Skip to content

Commit 9b282fe

Browse files
chore(deps): bump github.com/aquasecurity/trivy from 0.69.3 to 0.70.0
Bumps [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy) from 0.69.3 to 0.70.0. - [Release notes](https://github.com/aquasecurity/trivy/releases) - [Changelog](https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md) - [Commits](aquasecurity/trivy@v0.69.3...v0.70.0) --- updated-dependencies: - dependency-name: github.com/aquasecurity/trivy dependency-version: 0.70.0 dependency-type: direct:production update-type: version-update:semver-minor ... Signed-off-by: dependabot[bot] <support@github.com>
1 parent 83bd731 commit 9b282fe

2 files changed

Lines changed: 151 additions & 158 deletions

File tree

go.mod

Lines changed: 39 additions & 46 deletions
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ go 1.25.8
44

55
require (
66
github.com/CycloneDX/cyclonedx-go v0.10.0
7-
github.com/aquasecurity/trivy v0.69.3 // Also update .circle/config.yml
7+
github.com/aquasecurity/trivy v0.70.0 // Also update .circle/config.yml
88
github.com/aquasecurity/trivy-db v0.0.0-20251222105351-a833f47f8f0d
99
github.com/codacy/codacy-engine-golang-seed/v8 v8.0.2
1010
github.com/google/go-cmp v0.7.0
@@ -36,7 +36,7 @@ require (
3636
github.com/AzureAD/microsoft-authentication-library-for-go v1.6.0 // indirect
3737
github.com/BurntSushi/toml v1.6.0 // indirect
3838
github.com/DataDog/zstd v1.5.5 // indirect
39-
github.com/GoogleCloudPlatform/docker-credential-gcr/v2 v2.1.30 // indirect
39+
github.com/GoogleCloudPlatform/docker-credential-gcr/v2 v2.1.32 // indirect
4040
github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.30.0 // indirect
4141
github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.55.0 // indirect
4242
github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0 // indirect
@@ -78,8 +78,8 @@ require (
7878
github.com/aws/aws-sdk-go-v2/internal/ini v1.8.6 // indirect
7979
github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.22 // indirect
8080
github.com/aws/aws-sdk-go-v2/service/ebs v1.22.1 // indirect
81-
github.com/aws/aws-sdk-go-v2/service/ec2 v1.273.0 // indirect
82-
github.com/aws/aws-sdk-go-v2/service/ecr v1.53.1 // indirect
81+
github.com/aws/aws-sdk-go-v2/service/ec2 v1.290.0 // indirect
82+
github.com/aws/aws-sdk-go-v2/service/ecr v1.55.2 // indirect
8383
github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.7 // indirect
8484
github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.13 // indirect
8585
github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.21 // indirect
@@ -90,12 +90,11 @@ require (
9090
github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.17 // indirect
9191
github.com/aws/aws-sdk-go-v2/service/sts v1.41.9 // indirect
9292
github.com/aws/smithy-go v1.24.2 // indirect
93-
github.com/beorn7/perks v1.0.1 // indirect
9493
github.com/bgentry/go-netrc v0.0.0-20140422174119-9fd32a8b3d3d // indirect
9594
github.com/bitnami/go-version v0.0.0-20231130084017-bb00604d650c // indirect
9695
github.com/blang/semver v3.5.1+incompatible // indirect
9796
github.com/blang/semver/v4 v4.0.0 // indirect
98-
github.com/bmatcuk/doublestar/v4 v4.9.1 // indirect
97+
github.com/bmatcuk/doublestar/v4 v4.10.0 // indirect
9998
github.com/briandowns/spinner v1.23.0 // indirect
10099
github.com/cenkalti/backoff/v4 v4.3.0 // indirect
101100
github.com/cenkalti/backoff/v5 v5.0.3 // indirect
@@ -104,19 +103,19 @@ require (
104103
github.com/cheggaaa/pb/v3 v3.1.7 // indirect
105104
github.com/cloudflare/circl v1.6.3 // indirect
106105
github.com/cncf/xds/go v0.0.0-20251210132809-ee656c7534f5 // indirect
107-
github.com/containerd/cgroups/v3 v3.1.2 // indirect
106+
github.com/containerd/cgroups/v3 v3.1.3 // indirect
108107
github.com/containerd/containerd v1.7.30 // indirect
109108
github.com/containerd/containerd/api v1.10.0 // indirect
110-
github.com/containerd/containerd/v2 v2.2.1 // indirect
109+
github.com/containerd/containerd/v2 v2.2.2 // indirect
111110
github.com/containerd/continuity v0.4.5 // indirect
112111
github.com/containerd/errdefs v1.0.0 // indirect
113112
github.com/containerd/errdefs/pkg v0.3.0 // indirect
114113
github.com/containerd/fifo v1.1.0 // indirect
115114
github.com/containerd/log v0.1.0 // indirect
116-
github.com/containerd/platforms v1.0.0-rc.2 // indirect
115+
github.com/containerd/platforms v1.0.0-rc.4 // indirect
117116
github.com/containerd/plugin v1.0.0 // indirect
118117
github.com/containerd/stargz-snapshotter/estargz v0.18.2 // indirect
119-
github.com/containerd/ttrpc v1.2.7 // indirect
118+
github.com/containerd/ttrpc v1.2.8 // indirect
120119
github.com/containerd/typeurl/v2 v2.2.3 // indirect
121120
github.com/coreos/go-oidc/v3 v3.17.0 // indirect
122121
github.com/cyberphone/json-canonicalization v0.0.0-20241213102144-19d51d7fe467 // indirect
@@ -128,9 +127,8 @@ require (
128127
github.com/digitorus/timestamp v0.0.0-20231217203849-220c5c2851b7 // indirect
129128
github.com/distribution/reference v0.6.0 // indirect
130129
github.com/dlclark/regexp2 v1.11.0 // indirect
131-
github.com/docker/cli v29.2.1+incompatible // indirect
130+
github.com/docker/cli v29.4.0+incompatible // indirect
132131
github.com/docker/distribution v2.8.3+incompatible // indirect
133-
github.com/docker/docker v28.5.2+incompatible // indirect
134132
github.com/docker/docker-credential-helpers v0.9.5 // indirect
135133
github.com/docker/go-connections v0.6.0 // indirect
136134
github.com/docker/go-units v0.5.0 // indirect
@@ -141,7 +139,7 @@ require (
141139
github.com/envoyproxy/protoc-gen-validate v1.3.0 // indirect
142140
github.com/evanphx/json-patch v5.9.11+incompatible // indirect
143141
github.com/exponent-io/jsonpath v0.0.0-20210407135951-1de76d718b3f // indirect
144-
github.com/fatih/color v1.18.0 // indirect
142+
github.com/fatih/color v1.19.0 // indirect
145143
github.com/felixge/httpsnoop v1.0.4 // indirect
146144
github.com/fsnotify/fsnotify v1.9.0 // indirect
147145
github.com/fvbommel/sortorder v1.1.0 // indirect
@@ -181,15 +179,15 @@ require (
181179
github.com/go-viper/mapstructure/v2 v2.5.0 // indirect
182180
github.com/gobwas/glob v0.2.3 // indirect
183181
github.com/goccy/go-json v0.10.5 // indirect
184-
github.com/gocsaf/csaf/v3 v3.5.0 // indirect
182+
github.com/gocsaf/csaf/v3 v3.5.1 // indirect
185183
github.com/gogo/protobuf v1.3.2 // indirect
186-
github.com/golang-jwt/jwt/v5 v5.3.0 // indirect
184+
github.com/golang-jwt/jwt/v5 v5.3.1 // indirect
187185
github.com/golang/groupcache v0.0.0-20241129210726-2c02b8208cf8 // indirect
188186
github.com/golang/snappy v0.0.4 // indirect
189187
github.com/google/btree v1.1.3 // indirect
190188
github.com/google/certificate-transparency-go v1.3.2 // indirect
191189
github.com/google/gnostic-models v0.7.0 // indirect
192-
github.com/google/go-containerregistry v0.20.7 // indirect
190+
github.com/google/go-containerregistry v0.21.2 // indirect
193191
github.com/google/go-github/v62 v62.0.0 // indirect
194192
github.com/google/go-querystring v1.1.0 // indirect
195193
github.com/google/licenseclassifier/v2 v2.0.0 // indirect
@@ -199,15 +197,15 @@ require (
199197
github.com/googleapis/gax-go/v2 v2.19.0 // indirect
200198
github.com/gosuri/uitable v0.0.4 // indirect
201199
github.com/gregjones/httpcache v0.0.0-20190611155906-901d90724c79 // indirect
202-
github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.3 // indirect
200+
github.com/grpc-ecosystem/grpc-gateway/v2 v2.27.7 // indirect
203201
github.com/hashicorp/aws-sdk-go-base/v2 v2.0.0-beta.72 // indirect
204202
github.com/hashicorp/errwrap v1.1.0 // indirect
205203
github.com/hashicorp/go-cleanhttp v0.5.2 // indirect
206204
github.com/hashicorp/go-getter v1.8.6 // indirect
207205
github.com/hashicorp/go-multierror v1.1.1 // indirect
208206
github.com/hashicorp/go-retryablehttp v0.7.8 // indirect
209207
github.com/hashicorp/go-uuid v1.0.3 // indirect
210-
github.com/hashicorp/go-version v1.8.0 // indirect
208+
github.com/hashicorp/go-version v1.9.0 // indirect
211209
github.com/hashicorp/golang-lru/v2 v2.0.7 // indirect
212210
github.com/hashicorp/hcl/v2 v2.24.0 // indirect
213211
github.com/huandu/xstrings v1.5.0 // indirect
@@ -233,9 +231,8 @@ require (
233231
github.com/lestrrat-go/dsig v1.0.0 // indirect
234232
github.com/lestrrat-go/dsig-secp256k1 v1.0.0 // indirect
235233
github.com/lestrrat-go/httpcc v1.0.1 // indirect
236-
github.com/lestrrat-go/httprc/v3 v3.0.1 // indirect
237-
github.com/lestrrat-go/jwx/v3 v3.0.12 // indirect
238-
github.com/lestrrat-go/option v1.0.1 // indirect
234+
github.com/lestrrat-go/httprc/v3 v3.0.2 // indirect
235+
github.com/lestrrat-go/jwx/v3 v3.0.13 // indirect
239236
github.com/lestrrat-go/option/v2 v2.0.0 // indirect
240237
github.com/letsencrypt/boulder v0.20260223.0 // indirect
241238
github.com/lib/pq v1.10.9 // indirect
@@ -256,11 +253,11 @@ require (
256253
github.com/mitchellh/go-wordwrap v1.0.1 // indirect
257254
github.com/mitchellh/hashstructure/v2 v2.0.2 // indirect
258255
github.com/mitchellh/reflectwalk v1.0.2 // indirect
259-
github.com/moby/buildkit v0.28.1 // indirect
256+
github.com/moby/buildkit v0.29.0 // indirect
260257
github.com/moby/docker-image-spec v1.3.1 // indirect
261258
github.com/moby/locker v1.0.1 // indirect
262-
github.com/moby/moby/api v1.52.0 // indirect
263-
github.com/moby/moby/client v0.2.1 // indirect
259+
github.com/moby/moby/api v1.54.1 // indirect
260+
github.com/moby/moby/client v0.4.0 // indirect
264261
github.com/moby/sys/atomicwriter v0.1.0 // indirect
265262
github.com/moby/sys/mountinfo v0.7.2 // indirect
266263
github.com/moby/sys/sequential v0.6.0 // indirect
@@ -273,10 +270,10 @@ require (
273270
github.com/monochromegane/go-gitignore v0.0.0-20200626010858-205db1a8cc00 // indirect
274271
github.com/morikuni/aec v1.1.0 // indirect
275272
github.com/munnerz/goautoneg v0.0.0-20191010083416-a7dc8b61c822 // indirect
276-
github.com/nikolalohinski/gonja/v2 v2.4.2 // indirect
273+
github.com/nikolalohinski/gonja/v2 v2.7.0 // indirect
277274
github.com/nozzle/throttler v0.0.0-20180817012639-2ea982251481 // indirect
278275
github.com/oklog/ulid/v2 v2.1.1 // indirect
279-
github.com/open-policy-agent/opa v1.11.0 // indirect
276+
github.com/open-policy-agent/opa v1.15.2 // indirect
280277
github.com/opencontainers/go-digest v1.0.0 // indirect
281278
github.com/opencontainers/image-spec v1.1.1 // indirect
282279
github.com/opencontainers/runtime-spec v1.3.0 // indirect
@@ -293,10 +290,6 @@ require (
293290
github.com/pkg/errors v0.9.1 // indirect
294291
github.com/planetscale/vtprotobuf v0.6.1-0.20240319094008-0393e58bdf10 // indirect
295292
github.com/pmezard/go-difflib v1.0.1-0.20181226105442-5d4384ee4fb2 // indirect
296-
github.com/prometheus/client_golang v1.23.2 // indirect
297-
github.com/prometheus/client_model v0.6.2 // indirect
298-
github.com/prometheus/common v0.67.4 // indirect
299-
github.com/prometheus/procfs v0.17.0 // indirect
300293
github.com/rcrowley/go-metrics v0.0.0-20250401214520-65e299d6c5c9 // indirect
301294
github.com/rivo/uniseg v0.4.7 // indirect
302295
github.com/rubenv/sql-migrate v1.8.1 // indirect
@@ -314,7 +307,7 @@ require (
314307
github.com/shopspring/decimal v1.4.0 // indirect
315308
github.com/sigstore/cosign/v2 v2.6.2 // indirect
316309
github.com/sigstore/protobuf-specs v0.5.0 // indirect
317-
github.com/sigstore/rekor v1.5.0 // indirect
310+
github.com/sigstore/rekor v1.5.1 // indirect
318311
github.com/sigstore/rekor-tiles/v2 v2.0.1 // indirect
319312
github.com/sigstore/sigstore v1.10.5 // indirect
320313
github.com/sigstore/sigstore-go v1.1.4 // indirect
@@ -328,11 +321,11 @@ require (
328321
github.com/spf13/pflag v1.0.10 // indirect
329322
github.com/spf13/viper v1.21.0 // indirect
330323
github.com/spiffe/go-spiffe/v2 v2.6.0 // indirect
331-
github.com/stretchr/objx v0.5.2 // indirect
324+
github.com/stretchr/objx v0.5.3 // indirect
332325
github.com/subosito/gotenv v1.6.0 // indirect
333326
github.com/syndtr/goleveldb v1.0.1-0.20220721030215-126854af5e6d // indirect
334327
github.com/tchap/go-patricia/v2 v2.3.3 // indirect
335-
github.com/tetratelabs/wazero v1.10.1 // indirect
328+
github.com/tetratelabs/wazero v1.11.0 // indirect
336329
github.com/theupdateframework/go-tuf v0.7.0 // indirect
337330
github.com/theupdateframework/go-tuf/v2 v2.4.1 // indirect
338331
github.com/titanous/rocacheck v0.0.0-20171023193734-afe73141d399 // indirect
@@ -342,9 +335,9 @@ require (
342335
github.com/transparency-dev/merkle v0.0.2 // indirect
343336
github.com/twitchtv/twirp v8.1.3+incompatible // indirect
344337
github.com/ulikunitz/xz v0.5.15 // indirect
345-
github.com/valyala/fastjson v1.6.4 // indirect
338+
github.com/valyala/fastjson v1.6.7 // indirect
346339
github.com/vbatts/tar-split v0.12.2 // indirect
347-
github.com/vektah/gqlparser/v2 v2.5.31 // indirect
340+
github.com/vektah/gqlparser/v2 v2.5.32 // indirect
348341
github.com/vmihailenco/msgpack/v5 v5.4.1 // indirect
349342
github.com/vmihailenco/tagparser/v2 v2.0.0 // indirect
350343
github.com/x448/float16 v0.8.4 // indirect
@@ -355,30 +348,30 @@ require (
355348
github.com/xi2/xz v0.0.0-20171230120015-48954b6210f8 // indirect
356349
github.com/xlab/treeprint v1.2.0 // indirect
357350
github.com/yashtewari/glob-intersection v0.2.0 // indirect
358-
github.com/zclconf/go-cty v1.17.0 // indirect
359-
github.com/zclconf/go-cty-yaml v1.1.0 // indirect
351+
github.com/zclconf/go-cty v1.18.0 // indirect
352+
github.com/zclconf/go-cty-yaml v1.2.0 // indirect
360353
go.etcd.io/bbolt v1.4.3 // indirect
361354
go.opencensus.io v0.24.0 // indirect
362355
go.opentelemetry.io/auto/sdk v1.2.1 // indirect
363356
go.opentelemetry.io/contrib/detectors/gcp v1.39.0 // indirect
364357
go.opentelemetry.io/contrib/instrumentation/google.golang.org/grpc/otelgrpc v0.63.0 // indirect
365-
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.63.0 // indirect
358+
go.opentelemetry.io/contrib/instrumentation/net/http/otelhttp v0.65.0 // indirect
366359
go.opentelemetry.io/otel v1.43.0 // indirect
367-
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.38.0 // indirect
368-
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.38.0 // indirect
369-
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.38.0 // indirect
360+
go.opentelemetry.io/otel/exporters/otlp/otlpmetric/otlpmetricgrpc v1.40.0 // indirect
361+
go.opentelemetry.io/otel/exporters/otlp/otlptrace v1.40.0 // indirect
362+
go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracegrpc v1.40.0 // indirect
370363
go.opentelemetry.io/otel/metric v1.43.0 // indirect
371364
go.opentelemetry.io/otel/sdk v1.43.0 // indirect
372365
go.opentelemetry.io/otel/sdk/metric v1.43.0 // indirect
373366
go.opentelemetry.io/otel/trace v1.43.0 // indirect
374-
go.opentelemetry.io/proto/otlp v1.7.1 // indirect
367+
go.opentelemetry.io/proto/otlp v1.9.0 // indirect
375368
go.uber.org/multierr v1.11.0 // indirect
376369
go.uber.org/zap v1.27.1 // indirect
377370
go.yaml.in/yaml/v2 v2.4.3 // indirect
378371
go.yaml.in/yaml/v3 v3.0.4 // indirect
379372
go.yaml.in/yaml/v4 v4.0.0-rc.3 // indirect
380373
golang.org/x/crypto v0.50.0 // indirect
381-
golang.org/x/exp v0.0.0-20250911091902-df9299821621 // indirect
374+
golang.org/x/exp v0.0.0-20251023183803-a4bb9ffd2546 // indirect
382375
golang.org/x/net v0.53.0 // indirect
383376
golang.org/x/oauth2 v0.36.0 // indirect
384377
golang.org/x/sync v0.20.0 // indirect
@@ -387,7 +380,7 @@ require (
387380
golang.org/x/text v0.36.0 // indirect
388381
golang.org/x/time v0.15.0 // indirect
389382
golang.org/x/tools v0.43.0 // indirect
390-
golang.org/x/xerrors v0.0.0-20240716161551-93cc26a95ae9 // indirect
383+
golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
391384
google.golang.org/api v0.272.0 // indirect
392385
google.golang.org/genproto v0.0.0-20260316180232-0b37fe3546d5 // indirect
393386
google.golang.org/genproto/googleapis/api v0.0.0-20260316180232-0b37fe3546d5 // indirect
@@ -399,9 +392,9 @@ require (
399392
gopkg.in/warnings.v0 v0.1.2 // indirect
400393
gopkg.in/yaml.v3 v3.0.1 // indirect
401394
helm.sh/helm/v3 v3.20.2 // indirect
402-
k8s.io/api v0.35.1 // indirect
395+
k8s.io/api v0.35.3 // indirect
403396
k8s.io/apiextensions-apiserver v0.35.1 // indirect
404-
k8s.io/apimachinery v0.35.1 // indirect
397+
k8s.io/apimachinery v0.35.3 // indirect
405398
k8s.io/apiserver v0.35.1 // indirect
406399
k8s.io/cli-runtime v0.35.1 // indirect
407400
k8s.io/client-go v0.35.1 // indirect

0 commit comments

Comments
 (0)