Skip to content

Update aquasec/trivy Docker tag to v0.70.0#45

Open
alaudaa-renovate[bot] wants to merge 1 commit into
archived/alauda-v0.34.1from
renovate/aquasec-trivy-0.x
Open

Update aquasec/trivy Docker tag to v0.70.0#45
alaudaa-renovate[bot] wants to merge 1 commit into
archived/alauda-v0.34.1from
renovate/aquasec-trivy-0.x

Conversation

@alaudaa-renovate

@alaudaa-renovate alaudaa-renovate Bot commented Apr 17, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Type Update Change
aquasec/trivy (source) final minor 0.67.2 -> 0.70.0

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Release Notes

aquasecurity/trivy (aquasec/trivy)

v0.70.0

Compare Source

Features
Bug Fixes
Performance Improvements
  • plugin: optimize directory traversal by replacing filepath.Walk with filepath.WalkDir (#​10325) (d7fb355)

v0.69.3

Compare Source

Changelog
  • 6fb20c8 release: v0.69.3 [release/v0.69] (#​10293)
  • dabefec fix(deps): bump github.com/go-git/go-git/v5 from 5.16.4 to 5.16.5 [backport: release/v0.69] (#​10291)

v0.69.2

Compare Source

Changelog
  • cfa322e release: v0.69.2 [release/v0.69] (#​10266)
  • 86debce fix(deps): bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 [backport: release/v0.69] (#​10267)
  • cf3d4cd fix(deps): bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 [backport: release/v0.69] (#​10264)
  • 6dfd3b0 ci: remove apidiff workflow

v0.69.1

Compare Source

v0.69.0

Compare Source

⚠ BREAKING CHANGES
  • misconf: use ID instead of AVDID for providers mapping (#​9752)
Features
Bug Fixes
Performance Improvements
  • misconf: optimize string concatenation in azure scanner (#​9969) (10a50a7)
Code Refactoring
  • misconf: use ID instead of AVDID for providers mapping (#​9752) (6462dc8)

v0.68.2

Compare Source

v0.68.1

Compare Source

Bug Fixes
  • update cosing settings for GoReleaser after bumping cosing to v3 (#​9863) (c7accc8)

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR is behind base branch, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@alaudaa-renovate alaudaa-renovate Bot added the dependencies Pull requests that update a dependency file label Apr 17, 2026
@alaudabot

alaudabot commented Apr 17, 2026

Copy link
Copy Markdown

🤖 AI Code Review

Property Value
Model opencode/minimax-m2.5-free
Style strict
Issues Found 0
Config Source centralized
Profile ❌ Not Found
Personalized Prompt ❌ No
Prompt Path .github/review/profiles/alaudadevops/harbor-scanner-trivy/pr-review.md
Alauda Skills ✅ base-authoring, base-skill-setup, builders-component-knowledge, builders-confluence, builders-jira, builders-publish-errata, builders-story-split, devops-autodns, devops-bulk-string-replace, devops-candidate-version-supervisor, devops-connectors-explore, devops-connectors-poc-case, devops-connectors-review, devops-connectors-unit-test, devops-connectors-write-user-docs, devops-docker-keyword-analysis, devops-gen-advanced-form-descriptors, devops-go-vuln-fix, devops-knowledge-adoption, devops-refresh-alauda-tags, devops-sync-alauda-github-releases, devops-tekton-dynamic-form-optimizer, devops-tekton-operator-task-e2e, devops-tekton-task-generator, devops-tekton-task-overview-template, devops-tekton-task-version-upgrade, devops-tekton-upgrade-notes, devops-tool-report-troubleshoot, devops-ui-e2e-code-audit, devops-ui-e2e-fix-base-on-report, devops-ui-e2e-regression-and-fix, devops-ui-generate-e2e-from-feature, devops-ui-pre-setup, devops-update-containerfile-digests, devops-upgrade-go
Reviewed at 2026-04-19 04:22:29 UTC

Summary

This PR updates the Trivy Docker image version from v0.67.2 to v0.70.0 in both Dockerfile and Dockerfile.dev. The changes are straightforward version bumps performed by Renovate Bot. The update includes security fixes and new features from the Trivy release notes.

Review Statistics

Category Count
Critical Issues 0
Warnings 0
Suggestions 1
Files Reviewed 2

Critical Issues

Issues that MUST be addressed before merging (security, bugs, breaking changes)

(None)

Warnings

Issues that SHOULD be addressed but are not blocking

(None)

Suggestions

Recommendations for improvement (nice to have)

  • [Dockerfile:2] Consider adding a comment noting the minimum supported Trivy version for this project to help future maintainers understand version constraints.

Positive Feedback

  • The version update is consistent across both Dockerfile and Dockerfile.dev
  • Using the official aquasec/trivy image from a known registry
  • The ARG pattern follows Docker best practices for build-time variables
  • Update includes security fixes from v0.69.x and v0.70.0 releases


ℹ️ About this review

This review was automatically generated using the run-actions workflow.

  • Shared prompt: .github/prompts/code-review.md
  • Config source: centralized
  • Profile path: Not Found
  • Profile ref: 70116bce40f93e28716196a4b479fec1049b7950
  • No repository-specific prompt configured
  • Alauda skills: base-authoring, base-skill-setup, builders-component-knowledge, builders-confluence, builders-jira, builders-publish-errata, builders-story-split, devops-autodns, devops-bulk-string-replace, devops-candidate-version-supervisor, devops-connectors-explore, devops-connectors-poc-case, devops-connectors-review, devops-connectors-unit-test, devops-connectors-write-user-docs, devops-docker-keyword-analysis, devops-gen-advanced-form-descriptors, devops-go-vuln-fix, devops-knowledge-adoption, devops-refresh-alauda-tags, devops-sync-alauda-github-releases, devops-tekton-dynamic-form-optimizer, devops-tekton-operator-task-e2e, devops-tekton-task-generator, devops-tekton-task-overview-template, devops-tekton-task-version-upgrade, devops-tekton-upgrade-notes, devops-tool-report-troubleshoot, devops-ui-e2e-code-audit, devops-ui-e2e-fix-base-on-report, devops-ui-e2e-regression-and-fix, devops-ui-generate-e2e-from-feature, devops-ui-pre-setup, devops-update-containerfile-digests, devops-upgrade-go

@alaudaa-renovate alaudaa-renovate Bot force-pushed the renovate/aquasec-trivy-0.x branch from 6d9c450 to ef01e95 Compare April 17, 2026 06:12
@alaudaa-renovate alaudaa-renovate Bot changed the title Update aquasec/trivy Docker tag to v0.69.3 chore(deps): update aquasec/trivy docker tag to v0.69.3 Apr 17, 2026
Comment thread Dockerfile
@@ -1,5 +1,5 @@
# That's the only place where you're supposed to specify version of Trivy.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion (style/documentation): Consider tracking Trivy EOL dates to proactively update before versions become unsupported. Current v0.67.2 → v0.69.3 jump includes v0.69.0 with a breaking change in misconfiguration provider IDs.

Comment thread Dockerfile.dev
@@ -1,5 +1,5 @@
# That's the only place where you're supposed to specify version of Trivy.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion (style/documentation): Same as Dockerfile - consider EOL tracking for Trivy versions.

@alaudaa-renovate alaudaa-renovate Bot force-pushed the renovate/aquasec-trivy-0.x branch from ef01e95 to 4e35147 Compare April 18, 2026 00:39
@alaudaa-renovate alaudaa-renovate Bot changed the title chore(deps): update aquasec/trivy docker tag to v0.69.3 chore(deps): update aquasec/trivy docker tag to v0.70.0 Apr 18, 2026
@alaudaa-renovate alaudaa-renovate Bot changed the title chore(deps): update aquasec/trivy docker tag to v0.70.0 Update aquasec/trivy Docker tag to v0.70.0 Apr 18, 2026
Comment thread Dockerfile
@@ -1,5 +1,5 @@
# That's the only place where you're supposed to specify version of Trivy.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion (docs/missing): Consider verifying that v0.70.0 works correctly with the scanner. The v0.69.0 breaking change (ID instead of AVDID for providers mapping in misconf) affects configuration scanning, but this scanner primarily uses vulnerability scanning via the image subcommand. A quick integration test would confirm compatibility.

Comment thread Dockerfile.dev
@@ -1,5 +1,5 @@
# That's the only place where you're supposed to specify version of Trivy.

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Suggestion (style/documentation): Same as Dockerfile - consider verifying v0.70.0 compatibility via integration test.

@alaudaa-renovate

Copy link
Copy Markdown
Author

Edited/Blocked Notification

Renovate will not automatically rebase this PR, because it does not recognize the last commit author and assumes somebody else may have edited the PR.

You can manually request rebase by checking the rebase/retry box above.

⚠️ Warning: custom changes will be lost.

@alaudabot

Copy link
Copy Markdown

🚨 Stale Pull Request Warning

This pull request has been inactive for 32 days.

Automated Actions Schedule:

  • ⚠️ Warning: After 30 days (now)
  • 🔒 Auto-close: After 60 days
  • 🗑️ Branch deletion: After 90 days (if not protected)

To keep this PR active:

  • Add new commits
  • Reply to this comment
  • Request reviews

Protected branches (won't be deleted): main,release-*,alauda-*

This is an automated message. Reply to this comment to reset the inactivity timer.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants