v0.75.0 #11333
v0.75.0
#11333
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
📑 Table of Contents
uvworkspace support🌐 DNS lookup removed from report templates 🛑
The Sprig
getHostByNamefunction has been removed from report templates. Network access is not an intended use of report templates.Custom templates that call this function now fail to parse with
function "getHostByName" not defined. Remove these calls before upgrading.See the documentation for details.
🚀 What's new? 🚀
Cryptographic asset inventory (CBOM)
Trivy can now make an inventory of the cryptographic material in a container image and report it as a Cryptography Bill of Materials (CBOM) in the CycloneDX output.
The new
cryptoscanner reads X.509 certificates and private and public keys from.pem,.der,.crt,.cerand.keyfiles. Each certificate, key and algorithm becomes a CycloneDXcryptographic-assetcomponent with properties such as the algorithm, key size and validity period. Related assets are linked, so a certificate points to its key and to its signature algorithm. Post-quantum ML-DSA keys and signature algorithms are recognized too.A certificate or key found in several files and layers is reported once, with the list of places where it was found. Private key values never get into the report.
Usage:
The scanner is experimental and works only for container images with the CycloneDX output.
See the documentation for details and current limitations.
uvworkspace supportTrivy now supports uv workspaces in
uv.lockfiles.Workspace members are linked to the root package, as Trivy already does for Maven, Yarn and Cargo.
Their dependencies are no longer treated as development dependencies, so vulnerabilities in them are reported by default, without
--include-dev-deps.Lock files of virtual workspaces, which have no root package, are now parsed too.
Thanks to @drawliin
📂 Disable configuration file loading 🎛️
Explicitly empty
--configand--ignorefilevalues now disable loading their respective files. Combined with the existing--secret-config=""option, you can skip loadingtrivy.yaml,.trivyignore, andtrivy-secret.yamlfrom the current working directory.This is useful in CI when scanning repository checkouts whose configuration files should not control the scan.
Usage:
CLI flags and environment variables still apply. Secret scanning continues to use its built-in rules and allow rules.
See the documentation for details.
Vulnerability detection for Echo-patched Python packages
Trivy now detects vulnerabilities in Python packages patched by Echo.
These packages are identified by the
+echo.Nversion suffix (e.g.requests2.14.2+echo.1) and are checked against Echo's own security advisories from the Echo OSV feed instead of the upstream ones.Echo packages are detected regardless of the OS, including filesystem and repository scans.
See the documentation for details.
🏎️ Performance 🏎️
package-lock.jsonare parsed faster and with less memory. perf: reuse one JSON unmarshaler per document #11232 perf: take JSON line numbers from decoder offsets #11233See the linked PRs for benchmarks.
👷♂️ Notable Fixes 🛠️
index out of range [0]panic in dependency parsers and the OS detector from uncheckedstrings.Fields(...)[0]#10976 Thanks to @akshita317All reactions