Skip to content

fix(deps): update trivy (main) - #6747

Merged
elastic-renovate-prod[bot] merged 2 commits into
mainfrom
renovate/main-trivy
Aug 19, 2026
Merged

fix(deps): update trivy (main)#6747
elastic-renovate-prod[bot] merged 2 commits into
mainfrom
renovate/main-trivy

Conversation

@elastic-renovate-prod

@elastic-renovate-prod elastic-renovate-prod Bot commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence Type Update
github.com/aquasecurity/trivy v0.71.0v0.74.0 age confidence require minor
github.com/aquasecurity/trivy-db 11b0c9f0e0340a age confidence require digest

Warning

Some dependencies could not be looked up. Check the Dependency Dashboard for more information.


Configuration

📅 Schedule: Branch creation - Between 01:00 AM and 01:59 AM, Monday through Friday ( * 1 * * 1-5 ) (UTC), Automerge - At any time (no schedule defined).

🚦 Automerge: Enabled.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@elastic-renovate-prod
elastic-renovate-prod Bot requested a review from a team as a code owner June 17, 2026 08:07
@elastic-renovate-prod elastic-renovate-prod Bot added backport-skip dependencies Pull requests that update a dependency file renovate renovate-auto-approve Team:Security-Cloud Services Security Data Experience - Cloud Services team. labels Jun 17, 2026
@mergify

mergify Bot commented Jun 17, 2026

Copy link
Copy Markdown
Contributor

This pull request is now in conflicts. Could you fix it? 🙏
To fixup this pull request, you can check out it locally. See documentation: https://help.github.com/articles/checking-out-pull-requests-locally/

git fetch upstream
git checkout -b renovate/main-trivy upstream/renovate/main-trivy
git merge upstream/main
git push upstream renovate/main-trivy

@elastic-renovate-prod elastic-renovate-prod Bot changed the title fix(deps): update trivy (main) fix(deps): update module github.com/aquasecurity/trivy to v0.71.2 (main) Jun 22, 2026
@elastic-renovate-prod elastic-renovate-prod Bot changed the title fix(deps): update module github.com/aquasecurity/trivy to v0.71.2 (main) fix(deps): update trivy (main) Jun 24, 2026
@elastic-renovate-prod elastic-renovate-prod Bot changed the title fix(deps): update trivy (main) fix(deps): update module github.com/aquasecurity/trivy to v0.71.2 (main) Jun 26, 2026
@elastic-renovate-prod elastic-renovate-prod Bot changed the title fix(deps): update module github.com/aquasecurity/trivy to v0.71.2 (main) fix(deps): update trivy (main) Jun 28, 2026
@elastic-renovate-prod
elastic-renovate-prod Bot force-pushed the renovate/main-trivy branch 2 times, most recently from 8f2d3b5 to 434e5cf Compare August 14, 2026 14:58
@elastic-renovate-prod elastic-renovate-prod Bot changed the title fix(deps): update module github.com/aquasecurity/trivy to v0.73.0 (main) fix(deps): update trivy (main) Aug 15, 2026
@elastic-renovate-prod

Copy link
Copy Markdown
Contributor Author

ℹ️ Artifact update notice

File name: go.mod

In order to perform the update(s) described in the table above, Renovate ran the go get command, which resulted in the following additional change(s):

  • 1 additional dependency was updated

Details:

Package Change
github.com/docker/cli v29.6.2+incompatible -> v29.7.2+incompatible

@mergify

mergify Bot commented Aug 16, 2026

Copy link
Copy Markdown
Contributor

This pull request is now in conflicts. Could you fix it? 🙏
To fixup this pull request, you can check out it locally. See documentation: https://help.github.com/articles/checking-out-pull-requests-locally/

git fetch upstream
git checkout -b renovate/main-trivy upstream/renovate/main-trivy
git merge upstream/main
git push upstream renovate/main-trivy

Trivy-db 0e0340a marked types.Vulnerability.Severity deprecated in favor
of VendorSeverity. Trivy itself still resolves the effective severity
into DetectedVulnerability.Severity (see FillInfo in
pkg/vulnerability/vulnerability.go), so this is the correct field to
keep reading from during vulnerability event creation.
@mergify

mergify Bot commented Aug 19, 2026

Copy link
Copy Markdown
Contributor

Tick the box to add this pull request to the merge queue (same as @mergifyio queue).

  • Queue this pull request

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

backport-skip dependencies Pull requests that update a dependency file renovate renovate-auto-approve Team:Security-Cloud Services Security Data Experience - Cloud Services team.

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant