0.20.1 to 0.21.0.
- [Release notes](https://github.com/testcontainers/testcontainers-go/releases )
- [Commits](https://github.com/testcontainers/testcontainers-go/compare/v0.20.1...v0.21.0 )
---
updated-dependencies:
- dependency-name: github.com/testcontainers/testcontainers-go
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-07-02 13:57:46 +00:00
Alexandre
0621402bf7
fix: documentation about reseting trivy image ( #4733 )
2023-07-02 12:29:23 +00:00
Dirk Mueller
798fdbc013
fix(suse): Add openSUSE Leap 15.5 eol date as well ( #4744 )
...
Taken directly from https://en.opensuse.org/Lifetime
2023-07-02 11:22:26 +00:00
Teppei Fukuda
34a89293d5
fix: update Amazon Linux 1 EOL ( #4761 )
2023-07-02 11:00:20 +00:00
simar7
600819248d
chore(deps): Update defsec to v0.90.1 ( #4739 )
...
Fixes: https://github.com/aquasecurity/trivy/issues/4628
Signed-off-by: Simar <simar@linux.com >
2023-06-30 06:48:47 +00:00
Nikita Pivkin
73734eab21
feat(nodejs): support yarn workspaces ( #4664 )
...
* feat(nodejs): add the workspaces field to the package
* fix go.mod
* update go.mod
* compare workspaces by length
2023-06-30 06:40:28 +00:00
DmitriyLewen
22463ababd
feat(cli): add include-dev-deps flag ( #4700 )
...
* add Dev field for Package
* fix integration test
* update docs
* feat(cli): add include-dev flag
* bump go-dep-parser
* update docs
* add integration test
* refactor
* refactor
* fix integration test
* refactor: rename flag to include-dev-deps
* update docs
* update docs
* filter dev deps when scanning packages
* add flag support for server mode
* refactor: remove comment that might confuse
* refactor: move --include-dev-deps to the scanner flag group
* refactor: not return apps
* docs: update
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-06-29 13:15:52 +00:00
Nikita Pivkin
790c8054ec
fix(image): pass the secret scanner option to scan the img config ( #4735 )
2023-06-29 08:37:45 +00:00
chenk
86fec9c4a9
fix: scan job pod it not found on k8s-1.27.x ( #4729 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-06-28 14:38:39 +00:00
Manveer Singh
26bc91160b
feat(docker): add support for mTLS authentication when connecting to registry ( #4649 )
...
* feat: add support for mTLS authentication when connecting to registry
* feat: add support for mTLS authentication when connecting to registry - added error handling
* feat: add support for mTLS authentication when connecting to registry
- code quality improvements
* feat: add support for mTLS authentication when connecting to registry
- code quality improvements
* wrap errors
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-06-28 11:21:26 +00:00
simar7
d699e8c101
chore(deps): Update defsec to v0.90.0 ( #4723 )
...
Signed-off-by: Simar <simar@linux.com >
2023-06-28 08:34:56 +00:00
DmitriyLewen
1777878e83
fix: skip scanning the gpg-pubkey package ( #4720 )
2023-06-28 07:06:08 +00:00
Makhonin Alexey
9be08253a2
Fix http registry oci pull ( #4701 )
...
Signed-off-by: alexey.makhonin <alexey.makhonin@flant.com >
2023-06-26 12:40:40 +00:00
simar7
5d73b47dbc
feat(misconf): Support skipping services ( #4686 )
...
* feat(misconf): Add support for `--skip-service` flag.
Fixes: https://github.com/aquasecurity/trivy/issues/4619
Signed-off-by: Simar <simar@linux.com >
* update docs
Signed-off-by: Simar <simar@linux.com >
* update go mod
* refactor processOptions to reduce cyclo complexity
Signed-off-by: Simar <simar@linux.com >
* fix a bug with multiple skip services
Signed-off-by: Simar <simar@linux.com >
* refactor tests
Signed-off-by: Simar <simar@linux.com >
* use x/slice and x/xerrors
Signed-off-by: Simar <simar@linux.com >
* go mod tidy
* lint
---------
Signed-off-by: Simar <simar@linux.com >
2023-06-26 11:11:59 +00:00
DmitriyLewen
46e784c8a9
docs: fix supported modes for pubspec.lock files ( #4713 )
2023-06-26 11:04:45 +00:00
Teppei Fukuda
0f61a84712
fix(misconf): disable the terraform plan analyzer for other scanners ( #4714 )
2023-06-26 11:03:25 +00:00
Anais Urlichs
8a1aa448a1
clarifying a dir path is required for custom policies ( #4716 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2023-06-26 10:56:57 +00:00
Sandro
fbab9eea3a
chore: update alpine base images ( #4715 )
2023-06-26 10:34:50 +00:00
AliDatadog
f84417bba0
fix last-history-created ( #4697 )
2023-06-26 03:57:54 +00:00
chenk
85c681d443
feat: kbom and cyclonedx v1.5 spec support ( #4708 )
...
* feat: kbom and cyclonedx v1.5 spec support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kbom and cyclonedx v1.5 spec support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kbom and cyclonedx v1.5 spec support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: feat: kbom and cyclonedx 1.5 spec support
Signed-off-by: chenk <hen.keinan@gmail.com >
* fix: unmarshal bom on v1.5 return invalid specification version
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: cyclonedx-1.5 spec support
Signed-off-by: chenk <hen.keinan@gmail.com >
---------
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-06-25 13:47:06 +00:00
Itay Shakury
46748ce6ea
docs: add information about Aqua ( #4590 )
...
* docs: add information about Aqua
* update link
2023-06-25 10:40:45 +00:00
chenk
c6741bddff
fix: k8s escape resource filename on windows os ( #4693 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-06-22 11:16:24 +00:00
Teppei Fukuda
a21acc7e08
ci: ignore merge queue branches ( #4696 )
2023-06-22 11:02:22 +00:00
dependabot[bot]
32a3a3311c
chore(deps): bump actions/checkout from 2.4.0 to 3.5.3 ( #4695 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 2.4.0 to 3.5.3.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v2.4.0...v3.5.3 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-22 10:56:11 +00:00
dependabot[bot]
cbb47dc7c4
chore(deps): bump aquaproj/aqua-installer from 2.1.1 to 2.1.2 ( #4694 )
...
Bumps [aquaproj/aqua-installer](https://github.com/aquaproj/aqua-installer ) from 2.1.1 to 2.1.2.
- [Release notes](https://github.com/aquaproj/aqua-installer/releases )
- [Commits](https://github.com/aquaproj/aqua-installer/compare/v2.1.1...v2.1.2 )
---
updated-dependencies:
- dependency-name: aquaproj/aqua-installer
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-22 10:31:20 +00:00
chenk
e3d10d2512
feat: cyclondx sbom custom property support ( #4688 )
...
* feat: custom property support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: custom property support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: custom property support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: custom property support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: custom property support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: custom property support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: custom property support
Signed-off-by: chenk <hen.keinan@gmail.com >
---------
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-06-22 08:33:27 +00:00
Teppei Fukuda
e1770e046c
ci: do not trigger tests in main ( #4692 )
2023-06-22 08:25:58 +00:00
Dirk Mueller
337c0b70d5
add SUSE Linux Enterprise Server 15 SP5 and update SP4 eol date ( #4690 )
...
all dates are taken from https://www.suse.com/lifecycle#suse-linux-enterprise-server-15
2023-06-22 07:34:59 +00:00
DmitriyLewen
5ccee14304
use group field for jar in cyclonedx ( #4674 )
2023-06-22 07:19:38 +00:00
Nikita Pivkin
96db52c3f6
feat(java): capture licenses from pom.xml ( #4681 )
...
* feat(java): capture licenses from pom.xml
* update doc
2023-06-21 13:12:37 +00:00
Leroy Shirto
3e902a57a9
feat(helm): make sessionAffinity configurable ( #4623 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-06-21 11:14:36 +00:00
Tung Bui (Leo)
904f1cf24e
fix: Show the correct URL of the secret scanning ( #4682 )
2023-06-21 10:57:54 +00:00
Meisam
7d48c5d5d4
document expected file pattern definition format ( #4654 )
2023-06-20 14:02:55 +00:00
guangwu
dcc73e964a
fix: format arg error ( #4642 )
...
* fix: format arg error
* fix: xerrors.Errorf
2023-06-19 10:52:38 +00:00
chenk
35c4262d0b
feat(k8s): cyclonedx kbom support ( #4557 )
...
* feat: cyclonedx kbom support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: cyclonedx kbom support
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* chore: update sum db
Signed-off-by: chenk <hen.keinan@gmail.com >
* chore: update sum db
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* chore: update sumdb
Signed-off-by: chenk <hen.keinan@gmail.com >
* chore: update sumdb
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
* feat: kubernetes bill of materials
Signed-off-by: chenk <hen.keinan@gmail.com >
---------
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-06-19 10:48:26 +00:00
Nikita Pivkin
0e01851e9e
fix(nodejs): remove unused fields for the pnpm lockfile ( #4630 )
...
* refactor(nodejs): remove unused fields for the pnpm lockfile
* run go mod tidy
---------
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-06-19 03:17:31 +00:00
Masahiro331
4d9b444499
fix(vm): update ext4-filesystem parser for parse multi block extents ( #4616 )
...
* chore(deps): update ext4-filesystem parser for parse multi block extents
* test(vm): update integration-vm test fixtures
* test(vm): add gzip decompresser for sparse file
* test(vm): add mage command update golden file for vm integration test
* chore(magefile): [WIP] change test repository
* Revert "chore(magefile): [WIP] change test repository"
This reverts commit c015c8892f .
* fix(test): update fixtures and golden file
* fix(test): revert fixVersion and PkgID
2023-06-18 16:41:55 +00:00
afdesk
c29197ab7d
ci: update build IDs ( #4641 )
2023-06-18 11:24:29 +00:00
Chris Novakovic
d7637adc6b
fix(debian): update EOL for Debian 12 ( #4647 )
...
* fix(debian): update EOL for Debian 12
Debian 12 was released on 2023-06-10 and will be supported for five
years - see https://www.debian.org/News/2023/20230610 .
* Update docs
2023-06-16 04:18:55 +00:00
Teppei Fukuda
ef39eeedf3
chore(deps): bump go-containerregistry ( #4639 )
2023-06-15 09:44:24 +00:00
guangwu
1ce8bb535a
chore: unnecessary use of fmt.Sprintf (S1039) ( #4637 )
2023-06-15 08:36:15 +00:00
Björn Wenzel
bc9513fc57
fix(db): change argument order in Exists query for JavaDB ( #4595 )
2023-06-14 02:26:10 +00:00
simar7
aecd2f0bf0
feat(aws): Add support to see successes in results ( #4427 )
...
Fixes: https://github.com/aquasecurity/trivy/discussions/4417
Signed-off-by: Simar <simar@linux.com >
2023-06-13 17:36:05 +00:00
dependabot[bot]
2cbf402b6a
chore(deps): bump golangci/golangci-lint-action from 3.5.0 to 3.6.0 ( #4613 )
...
Bumps [golangci/golangci-lint-action](https://github.com/golangci/golangci-lint-action ) from 3.5.0 to 3.6.0.
- [Release notes](https://github.com/golangci/golangci-lint-action/releases )
- [Commits](https://github.com/golangci/golangci-lint-action/compare/v3.5.0...v3.6.0 )
---
updated-dependencies:
- dependency-name: golangci/golangci-lint-action
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-12 13:52:43 +00:00
Teppei Fukuda
0099b20e31
ci: do not trigger tests in main ( #4614 )
2023-06-12 13:00:32 +00:00
dependabot[bot]
a597a54fb6
chore(deps): bump sigstore/cosign-installer ( #4609 )
...
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer ) from 204a51a57a74d190b284a0ce69b44bc37201f343 to ef0e9691595ea19ec990a46b1a591dcafe568f34.
- [Release notes](https://github.com/sigstore/cosign-installer/releases )
- [Commits](204a51a57a...ef0e969159 )
---
updated-dependencies:
- dependency-name: sigstore/cosign-installer
dependency-type: direct:production
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-06-12 12:16:20 +00:00
dependabot[bot]
b453fbec37
chore(deps): bump CycloneDX/gh-gomod-generate-sbom from 1 to 2 ( #4608 )
...
Bumps [CycloneDX/gh-gomod-generate-sbom](https://github.com/CycloneDX/gh-gomod-generate-sbom ) from 1 to 2.
- [Release notes](https://github.com/CycloneDX/gh-gomod-generate-sbom/releases )
- [Commits](https://github.com/CycloneDX/gh-gomod-generate-sbom/compare/v1...v2 )
---
updated-dependencies:
- dependency-name: CycloneDX/gh-gomod-generate-sbom
dependency-type: direct:production
update-type: version-update:semver-major
...
Signed-off-by: dependabot[bot] <support@github.com >
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-06-12 11:40:58 +00:00
Teppei Fukuda
0e876d5aa0
ci: bypass the required status checks ( #4611 )
2023-06-12 14:39:47 +03:00
Teppei Fukuda
a4f27d24a3
ci: support merge queue ( #3652 )
2023-06-12 11:39:08 +03:00
Teppei Fukuda
9e6411e9f5
ci: matrix build for testing ( #4587 )
2023-06-12 10:49:13 +03:00
chenk
ef6538a171
feat: trivy k8s private registry support ( #4567 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-06-12 05:40:25 +03:00
Itay Shakury
139f3e1e32
docs: add general coverage page ( #3859 )
2023-06-11 08:49:29 +03:00
Itay Shakury
479cfdd40e
chore: create SECURITY.md ( #4601 )
2023-06-11 06:16:42 +03:00
afdesk
9a279fa7bb
ci: remove 32bit packages ( #4585 )
2023-06-08 16:52:37 +03:00
Teppei Fukuda
d52b0b7bc0
fix(misconf): deduplicate misconf results ( #4588 )
2023-06-08 15:15:21 +03:00
Amir Ben Nun
9b531fa27b
fix(vm): support sector size of 4096 ( #4564 )
...
Co-authored-by: masahiro331 <m_fujimura@r.recruit.co.jp >
2023-06-08 11:31:13 +03:00
Teppei Fukuda
8ca1bfdd23
fix(misconf): terraform relative paths ( #4571 )
2023-06-08 11:24:52 +03:00
Nikita Pivkin
c20d466044
fix(purl): skip unsupported library type ( #4577 )
2023-06-08 08:45:32 +03:00
Jonathan Lassoff
52cbe79759
fix(terraform): recursively detect all Root Modules ( #4457 )
...
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: Simar <simar@linux.com >
2023-06-08 07:06:00 +03:00
Masahiro331
4a5b915578
fix(vm): support post analyzer for vm command ( #4544 )
2023-06-07 16:16:27 +03:00
Nikita Pivkin
56cdc55f77
fix(nodejs): change the type of the devDependencies field ( #4560 )
2023-06-06 15:51:39 +03:00
Nikita Pivkin
17d753676b
fix(sbom): export empty dependencies in CycloneDX ( #4568 )
2023-06-06 15:49:23 +03:00
Teppei Fukuda
2796abe1ed
refactor: add composite fs for post-analyzers ( #4556 )
2023-06-06 08:19:15 +03:00
dependabot[bot]
22a1573807
chore(deps): bump golangci/golangci-lint-action from 3.4.0 to 3.5.0 ( #4554 )
2023-06-04 16:17:54 +03:00
dependabot[bot]
43586659a1
chore(deps): bump helm/kind-action from 1.5.0 to 1.7.0 ( #4526 )
2023-06-04 14:50:38 +03:00
dependabot[bot]
5081399659
chore(deps): bump github.com/BurntSushi/toml from 1.2.1 to 1.3.0 ( #4528 )
2023-06-04 14:48:41 +03:00
dependabot[bot]
e1a38128ab
chore(deps): bump github.com/alicebob/miniredis/v2 from 2.30.2 to 2.30.3 ( #4529 )
2023-06-04 11:19:53 +03:00
dependabot[bot]
283eef6372
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 ( #4536 )
2023-06-04 11:13:44 +03:00
dependabot[bot]
bbd7b98741
chore(deps): bump github.com/tetratelabs/wazero from 1.0.0 to 1.2.0 ( #4549 )
2023-06-04 11:12:49 +03:00
dependabot[bot]
11c81bf2f6
chore(deps): bump github.com/spf13/cast from 1.5.0 to 1.5.1 ( #4532 )
2023-06-04 11:11:32 +03:00
dependabot[bot]
2d8d63e61a
chore(deps): bump github.com/testcontainers/testcontainers-go ( #4537 )
2023-06-04 09:27:43 +03:00
dependabot[bot]
a46839b1ce
chore(deps): bump github.com/go-git/go-git/v5 from 5.6.1 to 5.7.0 ( #4530 )
2023-06-04 09:25:43 +03:00
dependabot[bot]
19715f5de8
chore(deps): bump github.com/aws/aws-sdk-go-v2/config ( #4534 )
2023-06-04 09:25:04 +03:00
dependabot[bot]
854b63940a
chore(deps): bump github.com/sigstore/rekor from 1.2.0 to 1.2.1 ( #4533 )
2023-06-02 09:36:08 +03:00
dependabot[bot]
59e1a86643
chore(deps): bump alpine from 3.17.3 to 3.18.0 ( #4525 )
2023-06-02 09:34:44 +03:00
Teppei Fukuda
9ef01133c8
feat: add SBOM analyzer ( #4210 )
...
Co-authored-by: DmitriyLewen <91113035+DmitriyLewen@users.noreply.github.com >
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-06-02 09:34:07 +03:00
DmitriyLewen
dadd1e10c2
fix(sbom): update logic for work with files in spdx format ( #4513 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2023-06-01 12:52:56 +03:00
chenk
1a658210a4
feat: azure workload identity support ( #4489 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-06-01 10:16:23 +03:00
DmitriyLewen
411862c908
feat(ubuntu): add eol date for 18.04 ESM ( #4524 )
2023-06-01 09:48:33 +03:00
simar7
62a1aaf031
fix(misconf): Update required extensions for terraformplan ( #4523 )
...
Signed-off-by: Simar <simar@linux.com >
2023-06-01 07:23:37 +03:00
Teppei Fukuda
48b2e15c23
refactor(cyclonedx): add intermediate representation ( #4490 )
2023-06-01 05:50:47 +03:00
simar7
c15f269a99
fix(misconf): Remove debug print while scanning ( #4521 )
...
Signed-off-by: Simar <simar@linux.com >
2023-06-01 05:28:37 +03:00
DmitriyLewen
b6ee08e55d
fix(java): remove duplicates of jar libs ( #4515 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-05-31 15:09:18 +03:00
DmitriyLewen
d4740401a3
fix(java): fix overwriting project props in pom.xml ( #4498 )
2023-05-31 13:16:28 +03:00
Tung Bui (Leo)
4cf2f94d0d
docs: Update compilation instructions ( #4512 )
2023-05-31 10:47:56 +03:00
DmitriyLewen
18ce1c3363
fix(nodejs): update logic for parsing pnpm lock files ( #4502 )
2023-05-31 08:41:08 +03:00
DmitriyLewen
87eed38c6c
fix(secret): remove aws-account-id rule ( #4494 )
2023-05-31 07:00:20 +03:00
LaurentiuNiculae
b0c591ef66
feat(oci): add support for referencing an input image by digest ( #4470 )
...
Signed-off-by: Laurentiu Niculae <niculae.laurentiu1@gmail.com >
2023-05-31 06:39:42 +03:00
dependabot[bot]
b84b5ecfc2
chore(deps): bump github.com/cloudflare/circl from 1.1.0 to 1.3.3 ( #4338 )
2023-05-30 18:50:09 +03:00
Tej Singh Rana
305255a497
docs: fixed the format ( #4503 )
2023-05-30 16:37:06 +03:00
DmitriyLewen
d586de585e
fix(java): add support of * for exclusions for pom.xml files ( #4501 )
2023-05-30 16:34:54 +03:00
Anais Urlichs
de6eef3b00
feat: adding issue template for documentation ( #4453 )
2023-05-30 12:23:05 +03:00
DmitriyLewen
83a9c4a4cf
docs: switch glad to ghsa for Go ( #4493 )
2023-05-30 09:46:49 +03:00
simar7
537272257b
chore(deps): Update defsec to v0.89.0 ( #4474 )
2023-05-30 06:06:46 +03:00
simar7
6fcd1538d9
feat(misconf): Add terraformplan support ( #4342 )
...
* feat(misconf): Add terraformplan support
Fixes: https://github.com/aquasecurity/trivy/issues/4341
Signed-off-by: Simar <simar@linux.com >
* update defsec
* fix lint
Signed-off-by: Simar <simar@linux.com >
* remove debug prints
Signed-off-by: Simar <simar@linux.com >
* update tests
Signed-off-by: Simar <simar@linux.com >
---------
Signed-off-by: Simar <simar@linux.com >
2023-05-29 14:48:26 -06:00
DmitriyLewen
72e302cf81
feat(debian): add digests for dpkg ( #4445 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-05-28 10:30:58 +03:00
dependabot[bot]
7e99d08a13
chore(deps): bump github.com/sigstore/rekor from 1.1.1 to 1.2.0 ( #4478 )
2023-05-28 06:37:30 +03:00
chenk
12a1789be5
feat(k8s): exclude node scanning by node labels ( #4459 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-05-25 14:52:28 +03:00
DmitriyLewen
919e8c92b2
docs: add info about multi-line mode for regexp from custom secret rules ( #4159 )
2023-05-24 14:59:50 +03:00
Teppei Fukuda
50fe43f14c
feat(cli): convert JSON reports into a different format ( #4452 )
...
Co-authored-by: Aurelien LAJOIE <aurelien.lajoie@kili-technology.com >
2023-05-24 11:45:26 +03:00
DmitriyLewen
09db1d4389
feat(image): add logic to guess base layer for docker-cis scan ( #4344 )
2023-05-24 10:43:09 +03:00
afdesk
3f0721ff6e
fix(cyclonedx): set original names for packages ( #4306 )
2023-05-23 12:35:52 +03:00
Teppei Fukuda
0ef0dadb16
feat: group subcommands ( #4449 )
2023-05-23 08:15:39 +03:00
rlubetkin
3a7717fdeb
feat(cli): add retry to cache operations ( #4189 )
2023-05-22 16:56:18 +03:00
AliDatadog
63cfb2714a
fix(vuln): report architecture for apk packages ( #4247 )
...
Co-authored-by: Sylvain Baubeau <lebauce@gmail.com >
2023-05-22 16:37:00 +03:00
Teppei Fukuda
e1361368a1
refactor: enable cases where return values are not needed in pipeline ( #4443 )
2023-05-22 08:11:24 +03:00
Mike Poindexter
29b5f7e8ec
fix(image): resolve scan deadlock when error occurs in slow mode ( #4336 )
2023-05-21 10:48:06 +03:00
simar7
92ed344e8a
docs(misconf): Update docs for kubernetes file patterns ( #4435 )
...
Signed-off-by: Simar <simar@linux.com >
2023-05-21 10:20:15 +03:00
chenk
16af41be15
test: k8s integration tests ( #4423 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-05-18 22:41:22 +03:00
DmitriyLewen
cab8569cd7
feat(redhat): add package digest for rpm ( #4410 )
2023-05-18 14:30:00 +03:00
simar7
92f9e98d04
feat(misconf): Add --reset-policy-bundle for policy bundle ( #4167 )
2023-05-18 11:54:01 +03:00
guangwu
33fb04763d
fix: typo ( #4431 )
2023-05-18 10:09:26 +03:00
DmitriyLewen
8b162f287f
add user instruction to imgconf ( #4429 )
2023-05-18 08:53:34 +03:00
DmitriyLewen
3b7c9198dd
fix(k8s): add image sources ( #4411 )
2023-05-17 07:01:58 +03:00
simar7
c75d35ff61
docs(scanning): Add versioning banner ( #4415 )
2023-05-17 06:32:17 +03:00
DmitriyLewen
d298415c09
feat(cli): add mage command to update golden integration test files ( #4380 )
2023-05-16 13:58:50 +03:00
chenk
1a56295ff8
feat: node-collector custom namespace support ( #4407 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-05-16 13:41:01 +03:00
DmitriyLewen
864ad10a38
chore(deps): bump owenrumney/go-sarif from v2.1.3 to v2.2.0 ( #4378 )
2023-05-16 09:02:15 +03:00
DmitriyLewen
7a20d96227
refactor(sbom): use multiline json for spdx-json format ( #4404 )
2023-05-16 08:22:07 +03:00
Chris Novakovic
ea5fd75ffe
fix(ubuntu): add EOL date for Ubuntu 23.04 ( #4347 )
2023-05-16 05:21:45 +03:00
guangwu
56a01ec6f7
refactor: code-optimization ( #4214 )
2023-05-15 14:48:09 +03:00
Peter Engelbert
6a0e152657
feat(image): Add image-src flag to specify which runtime(s) to use ( #4047 )
...
Signed-off-by: Peter Engelbert <pmengelbert@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-05-15 14:42:42 +03:00
DmitriyLewen
50c8b418a9
test: skip wrong update of test golden files ( #4379 )
2023-05-15 11:35:50 +03:00
DmitriyLewen
51ca6536c3
refactor: don't return error for package.json without version/name ( #4377 )
2023-05-15 11:30:10 +03:00
guangwu
e5e7ebcdab
docs: cmd error ( #4376 )
2023-05-15 08:58:32 +03:00
DmitriyLewen
6ee4960776
test(cli): add test for config file and env combination ( #2666 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-05-15 08:56:56 +03:00
afdesk
c067b026e0
fix(report): set a correct file location for license scan output ( #4326 )
2023-05-14 15:27:13 +03:00
afdesk
ff6374829a
ci: rpm repository for all versions and aarch64 ( #4077 )
...
Co-authored-by: Franco Gil <45880759+realFranco@users.noreply.github.com >
2023-05-14 14:53:25 +03:00
Eugene Bykov
0009b02bb8
chore(alpine): Update Alpine to 3.18 ( #4351 )
2023-05-14 14:37:35 +03:00
Chris Novakovic
d61ae8cc73
fix(alpine): add EOL date for Alpine 3.18 ( #4308 )
2023-05-12 13:30:11 +03:00
dependabot[bot]
636ce808fe
chore(deps): bump github.com/docker/distribution ( #4337 )
2023-05-12 07:59:23 +03:00
Teppei Fukuda
e859d10eef
feat: allow root break for mapfs ( #4094 )
2023-05-11 14:41:17 +03:00
simar7
a6ef37fa3d
docs(misconf): Remove examples.md ( #4256 )
2023-05-10 20:41:18 +03:00
afdesk
dca8c039ed
fix(ubuntu): update eol dates for Ubuntu ( #4258 )
2023-05-10 18:10:12 +03:00
DmitriyLewen
b003f58b2c
feat(alpine): add digests for apk packages ( #4168 )
2023-05-10 16:37:50 +03:00
Teppei Fukuda
86f0016165
chore: add discussion templates ( #4190 )
2023-05-10 12:06:37 +03:00
simar7
2f318ce97d
fix(terraform): Support tfvars ( #4123 )
2023-05-10 11:18:19 +03:00
Teppei Fukuda
ec3906c24e
chore: separate docs:generate ( #4242 )
2023-05-10 09:08:31 +03:00
dependabot[bot]
37b25d28b2
chore(deps): bump github.com/aws/aws-sdk-go-v2/config ( #4246 )
2023-05-10 09:06:23 +03:00
Teppei Fukuda
45d5edb0d7
refactor: define vulnerability scanner interfaces ( #4117 )
2023-05-09 22:25:08 +03:00
chenk
090a00e717
feat: unified k8s scan resources ( #4188 )
2023-05-09 16:52:02 +03:00
simar7
f2188eb56d
chore(deps): Update defsec to v0.88.1 ( #4178 )
2023-05-09 16:34:29 +03:00
dependabot[bot]
b79850f416
chore(deps): bump github.com/alicebob/miniredis/v2 from 2.30.1 to 2.30.2 ( #4141 )
2023-05-09 16:01:12 +03:00
guangwu
36acdfa8db
chore: trivy bin ignore ( #4212 )
2023-05-09 12:03:47 +03:00
Teppei Fukuda
55fb723a6e
feat(image): enforce image platform ( #4083 )
2023-05-08 21:04:22 +03:00
dependabot[bot]
9c87cb2710
chore(deps): bump github.com/owenrumney/go-sarif/v2 from 2.1.2 to 2.1.3 ( #4143 )
2023-05-08 12:07:30 +03:00
dependabot[bot]
21cf179f6b
chore(deps): bump github.com/docker/docker ( #4144 )
2023-05-07 21:56:16 +03:00
dependabot[bot]
fbf7a77aee
chore(deps): bump github.com/hashicorp/golang-lru/v2 from 2.0.1 to 2.0.2 ( #4146 )
2023-05-07 21:55:24 +03:00
dependabot[bot]
547391c224
chore(deps): bump aquaproj/aqua-installer from 2.0.2 to 2.1.1 ( #4140 )
2023-05-05 12:59:49 +03:00
DmitriyLewen
882bfdd782
fix(ubuntu): fix version selection logic for ubuntu esm ( #4171 )
2023-05-05 12:59:02 +03:00
dependabot[bot]
949cd10c0c
chore(deps): bump github.com/samber/lo from 1.37.0 to 1.38.1 ( #4147 )
2023-05-05 12:56:59 +03:00
dependabot[bot]
93bc162ca5
chore(deps): bump github.com/hashicorp/go-getter from 1.7.0 to 1.7.1 ( #4145 )
2023-05-04 15:06:52 +03:00
dependabot[bot]
57993ef673
chore(deps): bump sigstore/cosign-installer from 3.0.1 to 3.0.3 ( #4138 )
2023-05-04 13:55:10 +03:00
dependabot[bot]
dc4baeb359
chore(deps): bump github.com/testcontainers/testcontainers-go ( #4150 )
2023-05-04 13:53:27 +03:00
second-frank
25d0255dc3
chore: install.sh support for windows ( #4155 )
2023-05-04 13:48:58 +03:00
dependabot[bot]
73e54549f1
chore(deps): bump github.com/sigstore/rekor from 1.1.0 to 1.1.1 ( #4166 )
2023-05-04 13:44:02 +03:00
dependabot[bot]
08de7c613f
chore(deps): bump golang.org/x/crypto from 0.7.0 to 0.8.0 ( #4149 )
2023-05-03 12:23:58 +03:00
Anais Urlichs
ade4730fa7
docs: moving skipping files out of others ( #4154 )
...
Signed-off-by: AnaisUrlichs <urlichsanais@gmail.com >
2023-05-03 12:23:21 +03:00
Masahiro331
1be1e2e638
fix(spdx): add workaround for no src packages ( #4118 )
2023-04-28 07:16:21 +03:00
Teppei Fukuda
45bc9e0de4
test(golang): rename broken go.mod ( #4129 )
2023-04-28 07:02:59 +03:00
DmitriyLewen
3334e78fa3
feat(sbom): add supplier field ( #4122 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2023-04-27 14:31:49 +03:00
DmitriyLewen
27fb1bfdee
test(misconf): skip downloading of policies for tests #4126
2023-04-27 14:25:31 +03:00
DmitriyLewen
845ae31e5d
refactor: use debug message for post-analyze errors ( #4037 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-27 12:07:35 +03:00
Teppei Fukuda
11a5b91a1a
feat(sbom): add VEX support ( #4053 )
2023-04-27 10:21:06 +03:00
DmitriyLewen
5eab464987
feat(sbom): add primary package purpose field for SPDX ( #4119 )
2023-04-25 14:47:25 +03:00
chenk
a00d00eb94
fix(k8s): fix quiet flag ( #4120 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-04-25 14:46:37 +03:00
DmitriyLewen
9bc326909f
fix(python): parse of pip extras ( #4103 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-24 21:17:56 +03:00
DmitriyLewen
8559841677
feat(java): use full path for nested jars ( #3992 )
2023-04-24 13:45:41 +03:00
Adarsh A
0650e0e1d5
feat(license): add new flag for classifier confidence level ( #4073 )
...
Co-authored-by: Aswath S <aswath.s@thoughtworks.com >
2023-04-24 13:41:08 +03:00
chenk
43b6496274
feat: config and fs compliance support ( #4097 )
2023-04-24 11:49:19 +03:00
dependabot[bot]
9181bc1f70
chore(deps): bump sigstore/cosign-installer from 2.8.1 to 3.0.1 ( #3952 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-04-24 08:43:07 +03:00
Idan Frimark
48e021ea6b
feat(spdx): add support for SPDX 2.3 ( #4058 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-23 23:36:04 +03:00
chenk
107752df65
fix: k8s all-namespaces support ( #4096 )
2023-04-23 20:08:37 +03:00
Teppei Fukuda
bd0c60364a
perf(misconf): replace with post-analyzers ( #4090 )
...
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: Simar <simar@linux.com >
2023-04-23 19:22:46 +03:00
bgoareguer
76662d5dd7
fix(helm): update networking API version detection ( #4106 )
2023-04-23 10:50:40 +03:00
aswath-s-tw
be47b688c7
feat(image): custom docker host option ( #3599 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-20 22:10:51 +03:00
Chris Burns
cc18f92cf3
style: debug flag is incorrect and needs extra - ( #4087 )
2023-04-19 10:02:44 +03:00
Jonathan Lassoff
572a6193e7
docs(vuln): Document inline vulnerability filtering comments ( #4024 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-18 12:02:14 +03:00
Teppei Fukuda
914c6f0921
feat(fs): customize error callback during fs walk ( #4038 )
2023-04-17 16:51:51 +03:00
DmitriyLewen
3f02feeff3
fix(ubuntu): skip copyright files from subfolders ( #4076 )
2023-04-17 14:07:58 +03:00
Teppei Fukuda
57bb77c060
docs: restructure scanners ( #3977 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-04-17 11:54:31 +03:00
DmitriyLewen
b19b56c341
fix: fix file does not exist error for post-analyzers ( #4061 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-17 08:15:44 +03:00
simar7
b43b19ba54
feat(flag): Support globstar for --skip-files and --skip-directories ( #4026 )
...
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-16 13:48:20 +03:00
dependabot[bot]
14805002d3
chore(deps): bump actions/stale from 7 to 8 ( #3955 )
2023-04-16 13:40:12 +03:00
DmitriyLewen
83bb97ab13
fix: return insecure option to download javadb ( #4064 )
2023-04-15 08:26:50 +03:00
DmitriyLewen
79a1ba32d5
fix(nodejs): don't stop parsing when unsupported yarn.lock protocols are found ( #4052 )
2023-04-14 07:35:51 +03:00
afdesk
ff1c43a791
ci: add gpg signing for RPM packages ( #4056 )
2023-04-14 07:28:44 +03:00
chenk
b608b116cc
fix(k8s): current context title ( #4055 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-04-13 17:56:22 +03:00
chenk
2c3b60f4c9
fix(k8s): quit support on k8s progress bar ( #4021 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-04-13 17:30:54 +03:00
afdesk
a6b8642134
chore: add a note about Dockerfile.canary ( #4050 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-13 17:27:28 +03:00
afdesk
90b80662c6
ci: fix path to canary binaries ( #4045 )
2023-04-13 10:27:06 +03:00
AliDatadog
dcefc6bf3c
fix(vuln): report architecture for debian packages ( #4032 )
2023-04-12 15:51:12 +03:00
Dan Luhring
601e25fb2f
feat: add support for Chainguard's commercial distro ( #3641 )
2023-04-12 15:20:52 +03:00
afdesk
0bebec19f0
ci: bump goreleaser for Github Action from 1.4.1 to 1.16.2 ( #3979 )
2023-04-12 15:15:16 +03:00
AliDatadog
707ea94234
fix(vuln): fix error message for remote scanners ( #4031 )
2023-04-11 16:50:45 +03:00
Teppei Fukuda
8e1fe769e4
feat(report): add image metadata to SARIF ( #4020 )
...
* feat(report): add image metadata to SARIF
* test: fix sarif golden
2023-04-11 16:33:25 +03:00
DmitriyLewen
4b36e97dce
docs: fix broken cache link on Installation page ( #3999 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-10 15:38:03 +03:00
Teppei Fukuda
f0df725c5a
fix: lock downloading policies and database ( #4017 )
2023-04-10 15:37:13 +03:00
Teppei Fukuda
009675c825
fix: avoid concurrent access to the global map ( #4014 )
2023-04-10 12:30:08 +03:00
DmitriyLewen
3ed86aa3d0
feat(rust): add Cargo.lock v3 support ( #4012 )
2023-04-10 11:46:43 +03:00
chenk
f31dea4bd6
feat: auth support oci download server subcommand ( #4008 )
2023-04-10 08:26:17 +03:00
dependabot[bot]
d37c50a2b3
chore(deps): bump github.com/docker/docker ( #4009 )
2023-04-09 22:29:13 +03:00
Yousaf Nabi
693d20516b
chore: install.sh support for armv7 ( #3985 )
2023-04-09 22:18:13 +03:00
dependabot[bot]
65d89b99d1
chore(deps): bump github.com/Azure/go-autorest/autorest/adal ( #3961 )
2023-04-09 15:58:06 +03:00
DmitriyLewen
a119ef86ea
fix(rust): fix panic when 'dependencies' field is not used in cargo.toml ( #3997 )
2023-04-09 11:06:57 +03:00
DmitriyLewen
c8283cebde
fix(sbom): fix infinite loop for cyclonedx ( #3998 )
2023-04-09 09:10:02 +03:00
dependabot[bot]
6c8b042548
chore(deps): bump helm/chart-testing-action from 2.3.1 to 2.4.0 ( #3954 )
2023-04-04 16:15:26 +03:00
DmitriyLewen
c42f360f57
fix: use warning for errors from enrichment files for post-analyzers ( #3972 )
2023-04-04 16:11:07 +03:00
dependabot[bot]
20c21caccf
chore(deps): bump github.com/docker/docker ( #3963 )
2023-04-04 14:06:41 +03:00
Rewanth Tammana
54388ffd16
fix(helm): added annotation to psp configurable from values ( #3893 )
...
Signed-off-by: Rewanth Tammana <22347290+rewanthtammana@users.noreply.github.com >
2023-04-03 11:24:43 +03:00
dependabot[bot]
99a2519816
chore(deps): bump github.com/go-git/go-git/v5 from 5.5.2 to 5.6.1 ( #3962 )
2023-04-03 11:23:30 +03:00
afdesk
d113b93139
fix(secret): update built-in rule tests ( #3855 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2023-04-03 10:37:08 +03:00
dependabot[bot]
5ab6d25880
chore(deps): bump github.com/alicebob/miniredis/v2 from 2.23.0 to 2.30.1 ( #3957 )
2023-04-03 10:32:13 +03:00
Teppei Fukuda
0767cb8443
test: rewrite scripts in Go ( #3968 )
2023-04-03 10:31:10 +03:00
simar7
428ee19cae
docs(cli): Improve glob documentation ( #3945 )
...
Signed-off-by: Simar <simar@linux.com >
2023-04-03 07:59:02 +03:00
dependabot[bot]
3e00dc346f
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/sts ( #3959 )
2023-04-03 07:57:54 +03:00
Teppei Fukuda
cf2f0b2d1c
ci: check CLI references ( #3967 )
2023-04-03 07:57:08 +03:00
dependabot[bot]
70f507e1af
chore(deps): bump alpine from 3.17.2 to 3.17.3 ( #3951 )
2023-04-03 06:37:49 +03:00
dependabot[bot]
befabc6b99
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.212 to 1.44.234 ( #3956 )
2023-04-03 06:36:35 +03:00
dependabot[bot]
ee69abb78f
chore(deps): bump github.com/moby/buildkit from 0.11.4 to 0.11.5 ( #3958 )
2023-04-02 19:29:28 +03:00
dependabot[bot]
8901f7be62
chore(deps): bump actions/setup-go from 3 to 4 ( #3953 )
2023-04-02 19:28:40 +03:00
dependabot[bot]
4e6bbbc8cc
chore(deps): bump actions/cache from 3.2.6 to 3.3.1 ( #3950 )
2023-04-02 19:28:10 +03:00
dependabot[bot]
d70f346f53
chore(deps): bump github.com/containerd/containerd from 1.6.19 to 1.7.0 ( #3965 )
2023-04-02 16:27:22 +03:00
dependabot[bot]
3efb2fdeda
chore(deps): bump github.com/sigstore/rekor from 1.0.1 to 1.1.0 ( #3964 )
2023-04-02 10:49:41 +03:00
Krishna Dutt Panchagnula
ed590966a3
docs(cli): added makefile and go file to create docs ( #3930 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2023-04-01 08:43:21 +03:00
Teppei Fukuda
a2f39a34c5
chore: Revert "ci: add gpg signing for RPM packages ( #3612 )" ( #3946 )
...
This reverts commit 67572dff6d .
2023-04-01 08:39:22 +03:00
Teppei Fukuda
5a10631023
chore: ignore gpg key ( #3943 )
2023-04-01 06:39:31 +03:00
afdesk
4072115e5a
feat(cyclonedx): support dependency graph ( #3177 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-04-01 00:46:30 +03:00
simar7
7cad265b7a
chore(deps): Bump defsec to v0.85.0 ( #3940 )
...
Signed-off-by: Simar <simar@linux.com >
2023-03-31 16:58:01 +03:00
DmitriyLewen
f8b5733112
feat(rust): remove dev deps and find direct deps for Cargo.lock ( #3919 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-30 22:05:34 +03:00
Rо́man
10796a2910
feat(server): redis with public TLS certs support ( #3783 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-30 15:53:21 +03:00
simar7
abff1398c2
feat(flag): Add glob support to --skip-dirs and --skip-files ( #3866 )
2023-03-30 10:48:56 +03:00
Teppei Fukuda
b40f60c405
chore: replace make with mage ( #3932 )
2023-03-30 10:40:24 +03:00
DmitriyLewen
67236f6aac
fix(sbom): add checksum to files ( #3888 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-30 09:24:27 +03:00
dependabot[bot]
00de24b16e
chore(deps): bump github.com/opencontainers/runc from 1.1.4 to 1.1.5 ( #3928 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-30 09:23:39 +03:00
chenk
5976d1fa07
chore: remove unused mount volumes ( #3927 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-03-30 07:33:03 +03:00
Teppei Fukuda
f14bed4532
feat: add auth support for downloading OCI artifacts ( #3915 )
2023-03-30 05:53:24 +03:00
DmitriyLewen
1ee05189f0
refactor(purl): use epoch in qualifier ( #3913 )
2023-03-28 13:26:56 +03:00
dependabot[bot]
0000252ce4
chore(deps): bump github.com/in-toto/in-toto-golang from 0.5.0 to 0.7.0 ( #3727 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-28 13:22:47 +03:00
Teppei Fukuda
ca0d972cdb
feat(image): add registry options ( #3906 )
2023-03-28 07:00:04 +03:00
AndreyLevchenko
0336555773
feat(rust): dependency tree and line numbers support for cargo lock file ( #3746 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-26 14:43:45 +03:00
dependabot[bot]
dd9cd9528f
chore(deps): bump google.golang.org/protobuf from 1.29.0 to 1.29.1 ( #3905 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-26 13:20:02 +03:00
DmitriyLewen
edb06826b4
feat(php): add support for location, licenses and graph for composer.lock files ( #3873 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-26 12:02:53 +03:00
Crypt Keeper
c02b15b371
chore(deps): updates wazero to 1.0.0 ( #3904 )
...
Signed-off-by: Adrian Cole <adrian@tetrate.io >
2023-03-26 08:50:38 +03:00
Teppei Fukuda
63ef760c69
feat(image): discover SBOM in OCI referrers ( #3768 )
...
Co-authored-by: saso <sasoakira6114@gmail.com >
2023-03-26 08:27:10 +03:00
DmitriyLewen
3fa703c034
docs: change cache-dir key in config file ( #3897 )
2023-03-24 19:12:14 +03:00
DmitriyLewen
4d78747c40
fix(sbom): use release and epoch for SPDX package version ( #3896 )
2023-03-24 19:11:06 +03:00
afdesk
67572dff6d
ci: add gpg signing for RPM packages ( #3612 )
2023-03-24 06:46:18 +03:00
adamcohen2
e76d5ff98a
docs: Update incorrect comment for skip-update flag ( #3878 )
2023-03-23 07:25:01 +02:00
Teppei Fukuda
011ea60db4
refactor(misconf): simplify policy filesystem ( #3875 )
2023-03-23 06:27:29 +02:00
DmitriyLewen
6445309de4
feat(nodejs): parse package.json alongside yarn.lock ( #3757 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-21 19:13:02 +02:00
DmitriyLewen
6e9c2c36da
fix(spdx): add PkgDownloadLocation field ( #3879 )
2023-03-21 16:11:38 +02:00
DmitriyLewen
18eeea2f62
fix(report): try to guess direct deps for dependency tree ( #3852 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-21 12:55:07 +02:00
DmitriyLewen
02b6914212
chore(amazon): update EOL ( #3876 )
2023-03-21 07:11:56 +02:00
DmitriyLewen
79096e1161
fix(nodejs): improvement logic for package-lock.json v2-v3 ( #3877 )
2023-03-21 07:06:34 +02:00
DmitriyLewen
fc2e80cfe0
feat(amazon): add al2023 support ( #3854 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-20 15:56:16 +02:00
dependabot[bot]
5f8d69d72e
chore(deps): bump github.com/cheggaaa/pb/v3 from 3.1.0 to 3.1.2 ( #3736 )
2023-03-20 14:13:30 +02:00
simar7
7916aafffb
docs(misconf): Add information about selectors ( #3703 )
...
Signed-off-by: Simar <simar@linux.com >
2023-03-20 14:12:35 +02:00
Shubham Palriwala
1b1ed39c7d
docs(cli): update CLI docs with cobra ( #3815 )
2023-03-20 13:48:58 +02:00
chenk
234a360a7a
feat: k8s parallel processing ( #3693 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-20 13:34:38 +02:00
bgoareguer
b864b3b926
docs: add DefectDojo in the Security Management section ( #3871 )
2023-03-20 11:38:26 +02:00
Crypt Keeper
ad34c989de
chore(deps): updates wazero to 1.0.0-rc.2 ( #3853 )
...
Signed-off-by: Adrian Cole <adrian@tetrate.io >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-19 19:56:01 +02:00
Teppei Fukuda
7148de3252
refactor: add pipeline ( #3868 )
2023-03-19 19:55:36 +02:00
DmitriyLewen
927acf9579
feat(cli): add javadb metadata to version info ( #3835 )
2023-03-19 15:51:14 +02:00
simar7
33074cfab3
chore(deps): Move compliance types to defsec ( #3842 )
...
Signed-off-by: Simar <simar@linux.com >
2023-03-19 15:46:06 +02:00
saso
ba9b0410c9
feat(sbom): add support for CycloneDX JSON Attestation of the correct specification ( #3849 )
2023-03-19 15:40:58 +02:00
chenk
a754a04e2b
feat: add node toleration option ( #3823 )
2023-03-19 14:05:57 +02:00
Teppei Fukuda
9e4b57fb43
fix: allow mapfs to open dirs ( #3867 )
2023-03-19 13:33:50 +02:00
DmitriyLewen
09fd299f96
fix(report): update uri only for os class targets ( #3846 )
2023-03-17 10:15:24 +02:00
DmitriyLewen
09e13022c2
feat(nodejs): Add v3 npm lock file support ( #3826 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-15 21:54:59 +02:00
DmitriyLewen
52cbfebcdd
feat(nodejs): parse package.json files alongside package-lock.json ( #2916 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-15 21:54:01 +02:00
simar7
d6a2d6369a
docs(misconf): Fix links to built in policies ( #3841 )
...
Signed-off-by: Simar <simar@linux.com >
2023-03-15 11:47:44 +02:00
dependabot[bot]
a12f58be57
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.86.1 to 1.89.1 ( #3827 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-14 11:17:36 +02:00
DmitriyLewen
ee518350c5
fix(java): skip empty files for jar post analyzer ( #3832 )
2023-03-14 11:15:31 +02:00
DmitriyLewen
3987a679f9
fix(docker): build healthcheck command for line without /bin/sh prefix ( #3831 )
2023-03-14 09:28:36 +02:00
Teppei Fukuda
2bb25e766b
refactor(license): use goyacc for license parser ( #3824 )
2023-03-14 09:27:17 +02:00
dependabot[bot]
00c763bc10
chore(deps): bump github.com/docker/docker from 23.0.0-rc.1+incompatible to 23.0.1+incompatible ( #3586 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-13 17:33:07 +02:00
chenk
cac5881bbb
fix: populate timeout context to node-collector ( #3766 )
2023-03-13 13:10:37 +02:00
chenk
bd9c6e613e
fix: exclude node collector scanning ( #3771 )
2023-03-13 11:40:23 +02:00
Ari Yonaty
20f10673b9
fix: display correct flag in error message when skipping java db update #3808
2023-03-13 00:39:17 +02:00
DmitriyLewen
1fac7bf1ba
fix: disable jar analyzer for scanners other than vuln ( #3810 )
2023-03-13 00:11:25 +02:00
Masahiro331
aaf265881e
fix(sbom): fix incompliant license format for spdx ( #3335 )
2023-03-12 17:21:25 +02:00
DmitriyLewen
f8307635ad
fix(java): the project props take precedence over the parent's props ( #3320 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-09 19:25:52 +02:00
DmitriyLewen
1aa3b7dc28
docs: add canary build info to README.md ( #3799 )
2023-03-09 13:36:04 +02:00
Anais Urlichs
57904c0f97
docs: adding link to gh token generation ( #3784 )
2023-03-08 14:24:02 +02:00
Anais Urlichs
bdccf72338
docs: changing docs in accordance with #3460 ( #3787 )
2023-03-08 14:23:17 +02:00
dependabot[bot]
800473a8bc
chore(deps): bump github.com/moby/buildkit from 0.11.0 to 0.11.4 ( #3789 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-08 11:51:16 +02:00
dependabot[bot]
e6ab389f9e
chore(deps): bump actions/add-to-project from 0.4.0 to 0.4.1 ( #3724 )
2023-03-07 13:35:06 +02:00
DmitriyLewen
6614398ab4
fix(license): disable jar analyzer for licence scan only ( #3780 )
2023-03-07 13:22:23 +02:00
DmitriyLewen
1dc6fee781
bump trivy-issue-action to v0.0.0; skip pkg dir ( #3781 )
2023-03-07 11:52:32 +02:00
DmitriyLewen
3357ed096b
fix: skip checking dirs for required post-analyzers ( #3773 )
2023-03-06 13:29:35 +02:00
afdesk
1064636b3d
docs: add information about plugin format ( #3749 )
2023-03-06 11:27:30 +02:00
DmitriyLewen
60b7ef5a55
fix(sbom): add trivy version to spdx creators tool field ( #3756 )
...
* fix(sbom): add trivy version to spdx creators tool field
* refactor test
2023-03-03 10:41:39 +02:00
simar7
497c955a4b
feat(misconf): Add support to show policy bundle version ( #3743 )
...
Fixes: https://github.com/aquasecurity/trivy/issues/3696
Signed-off-by: Simar <simar@linux.com >
2023-03-02 17:00:45 +02:00
Andrea Scarpino
5d54310d76
fix(python): fix error with optional dependencies in pyproject.toml ( #3741 )
2023-03-02 16:58:03 +02:00
dependabot[bot]
44cf1e2f57
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.210 to 1.44.212 ( #3740 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-02 15:18:51 +02:00
DmitriyLewen
743b4b0d97
add id for package.json files ( #3750 )
2023-03-02 14:25:56 +02:00
dependabot[bot]
6de43855f8
chore(deps): bump github.com/containerd/containerd from 1.6.18 to 1.6.19 ( #3738 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-02 13:20:32 +02:00
dependabot[bot]
9a0ceef166
chore(deps): bump actions/cache from 3.2.4 to 3.2.6 ( #3725 )
2023-03-01 23:14:17 +02:00
dependabot[bot]
0501b46d48
chore(deps): bump github.com/google/go-containerregistry ( #3731 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-01 23:13:31 +02:00
dependabot[bot]
ee3004d292
chore(deps): bump go.etcd.io/bbolt from 1.3.6 to 1.3.7 ( #3732 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-01 20:53:53 +02:00
dependabot[bot]
5c8e604f56
chore(deps): bump alpine from 3.17.1 to 3.17.2 ( #3723 )
2023-03-01 20:53:30 +02:00
Teppei Fukuda
bc0836623c
fix(cli): pass integer to exit-on-eol ( #3716 )
2023-03-01 12:18:11 +02:00
Itay Shakury
23cdac02ee
feat: add kubernetes pss compliance ( #3498 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-01 12:10:34 +02:00
Kalyana Krishna Varanasi
302c8ae24c
feat: Adding --module-dir and --enable-modules ( #3677 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-03-01 12:09:53 +02:00
Teppei Fukuda
34120f4201
feat: add special IDs for filtering secrets ( #3702 )
2023-03-01 09:51:11 +02:00
simar7
e399ed8439
chore(deps): Update defsec ( #3713 )
...
* chore(deps): Update defsec
* fix tests
2023-03-01 08:10:03 +02:00
simar7
ef7b762e48
docs(misconf): Add guide on input schema ( #3692 )
...
* docs(misconf): Add guide on input schema
* Update docs/docs/misconfiguration/custom/schema.md
Co-authored-by: Itay Shakury <itay@itaysk.com >
* make schema usage more descriptive
* docs: point to the full page
* update docs
Signed-off-by: Simar <simar@linux.com >
---------
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: Itay Shakury <itay@itaysk.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-28 15:55:49 -08:00
Teppei Fukuda
00daebc161
feat(go): support dependency graph and show only direct dependencies in the tree ( #3691 )
2023-02-28 13:24:53 +02:00
chenk
98d1031552
feat: docker multi credential support ( #3631 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-02-28 11:42:37 +02:00
Teppei Fukuda
b791362871
feat: summarize vulnerabilities in compliance reports ( #3651 )
2023-02-28 00:09:00 +02:00
Teppei Fukuda
719fdb1b11
feat(python): parse pyproject.toml alongside poetry.lock ( #3695 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-02-27 20:48:55 +02:00
DmitriyLewen
3ff5699b4b
feat(python): add dependency tree for poetry lock file ( #3665 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-26 16:15:00 +02:00
Masahiro331
33909d9df3
fix(cyclonedx): incompliant affect ref ( #3679 )
2023-02-26 16:04:29 +02:00
Manuel Morejón
d85a3e087b
chore(helm): update skip-db-update environment variable ( #3657 )
...
Signed-off-by: Manuel Morejon <manuel@mmorejon.io >
2023-02-26 14:16:17 +02:00
Masahiro331
551899c24e
fix(spdx): change CreationInfo timestamp format RFC3336Nano to RFC3336 ( #3675 )
2023-02-26 10:11:47 +02:00
Teppei Fukuda
3aaa2cfb75
fix(sbom): export empty dependencies in CycloneDX ( #3664 )
2023-02-25 18:33:59 +02:00
Dmitry Ivankov
9d1300c3e7
docs: java-db air-gap doc tweaks ( #3561 )
...
Downloaded file name is `javadb.tar.gz` rather than `db.tar.gz`.
Also `--skip-update` is deprecated in favor of `--skip-db-update` and `--skip-java-db-update`.
2023-02-24 17:54:29 +02:00
Teppei Fukuda
793cc43d4c
feat(go): license support ( #3683 )
2023-02-24 17:52:35 +02:00
AndreyLevchenko
6a3294e476
feat(ruby): add dependency tree/location support for Gemfile.lock ( #3669 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-23 23:47:28 +02:00
chenk
e9dc21d88a
fix(k8s): k8s label size ( #3678 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-02-23 15:09:27 +02:00
Masahiro331
12976d42df
fix(cyclondx): fix array empty value, null to [] ( #3676 )
2023-02-23 13:35:59 +02:00
Teppei Fukuda
1dc2b349c6
refactor: rewrite gomod analyzer as post-analyzer ( #3674 )
2023-02-23 13:35:08 +02:00
chenk
92eaf636ca
feat: config outdated-api result filtered by k8s version ( #3578 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-22 15:41:37 +02:00
Alexander Lauster
9af436b999
fix: Update to Alpine 3.17.2 ( #3655 )
...
Fix CVE-2023-0286
2023-02-21 19:38:20 +02:00
Teppei Fukuda
88ee68d0c6
feat: add support for virtual files ( #3654 )
2023-02-20 17:20:57 +02:00
Teppei Fukuda
75c96bd968
feat: add post-analyzers ( #3640 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2023-02-20 13:08:26 +02:00
Edoardo Vacchi
baea3997d2
chore(deps): updates wazero to 1.0.0-pre.9 ( #3653 )
...
Signed-off-by: Edoardo Vacchi <evacchi@users.noreply.github.com >
2023-02-20 13:03:28 +02:00
dependabot[bot]
7ca0db17ea
chore(deps): bump github.com/go-openapi/runtime from 0.24.2 to 0.25.0 ( #3528 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-20 13:01:33 +02:00
dependabot[bot]
866999e454
chore(deps): bump github.com/containerd/containerd from 1.6.15 to 1.6.18 ( #3633 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-20 10:11:01 +02:00
DmitriyLewen
b7bfb9a207
feat(python): add dependency locations for Pipfile.lock ( #3614 )
2023-02-20 09:51:42 +02:00
dependabot[bot]
9badef27ac
chore(deps): bump golang.org/x/net from 0.5.0 to 0.7.0 ( #3648 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-19 15:51:12 +02:00
DmitriyLewen
d856595b8e
fix(java): fix groupID selection by ArtifactID for jar files. ( #3644 )
2023-02-18 09:07:08 +02:00
dependabot[bot]
fe7c26a741
chore(deps): bump github.com/aws/aws-sdk-go-v2/service/ec2 from 1.63.1 to 1.85.0 ( #3607 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-17 12:44:55 +02:00
Gio Rodriguez
f251dfc5ce
fix(aws): Adding a fix for update-cache flag that is not applied on AWS scans. ( #3619 )
...
* adding a fix for update-cache that was not applied on AWS scans.
* removing unneeded code
---------
Co-authored-by: Gio Rodriguez <giovanni.rodriguez@aquasec.com >
2023-02-16 22:49:20 +02:00
didiermichel
9be8062c10
feat(cli): add command completion ( #3061 )
...
Co-authored-by: congbang-le <lecongbang314@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-15 13:29:03 +02:00
Duy Nguyen
370098dbf4
docs(misconf): update dockerfile link ( #3627 )
2023-02-15 11:54:56 +02:00
Jack Lin
32acd293fd
feat(flag): add exit-on-eosl option ( #3423 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-15 10:51:15 +02:00
dependabot[bot]
aa8e185e03
chore(deps): bump github.com/go-git/go-git/v5 from 5.4.2 to 5.5.2 ( #3533 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-14 16:17:28 +02:00
Alexej Disterhoft
86603bb9c5
fix(cli): make java db repository configurable ( #3595 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-14 15:01:15 +02:00
chenk
7b1e173f51
chore: bump trivy-kubernetes ( #3613 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-02-14 13:23:45 +02:00
Helge Eichelberg
85d5d61bc7
chore(helm): update Trivy from v0.36.1 to v0.37.2 ( #3574 )
...
* chore(helm): update Trivy from v0.36.1 to v0.37.1
Signed-off-by: elchenberg <elchenberg@users.noreply.github.com >
* chore(helm): bump Trivy to v0.37.2
Signed-off-by: elchenberg <elchenberg@users.noreply.github.com >
---------
Signed-off-by: elchenberg <elchenberg@users.noreply.github.com >
2023-02-14 13:10:07 +02:00
dependabot[bot]
2c17260ba8
chore(deps): bump github.com/spf13/viper from 1.14.0 to 1.15.0 ( #3536 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-14 13:09:43 +02:00
Teppei Fukuda
c54f1aa8f0
chore(deps): bump golang/x/mod to v0.8.0 ( #3606 )
2023-02-14 07:02:26 +02:00
dependabot[bot]
625ea58122
chore(deps): bump golang.org/x/crypto from 0.3.0 to 0.5.0 ( #3529 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-13 16:15:12 +02:00
dependabot[bot]
623c7f9432
chore(deps): bump helm.sh/helm/v3 from 3.10.3 to 3.11.1 ( #3580 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-13 16:14:25 +02:00
DmitriyLewen
d291c34f51
ci: quote pros in c++ for semantic pr ( #3605 )
2023-02-13 14:05:35 +02:00
DmitriyLewen
6cac6c917f
fix(image): check proxy settings from env for remote images ( #3604 )
2023-02-13 12:54:38 +02:00
DmitriyLewen
12b563b974
BREAKING: use normalized trivy-java-db ( #3583 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-10 02:16:37 +02:00
DmitriyLewen
72a14c67af
fix(image): add timeout for remote images ( #3582 )
...
* add timeout for remote image
* fix linter error
2023-02-09 14:19:17 +02:00
dependabot[bot]
4c01d73fb7
chore(deps): bump golang.org/x/mod from 0.6.0 to 0.7.0 ( #3532 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-07 08:38:25 +02:00
dependabot[bot]
10dd5d1a95
chore(deps): bump golang.org/x/text from 0.5.0 to 0.6.0 ( #3534 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2023-02-07 06:51:49 +02:00
simar7
439c541fd3
fix(misconf): handle dot files better ( #3550 )
2023-02-05 09:10:10 +09:00
Teppei Fukuda
200e04a767
chore: bump Go to 1.19 ( #3551 )
2023-02-03 15:08:01 +09:00
dependabot[bot]
a533ca87e6
chore(deps): bump alpine from 3.17.0 to 3.17.1 ( #3522 )
2023-02-03 04:21:25 +02:00
dependabot[bot]
4bccbe6e1c
chore(deps): bump docker/build-push-action from 3 to 4 ( #3523 )
2023-02-03 04:20:52 +02:00
dependabot[bot]
d0562085df
chore(deps): bump actions/cache from 3.2.2 to 3.2.4 ( #3524 )
2023-02-03 04:20:15 +02:00
dependabot[bot]
f5e65749b4
chore(deps): bump golangci/golangci-lint-action from 3.3.0 to 3.4.0 ( #3525 )
2023-02-03 04:17:39 +02:00
dependabot[bot]
d3da459d45
chore(deps): bump aquaproj/aqua-installer from 1.2.0 to 2.0.2 ( #3526 )
2023-02-03 04:15:56 +02:00
Teppei Fukuda
7f8868b7d8
fix(sbom): download the Java DB when generating SBOM ( #3539 )
2023-02-01 17:33:09 +02:00
Teppei Fukuda
364379b7b2
fix: use cgo free sqlite driver ( #3521 )
...
* fix: use cgo free sqlite driver
* chore: add CGO_ENABLED=0
* chore(deps): bump go-rpmdb
2023-02-01 17:06:12 +02:00
afdesk
0205475fa9
ci: fix path to dist folder ( #3527 )
2023-02-01 16:44:01 +02:00
Teppei Fukuda
e9d2af9174
fix(image): close layers ( #3517 )
2023-02-01 13:36:48 +02:00
Naimuddin Shaik
b169424089
refactor: db client changed ( #3515 )
...
changed the constructor to accept interface.
2023-02-01 13:15:36 +02:00
DmitriyLewen
7bf1e192ec
feat(java): use trivy-java-db to get GAV ( #3484 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-01 11:48:05 +02:00
Batuhan Apaydın
023e45b896
docs: add note about the limitation in Rekor ( #3494 )
...
Signed-off-by: Batuhan Apaydın <batuhan.apaydin@trendyol.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-02-01 11:14:47 +02:00
Teppei Fukuda
0fe62a93df
docs: aggregate targets ( #3503 )
2023-02-01 08:48:33 +02:00
Edoardo Vacchi
0373e0822d
deps: updates wazero to 1.0.0-pre.8 ( #3510 )
...
Signed-off-by: Edoardo Vacchi <evacchi@users.noreply.github.com >
2023-02-01 06:48:37 +02:00
DmitriyLewen
a2e21f9b5c
docs: add alma 9 and rocky 9 to supported os ( #3513 )
2023-02-01 06:47:26 +02:00
simar7
7d778b75f7
chore(deps): bump defsec to v0.82.9 ( #3512 )
2023-02-01 04:14:25 +02:00
Itay Shakury
9e9dbea717
chore: add missing target labels ( #3504 )
2023-01-31 17:20:56 +02:00
DmitriyLewen
d99a7b82f7
docs: add java vulnerability page ( #3429 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-31 08:10:24 +02:00
Teppei Fukuda
cb5af0b33b
feat(image): add support for Docker CIS Benchmark ( #3496 )
...
Co-authored-by: chenk <hen.keinan@gmail.com >
2023-01-31 07:31:59 +02:00
Teppei Fukuda
6eec9ac0a4
feat(image): secret scanning on container image config ( #3495 )
2023-01-30 16:50:56 +02:00
simar7
1eca973cbf
chore(deps): Upgrade defsec to v0.82.8 ( #3488 )
...
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-30 09:38:17 +02:00
Teppei Fukuda
fb0d8f3f30
feat(image): scan misconfigurations in image config ( #3437 )
2023-01-30 04:48:29 +02:00
Helge Eichelberg
501d424d1f
chore(helm): update Trivy from v0.30.4 to v0.36.1 ( #3489 )
...
Signed-off-by: elchenberg <elchenberg@users.noreply.github.com >
2023-01-28 07:12:08 +02:00
chenk
475dc17bc8
feat(k8s): add node info resource ( #3482 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2023-01-25 22:00:05 +02:00
kunlongli
ed173b8295
perf(secret): optimize secret scanning memory usage ( #3453 )
2023-01-25 11:45:09 +02:00
Teppei Fukuda
1b368be367
feat: support aliases in CLI flag, env and config ( #3481 )
2023-01-25 11:33:12 +02:00
chenk
66a83d5cdb
fix(k8s): migrate rbac k8s ( #3459 )
2023-01-25 11:13:41 +02:00
DmitriyLewen
81bee0f11e
feat(java): add implementationVendor and specificationVendor fields to detect GroupID from MANIFEST.MF ( #3480 )
2023-01-24 12:21:19 +02:00
Teppei Fukuda
e1076085d9
refactor: rename security-checks to scanners ( #3467 )
2023-01-23 16:53:06 +02:00
Teppei Fukuda
aaf845d02e
chore: display the troubleshooting URL for the DB denial error ( #3474 )
2023-01-23 16:12:00 +02:00
Corey Wilson
ed5bb0ba92
docs: yaml tabs to spaces, auto create namespace ( #3469 )
2023-01-23 10:51:55 +02:00
Anais Urlichs
3158bfe605
docs: adding show-and-tell template to GH discussions ( #3391 )
2023-01-22 17:34:09 +02:00
Lénaïc Huard
85b6c4aa15
fix: Fix a temporary file leak in case of error ( #3465 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-22 16:12:56 +02:00
Teppei Fukuda
60bddae64c
fix(test): sort cyclonedx components ( #3468 )
2023-01-22 14:21:20 +02:00
Anais Urlichs
e0bb04c915
docs: fixing spelling mistakes ( #3462 )
2023-01-22 14:18:15 +02:00
Teppei Fukuda
c25e826bb5
ci: set paths triggering VM tests in PR ( #3438 )
2023-01-22 11:35:19 +02:00
Raz Cohen
07ddc85a46
docs: typo in --skip-files ( #3454 )
2023-01-18 14:23:56 +02:00
Srinivas Kandukuri
e88507c999
feat(custom-forward): Extended advisory data ( #3444 )
2023-01-17 16:06:27 +02:00
Carl Winbäck
e2dfee208f
docs: fix spelling error ( #3436 )
2023-01-16 14:31:43 +00:00
Teppei Fukuda
c575d6f7de
refactor(image): extend image config analyzer ( #3434 )
2023-01-16 13:48:26 +02:00
Lior Vaisman Argon
036d5a8233
fix(nodejs): add ignore protocols to yarn parser ( #3433 )
2023-01-16 11:27:20 +02:00
DmitriyLewen
e6d7f15762
fix(db): check proxy settings when using insecure flag ( #3435 )
2023-01-16 10:40:27 +02:00
simar7
a1d4427c8b
feat(misconf): Fetch policies from OCI registry ( #3015 )
...
Signed-off-by: Simar <simar@linux.com >
2023-01-15 13:37:04 +02:00
DmitriyLewen
682351a131
ci: downgrade Go to 1.18 and use stable and oldstable go versions for unit tests ( #3413 )
...
* use stable and oldstable go versions for unit tests
* downgrade Go to 1.18
2023-01-15 12:03:15 +02:00
afdesk
ff0c4516db
ci: store URLs to Github Releases in RPM repository ( #3414 )
2023-01-15 11:59:18 +02:00
DmitriyLewen
ee12442b8d
feat(server): add support of skip-db-update flag for hot db update ( #3416 )
2023-01-15 10:28:50 +02:00
DmitriyLewen
2033e05b6b
chore(deps): bump github.com/moby/buildkit from v0.10.6 to v0.11.0 ( #3411 )
2023-01-12 08:45:07 +02:00
Teppei Fukuda
6bc564e887
fix(image): handle wrong empty layer detection ( #3375 )
2023-01-11 20:17:12 +02:00
DmitriyLewen
b3b8d4dd6e
test: fix integration tests for spdx and cycloneDX ( #3412 )
2023-01-11 14:02:10 +02:00
Matthieu Maitre
b88bccae6e
feat(python): Include Conda packages in SBOMs ( #3379 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-10 16:11:17 +02:00
DmitriyLewen
fbd8a13d54
feat: add support pubspec.lock files for dart ( #3344 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-10 13:34:53 +02:00
Kalyana Krishna Varanasi
0f545cfa96
fix(image): parsePlatform is failing with UNAUTHORIZED error ( #3326 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-10 13:26:57 +02:00
DmitriyLewen
76c883dc43
fix(license): change normalize for GPL-3+-WITH-BISON-EXCEPTION ( #3405 )
2023-01-10 09:24:11 +00:00
Jack Lin
a8b671bc29
feat(server): log errors on server side ( #3397 )
2023-01-10 10:21:31 +02:00
Teppei Fukuda
a5919ca363
chore(deps): bump defsec to address helm vulnerabilities ( #3399 )
2023-01-08 15:34:11 +02:00
Itay Shakury
89016da21e
docs: rewrite installation docs and general improvements ( #3368 )
...
improve installation guide, improve overview pages, rename cli section to docs
2023-01-08 15:16:03 +02:00
Itay Shakury
c3759c6d83
chore: update code owners ( #3393 )
2023-01-08 15:14:10 +02:00
Itay Shakury
044fb9761e
chore: test docs separately from code ( #3392 )
2023-01-08 11:10:31 +02:00
Teppei Fukuda
ad2e648b33
docs: use the formula maintained by Homebrew ( #3389 )
2023-01-05 16:25:57 +02:00
Max Usachev
ad25a776cc
docs: add Security Management section with SonarQube plugin
2023-01-05 14:59:47 +02:00
jerbob92
9039df4993
fix(deps): fix errors on yarn.lock files that contain local file reference ( #3384 )
2023-01-05 12:17:11 +02:00
Jack Lin
60cf4fe49f
feat(flag): early fail when the format is invalid ( #3370 )
2023-01-04 13:46:04 +02:00
dependabot[bot]
9470e3cd27
chore(deps): bump github.com/aws/aws-sdk-go from 1.44.136 to 1.44.171 ( #3366 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-03 20:53:50 +02:00
Olivier Jacques
d274d1568a
docs(aws): fix broken links ( #3374 )
2023-01-03 17:59:28 +02:00
dependabot[bot]
2a870f8a82
chore(deps): bump actions/stale from 6 to 7 ( #3360 )
2023-01-03 15:28:29 +02:00
dependabot[bot]
5974023b7f
chore(deps): bump helm/kind-action from 1.4.0 to 1.5.0 ( #3359 )
2023-01-03 15:23:58 +02:00
dependabot[bot]
02aa8c2c50
chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.6.0 to 0.7.0 ( #2974 )
...
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
Co-authored-by: masahiro331 <m_fujimura@r.recruit.co.jp >
2023-01-03 15:15:07 +02:00
dependabot[bot]
6e6171fead
chore(deps): bump azure/setup-helm from 3.4 to 3.5 ( #3358 )
2023-01-03 15:04:29 +02:00
dependabot[bot]
066f27792f
chore(deps): bump github.com/moby/buildkit from 0.10.4 to 0.10.6 ( #3173 )
2023-01-03 14:44:40 +02:00
dependabot[bot]
8cc3284106
chore(deps): bump goreleaser/goreleaser-action from 3 to 4 ( #3357 )
2023-01-03 14:19:00 +02:00
dependabot[bot]
8d71346143
chore(deps): bump github.com/containerd/containerd from 1.6.8 to 1.6.14 ( #3367 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-03 12:01:45 +02:00
Crypt Keeper
5b944d20ac
chore(go): updates wazero to v1.0.0-pre.7 ( #3355 )
...
Signed-off-by: Adrian Cole <adrian@tetrate.io >
2023-01-03 11:08:17 +02:00
dependabot[bot]
9c645b99e2
chore(deps): bump golang.org/x/text from 0.4.0 to 0.5.0 ( #3362 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2023-01-03 08:45:14 +02:00
dependabot[bot]
e2cd782d3a
chore(deps): bump actions/cache from 3.0.11 to 3.2.2 ( #3356 )
2023-01-02 15:59:36 +02:00
Itay Shakury
4813cf5cfd
docs: improve compliance docs ( #3340 )
2022-12-30 13:55:18 +02:00
Lior Vaisman Argon
025e5099d2
feat(deps): add yarn lock dependency tree ( #3348 )
2022-12-29 19:45:18 +02:00
chenk
4d59a1ef9b
fix: compliance change id and title naming ( #3349 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-29 17:46:50 +02:00
DmitriyLewen
eaa5bcf7d2
feat: add support for mix.lock files for elixir language ( #3328 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-29 15:18:51 +02:00
chenk
a888440922
feat: add k8s cis bench ( #3315 )
...
Signed-off-by: chenk <hen.keinan@gmail.com >
2022-12-28 20:38:48 +02:00
DmitriyLewen
62b369ee39
test: disable SearchLocalStoreByNameOrDigest test for non-amd64 arch ( #3322 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-28 13:02:25 +02:00
behara
c110c4e028
revert: cache merged layers ( #3334 )
...
This reverts commit 6b4ddaaef2 .
2022-12-28 10:01:01 +02:00
Masahiro331
bc759efdc3
feat(cyclonedx): add recommendation ( #3336 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-27 15:25:27 +02:00
DmitriyLewen
fe3831e0fe
feat(ubuntu): added support ubuntu ESM versions ( #1893 )
...
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-27 10:24:28 +02:00
DmitriyLewen
b0cebec324
fix: change logic to build relative paths for skip-dirs and skip-files ( #3331 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-26 17:38:31 +02:00
dependabot[bot]
a66d3fe3f0
chore(deps): bump github.com/hashicorp/golang-lru from 0.5.4 to 2.0.1 ( #3265 )
...
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: masahiro331 <m_fujimura@r.recruit.co.jp >
2022-12-25 12:39:26 +02:00
Owen Rumney
5190f9566b
feat: Adding support for Windows testing ( #3037 )
...
Signed-off-by: Owen Rumney <owen.rumney@aquasec.com >
Signed-off-by: knqyf263 <knqyf263@gmail.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-22 22:54:18 +02:00
gboer
b00f3c60f6
feat: add support for Alpine 3.17 ( #3319 )
2022-12-19 13:25:29 +02:00
Teppei Fukuda
a70f885113
docs: change PodFile.lock to Podfile.lock ( #3318 )
2022-12-19 13:24:26 +02:00
saso
1ec1fe64e8
fix(sbom): support for the detection of old CycloneDX predicate type ( #3316 )
2022-12-19 11:06:36 +02:00
lsoumille
68eda79357
feat(secret): Use .trivyignore for filtering secret scanning result ( #3312 )
2022-12-18 11:58:34 +02:00
Takeshi Yoneda
b95d435a6a
chore(go): remove experimental FS API usage in Wasm ( #3299 )
...
Signed-off-by: Takeshi Yoneda <takeshi@tetrate.io >
2022-12-18 11:55:53 +02:00
DmitriyLewen
ac6b7c3354
ci: add workflow to add issues to roadmap project ( #3292 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-18 10:32:39 +02:00
gmetaxo
cfabdf9138
fix(vuln): include duplicate vulnerabilities with different package paths in the final report ( #3275 )
...
* Add test for filter with both duplicates and different package paths
* Add package path in key of uniqVulns map
* Add package path to the sorting logic
2022-12-15 19:21:54 +02:00
dependabot[bot]
56e3d8de09
chore(deps): bump github.com/spf13/viper from 1.13.0 to 1.14.0 ( #3250 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-15 16:29:58 +02:00
Masahiro331
bbccb4484a
feat(sbom): better support for third-party SBOMs ( #3262 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-15 16:20:21 +02:00
DmitriyLewen
e879b0697c
docs: add information about languages with support for dependency locations ( #3306 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2022-12-15 15:25:40 +02:00
tockn
e92266f2c8
feat(vm): add region option to vm scan to be able to scan any region's ami and ebs snapshots ( #3284 )
...
Co-authored-by: Teppei Fukuda <knqyf263@gmail.com >
2022-12-15 12:21:05 +02:00
dependabot[bot]
01c7fb14bc
chore(deps): bump github.com/Azure/azure-sdk-for-go from 66.0.0+incompatible to 67.1.0+incompatible ( #3251 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-13 19:46:54 +02:00
DmitriyLewen
23d0613879
fix(vuln): change severity vendor priority for ghsa-ids and vulns from govuln ( #3255 )
2022-12-13 17:29:43 +02:00
Itay Shakury
407c2407d1
docs: remove comparisons ( #3289 )
2022-12-13 11:13:56 +02:00
Dan Luhring
93c5d2dc71
feat: add support for Wolfi Linux ( #3215 )
2022-12-12 22:43:44 +02:00
DmitriyLewen
2809794964
ci: add go.mod to canary workflow ( #3288 )
2022-12-12 22:40:14 +02:00
Catminusminus
08b55c3347
feat(python): skip dev dependencies ( #3282 )
...
This commit bumps the go-dep-parser version. This revents Trivy from detecting vulnerabilities in Poetry dev-dependency, so the document is also updated.
Co-authored-by: DmitriyLewen <dmitriy.lewen@smartforce.io >
2022-12-12 15:04:48 +02:00
afdesk
52300e6069
chore: update ubuntu version for Github action runnners ( #3257 )
...
* chore: update ubuntu version for Github action runnners
* update the ubuntu version for docs actions
2022-12-12 11:09:46 +02:00
DmitriyLewen
a7ac6acaa2
fix(go): skip dep without Path for go-binaries ( #3254 )
2022-12-12 11:04:57 +02:00
DmitriyLewen
4436a202ff
feat(rust): add ID for cargo pgks ( #3256 )
2022-12-12 07:40:15 +02:00
dependabot[bot]
34d505ad14
chore(deps): bump github.com/samber/lo from 1.33.0 to 1.36.0 ( #3263 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-11 19:21:31 +02:00
dependabot[bot]
ea956026c8
chore(deps): bump github.com/Masterminds/sprig/v3 from 3.2.2 to 3.2.3 ( #3253 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-11 19:16:10 +02:00
DmitriyLewen
aea298b3dc
feat: add support for swift cocoapods lock files ( #2956 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-11 19:15:10 +02:00
Teppei Fukuda
c67fe17b4e
fix(sbom): use proper constants ( #3286 )
2022-12-11 15:56:48 +02:00
dependabot[bot]
f907255672
chore(deps): bump golang.org/x/term from 0.1.0 to 0.3.0 ( #3278 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-11 15:33:28 +02:00
Teppei Fukuda
8f95743502
test(vm): import relevant analyzers ( #3285 )
2022-12-11 15:02:43 +02:00
Pikaqiu
8744534c28
feat: support scan remote repository ( #3131 )
...
Co-authored-by: AMF <work@afdesk.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-11 11:57:04 +02:00
DmitriyLewen
c278d86614
docs: fix typo in fluxcd ( #3268 )
2022-12-08 10:55:14 +02:00
Ari Yonaty
fa2281f723
docs: fix broken "ecosystem" link in readme ( #3280 )
2022-12-08 10:43:23 +02:00
simar7
a3eece4fef
feat(misconf): Add compliance check support ( #3130 )
...
Signed-off-by: Simar <simar@linux.com >
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-07 22:42:59 +02:00
hriprsd
7a6cf5a27c
docs: Adding Concourse resource for trivy ( #3224 )
2022-12-04 16:22:10 +02:00
dependabot[bot]
dd26bd2306
chore(deps): change golang from 1.19.2 to 1.19 ( #3249 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-12-04 11:03:02 +02:00
Masahiro331
cbba6d101a
fix(sbom): duplicate dependson ( #3261 )
2022-12-04 10:48:02 +02:00
dependabot[bot]
fa2e3ac2c1
chore(deps): bump alpine from 3.16.2 to 3.17.0 ( #3247 )
2022-12-04 10:24:56 +02:00
Crypt Keeper
5c434753ce
chore(go): updates wazero to 1.0.0-pre.4 ( #3242 )
...
Signed-off-by: Adrian Cole <adrian@tetrate.io >
2022-12-04 10:17:37 +02:00
DmitriyLewen
d29b0edcc7
feat(report): add dependency locations to sarif format ( #3210 )
2022-12-01 13:23:58 +02:00
Masahiro331
967e32f4a2
fix(rpm): add rocky to osVendors ( #3241 )
2022-12-01 12:44:21 +02:00
tsanva
947741660b
docs: fix a typo ( #3236 )
2022-11-30 11:56:45 +02:00
DmitriyLewen
97ce61eef0
feat(dotnet): add dependency parsing for nuget lock files ( #3222 )
...
Co-authored-by: knqyf263 <knqyf263@gmail.com >
2022-11-29 16:15:46 +02:00
Max Fröhlich
17e13c4dbd
docs: add pre-commit hook to community tools ( #3203 )
2022-11-29 16:15:17 +02:00
Cyril Jouve
b1a2c4e9c8
feat(helm): pass arbitrary env vars to trivy ( #3208 )
2022-11-29 11:36:45 +02:00