fix: use --pkg-types instead of deprecated --vuln-type for trivy - #1223
Merged
Conversation
jiashun0011
requested review from
ashnamehrotra,
pmengelbert and
sozercan
as code owners
July 28, 2026 06:17
Codecov Report❌ Patch coverage is
Flags with carried forward coverage won't be shown. Click here to find out more.
... and 37 files with indirect coverage changes 🚀 New features to boost your workflow:
|
Member
|
@jiashun0011 looks like its missing dco, please sign when you get a chance |
Trivy deprecated the --vuln-type flag in v0.54.0 in favor of --pkg-types. Since eraser pins trivy 0.67.2, every scan emits: WARN '--vuln-type' is deprecated. Use '--pkg-types' instead. Rename the internal flag constant and update tests. The user-facing VulnConfig.Types field (JSON: vulnerabilities.types) is unchanged, so existing eraser configurations continue to work. Signed-off-by: Jiashun Liu <jiashunliu@microsoft.com>
jiashun0011
force-pushed
the
jiashunliu/vuln-type-fix
branch
from
July 30, 2026 07:11
59b5bda to
695ad31
Compare
Signed-off-by: Sertac Ozercan <sozercan@gmail.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
What this PR does / why we need it:
Trivy deprecated the --vuln-type flag in v0.54.0 in favor of --pkg-types. Since eraser pins trivy 0.67.2, every scan emits:
WARN '--vuln-type' is deprecated. Use '--pkg-types' instead.
Which issue(s) this PR fixes (optional, using
fixes #<issue number>(, fixes #<issue_number>, ...)format, will close the issue(s) when the PR gets merged):Fixes #
Special notes for your reviewer: