Skip to content

Choose a tag to compare

@docker-scout-ci docker-scout-ci released this 30 Sep 17:19
· 2 commits to main since this release
221e7f4

What's Changed

  • Fixes docker scout watch failing with 401 Unauthorized about 15 minutes after it starts. The Docker token is now refreshed before it expires, and an image that fails to process no longer stops the watcher; it is retried on the next check. @aubm
  • Fixes docker scout attest list and docker scout attest get so they find attestations attached as OCI referrers on Docker Hub and other registries. Previously only attestations served by the Scout registry were listed. @benja-M-1
  • Fixes docker scout quickview showing VEX-suppressed CVEs in the Target row when VEX suppresses every CVE in the image. @whostolebenfrog
  • Fixes DHI base-image VEX statements not being applied to multistage builds that use a mirrored DHI base image (<org>/dhi-<name> naming). @flyingmachine
  • Fixes CycloneDX SBOM output to keep the original creation timestamp and generator tool names and versions. @brianru
  • Updates the embedded Trivy (0.72.0) and Syft (1.46.0) scanning engines. @brianru