Skip to content

build(docker): bump aquasec/trivy from 0.71.1 to 0.71.2 in /docker#38

Merged
valdacf merged 1 commit into
mainfrom
dependabot/docker/docker/aquasec/trivy-0.71.2
Jun 22, 2026
Merged

build(docker): bump aquasec/trivy from 0.71.1 to 0.71.2 in /docker#38
valdacf merged 1 commit into
mainfrom
dependabot/docker/docker/aquasec/trivy-0.71.2

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jun 22, 2026

Copy link
Copy Markdown
Contributor

Bumps aquasec/trivy from 0.71.1 to 0.71.2.

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file docker Pull requests that update docker code labels Jun 22, 2026
@valdacf

valdacf commented Jun 22, 2026

Copy link
Copy Markdown
Collaborator

@dependabot rebase

Bumps aquasec/trivy from 0.71.1 to 0.71.2.

---
updated-dependencies:
- dependency-name: aquasec/trivy
  dependency-version: 0.71.2
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/docker/docker/aquasec/trivy-0.71.2 branch from e3b1d53 to fdd23c5 Compare June 22, 2026 18:25
@valdacf valdacf merged commit 28a6f7d into main Jun 22, 2026
7 checks passed
@valdacf valdacf deleted the dependabot/docker/docker/aquasec/trivy-0.71.2 branch June 22, 2026 18:25
valdacf added a commit that referenced this pull request Jun 22, 2026
Dependabot only bumped the runtime Docker image (aquasec/trivy:0.71.2,
PR #38). The authoritative pin also lives in the shdg CLI, which
downloads the Trivy binary by version with SHA-256-pinned checksums.
Bump it there too so the CLI caches 0.71.2 instead of 0.71.1, keeping
the whole repo consistent.

- cmd/shdg/trivy.go: trivyVersion 0.71.1 -> 0.71.2 + refreshed the four
  per-platform SHA-256 checksums (verified against the upstream
  trivy_0.71.2_checksums.txt release file)
- cmd/shdg/trivy_test.go: update fixtures + the AllPinned build-gate
- docs (architecture, deployment, configuration, vulnerability-scan,
  cli/shdg): reflect v0.71.2

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker Pull requests that update docker code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant