Update Info

openSUSE-2026-263


Security update for trivy


Type: security
Severity: important
Issued: 2026-07-27
Description:
This update for trivy fixes the following issues:

- Update embedded dependencies:
  * update x/net to 0.57.0 (boo#1266495, CVE-2026-39821)
  * update x/text to 0.40.0 (boo#1271670, CVE-2026-56852)
  * update oras-go to 2.6.1 (boo#1271658, CVE-2026-50151)

- Update trivy to version 0.72.0:
  * release: v0.72.0 [main] (#10782)
  * test: close plugin manager in tests cleanup (#10904)
  * Merge commit from fork
  * feat(bottlerocket): add vulnerability matching for Bottlerocket OS (#10893)
  * fix(misconf): support github_repository_vulnerability_alerts resource (#10680)
  * feat(java): detect JAR licenses from packaged LICENSE files (#10856)
  * fix(nodejs): parse project dependencies from multi-document pnpm-lock.yaml (#10861)
  * fix(server): propagate package repository class in client/server mode (#10874)
  * chore(deps): bump github.com/containerd/containerd/v2 from 2.3.1 to 2.3.2 (#10888)
  * fix(vuln): fall back to UNKNOWN severity when vulnerability details are missing (#10795)
  * feat(java): detect JAR licenses from the embedded pom.xml (#10851)
  * chore(deps): Upgrade github.com/cenkalti/backoff to v6 (#10863)
  * ci(helm): bump Trivy version to 0.71.2 for Trivy Helm Chart 0.23.2 (#10873)
  * chore(deps): bump alpine to 3.24.1 (#10868)
  * docs: fix article typo in plugin developer guide (#10860)
  * feat(misconf): Adds CloudFront standard logging v2 support to AVD-AWS-0010 (#10848)
  * docs: fix typos (#10857)
  * fix(terraform): avoid data race on global getter.Getters in remote module resolver (#10843)
  * feat(secret): support new stateless format for GitHub App installation tokens (#10826)
  * fix: correct format verbs in diagnostic messages (#10805)
  * ci(helm): bump Trivy version to 0.71.1 for Trivy Helm Chart 0.23.1 (#10845)
  * refactor: use ParseErrorsAllowlist instead of ParseErrorsWhitelist (#10830)
  * docs: fix repository scan heading typo (#10828)
  * Merge commit from fork
  * fix: forward ospkg detector options through ospkg.NewScanner (#10811)
  * chore(deps): bump github.com/bufbuild/buf to v1.70.0 (#10801)
  * fix(vex): load VEX documents from within the repository directory (#10820)
  * ci!: migrate docker config to dockers_v2 (#10783)
  * feat(dotnet): detect bundled runtime in self-contained deployments (#10786)
  * feat(secret): add OpenAI secret detection rules (#10798)
  * ci: expect GitHub App bot as backport PR author (#10813)
  * fix: surface the original analysis error instead of context cancellation (#10793)
  * chore(deps): bump the github-actions group across 1 directory with 11 updates (#10803)
  * chore(deps): bump the common group with 4 updates (#10797)
  * chore(deps): bump the aws group with 4 updates (#10796)
  * fix: use random suffix for process temp directory instead of PID (#10431)
  * docs: update signature verification for deb and rpm packages (#10784)
  * fix(image): lookup origin layer for custom resources in merged layers (#10788)
  * test: fix flaky containerd integration test (#10760)
  * ci: bump GoReleaser to v2.16.0 (#10774)
  * docs: fix broken nixpkgs reference link in installation guide (#10776)
  * test(java): force offline-scan for client/server integration tests (#10721)
  * fix(image): deterministic OS package deduplication for images with embedded SBOMs (#10777)
  * fix(spdx): guard against nil root component in SPDX marshaler (#10771)
  * ci(helm): bump Trivy version to 0.71.0 for Trivy Helm Chart 0.23.0 (#10768)


              

Packages


  • trivy-0.72.0-bp157.2.15.1