chore(docker): update aquasec/trivy docker tag to v0.74.0 #198

Merged
murdoc merged 1 commit from renovate-aquasec-trivy-0-x into main 2026-08-17 05:49:23 +00:00
Owner

This PR contains the following updates:

Package Type Update Change OpenSSF
aquasec/trivy (source) container minor 0.73.00.74.0 OpenSSF Scorecard

Release Notes

aquasecurity/trivy (aquasec/trivy)

v0.74.0

Compare Source

Features
Bug Fixes
  • java: read artifact properties only from the MANIFEST.MF main section (#​11066) (018bfbf)
  • misconf: parse Azure flexible server parameters under their own names (#​11072) (d59f0f8)
  • misconf: unmark cty values outside the evaluation context (#​11078) (9e85b6b)
  • python: normalize dependency names in PEP 621 pyproject.toml (#​11050) (0012281)
  • server: preserve check aliases and query in uploaded blobs (#​11080) (0512d6d)
  • terraform: avoid panic when for_each local has unknown object values (#​11019) (199a126)
  • terraform: support OpenTofu language block (#​10923) (bacf17f)

Configuration

📅 Schedule: (in timezone Europe/Berlin)

  • Branch creation
    • "after 3am and before 6pm"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Type | Update | Change | OpenSSF | |---|---|---|---|---| | [aquasec/trivy](https://www.aquasec.com/products/trivy/) ([source](https://github.com/aquasecurity/trivy)) | container | minor | `0.73.0` → `0.74.0` | [![OpenSSF Scorecard](https://api.securityscorecards.dev/projects/github.com/aquasecurity/trivy/badge)](https://securityscorecards.dev/viewer/?uri=github.com/aquasecurity/trivy) | --- ### Release Notes <details> <summary>aquasecurity/trivy (aquasec/trivy)</summary> ### [`v0.74.0`](https://github.com/aquasecurity/trivy/blob/HEAD/CHANGELOG.md#0740-2026-08-14) [Compare Source](https://github.com/aquasecurity/trivy/compare/v0.73.0...v0.74.0) ##### Features - add RapidFort curated image scanner ([#&#8203;10452](https://github.com/aquasecurity/trivy/issues/10452)) ([2c3b86c](https://github.com/aquasecurity/trivy/commit/2c3b86c9bba05beb8a0ad6ff06de9678dddc8a4e)) - **java:** resolve JAR license URLs to SPDX IDs (Bundle-License, pom \<url>) ([#&#8203;10948](https://github.com/aquasecurity/trivy/issues/10948)) ([171e391](https://github.com/aquasecurity/trivy/commit/171e39168b1ad100f7c5ddc7bc65c1e796d8d2d5)) ##### Bug Fixes - **java:** read artifact properties only from the MANIFEST.MF main section ([#&#8203;11066](https://github.com/aquasecurity/trivy/issues/11066)) ([018bfbf](https://github.com/aquasecurity/trivy/commit/018bfbff1c37ccaff016973dd7c4468545edf3bf)) - **misconf:** parse Azure flexible server parameters under their own names ([#&#8203;11072](https://github.com/aquasecurity/trivy/issues/11072)) ([d59f0f8](https://github.com/aquasecurity/trivy/commit/d59f0f872fddca976c756d92e99caa817c11f741)) - **misconf:** unmark cty values outside the evaluation context ([#&#8203;11078](https://github.com/aquasecurity/trivy/issues/11078)) ([9e85b6b](https://github.com/aquasecurity/trivy/commit/9e85b6b9d8df113a134d425ba1ad70768345a516)) - **python:** normalize dependency names in PEP 621 pyproject.toml ([#&#8203;11050](https://github.com/aquasecurity/trivy/issues/11050)) ([0012281](https://github.com/aquasecurity/trivy/commit/0012281c8a8adad2eff1889f12fe08a0ca5a7bfc)) - **server:** preserve check aliases and query in uploaded blobs ([#&#8203;11080](https://github.com/aquasecurity/trivy/issues/11080)) ([0512d6d](https://github.com/aquasecurity/trivy/commit/0512d6dcdfac47622f1a15ded9bab9d0d5764c40)) - **terraform:** avoid panic when for\_each local has unknown object values ([#&#8203;11019](https://github.com/aquasecurity/trivy/issues/11019)) ([199a126](https://github.com/aquasecurity/trivy/commit/199a12624b84d82aaa48a14f85b38c1a3ea3e9ca)) - **terraform:** support OpenTofu language block ([#&#8203;10923](https://github.com/aquasecurity/trivy/issues/10923)) ([bacf17f](https://github.com/aquasecurity/trivy/commit/bacf17fe52a45dda1adaec8c0bb04ccc3cd98c65)) </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Berlin) - Branch creation - "after 3am and before 6pm" - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Enabled. ♻ **Rebasing**: Whenever PR is behind base branch, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4zMC4zIiwidXBkYXRlZEluVmVyIjoiNDQuMzAuMyIsInRhcmdldEJyYW5jaCI6Im1haW4iLCJsYWJlbHMiOlsiZG9ja2VyIiwibWlub3IiLCJyZW5vdmF0ZSJdfQ==-->
chore(docker): update aquasec/trivy docker tag to v0.74.0
Some checks failed
renovate/stability-days Updates have not met minimum release age requirement
pre-commit-check / pre-commit (pull_request) Successful in 10s
CI Pipeline for building and pushing Docker images (staging and latest) / build_and_push_temp (pull_request) Has been cancelled
CI Pipeline for building and pushing Docker images (staging and latest) / trivy_scan (pull_request) Has been cancelled
CI Pipeline for building and pushing Docker images (staging and latest) / push_final (pull_request) Has been cancelled
0ec5902eae
murdoc scheduled this pull request to auto merge when all checks succeed 2026-08-17 05:49:04 +00:00
murdoc merged commit 861bada710 into main 2026-08-17 05:49:23 +00:00
murdoc deleted branch renovate-aquasec-trivy-0-x 2026-08-17 05:49:23 +00:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
murdoc/opencode-sandbox!198
No description provided.