s3cme
s3cme copied to clipboard
Bump aquasecurity/trivy-action from 0.16.1 to 0.19.0
Bumps aquasecurity/trivy-action from 0.16.1 to 0.19.0.
Release notes
Sourced from aquasecurity/trivy-action's releases.
v0.19.0
What's Changed
- bump trivy version to v0.50.1 by
@simar7
in aquasecurity/trivy-action#324Full Changelog: https://github.com/aquasecurity/trivy-action/compare/0.18.0...0.19.0
v0.18.0
What's Changed
- docs(report): improve documentation around
Using Trivy to generate SBOM
and sending it to Github by@Maxim-Durand
in aquasecurity/trivy-action#307- fix: Refer to scan-ref when scan-type is "sbom" by
@cococig
in aquasecurity/trivy-action#314New Contributors
@Maxim-Durand
made their first contribution in aquasecurity/trivy-action#307@cococig
made their first contribution in aquasecurity/trivy-action#314Full Changelog: https://github.com/aquasecurity/trivy-action/compare/0.17.0...0.18.0
v0.17.0
What's Changed
- docs: add configuration info for flags not supported by inputs by
@DmitriyLewen
in aquasecurity/trivy-action#296- fix: Fix
skip-files
andhide-progress
options not being applied when using Sarif report format by@simao-silva
in aquasecurity/trivy-action#297- Upgrades Trivy from 0.48.1 to v0.49.0 by
@kderck
in aquasecurity/trivy-action#304New Contributors
@simao-silva
made their first contribution in aquasecurity/trivy-action#297Full Changelog: https://github.com/aquasecurity/trivy-action/compare/0.16.1...0.17.0
Commits
d710430
bump trivy version to v0.50.1 (#324)062f259
fix: Refer to scan-ref when scan-type is "sbom" (#314)1f6384b
docs(report): improve documentation aroundUsing Trivy to generate SBOM
and...84384bd
Upgraded Trivy from 0.48.1 to v0.49.0 (#304)f3d9851
fix: Fixskip-files
andhide-progress
options not being applied when usin...0b9d17b
docs: add configuration info for flags not supported by inputs (#296)- See full diff in compare view
Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase
.
Dependabot commands and options
You can trigger Dependabot actions by commenting on this PR:
-
@dependabot rebase
will rebase this PR -
@dependabot recreate
will recreate this PR, overwriting any edits that have been made to it -
@dependabot merge
will merge this PR after your CI passes on it -
@dependabot squash and merge
will squash and merge this PR after your CI passes on it -
@dependabot cancel merge
will cancel a previously requested merge and block automerging -
@dependabot reopen
will reopen this PR if it is closed -
@dependabot close
will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually -
@dependabot show <dependency name> ignore conditions
will show all of the ignore conditions of the specified dependency -
@dependabot ignore this major version
will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this minor version
will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself) -
@dependabot ignore this dependency
will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)