Skip to content

chore(deps): bump github.com/aquasecurity/trivy from 0.72.0 to 0.73.0 in the trivy group across 1 directory - #2632

Open
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/master/trivy-6aba48435a
Open

chore(deps): bump github.com/aquasecurity/trivy from 0.72.0 to 0.73.0 in the trivy group across 1 directory#2632
dependabot[bot] wants to merge 1 commit into
masterfrom
dependabot/go_modules/master/trivy-6aba48435a

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 7, 2026

Copy link
Copy Markdown
Contributor

Bumps the trivy group with 1 update in the / directory: github.com/aquasecurity/trivy.

Updates github.com/aquasecurity/trivy from 0.72.0 to 0.73.0

Release notes

Sourced from github.com/aquasecurity/trivy's releases.

v0.73.0

⚡ Highlights ⚡

👉 aquasecurity/trivy#11033

Changelog

https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md#0730-2026-08-03

Changelog

Sourced from github.com/aquasecurity/trivy's changelog.

0.73.0 (2026-08-03)

Features

  • add bounded read helpers (#10974) (35384b4)
  • java: read Jenkins plugin manifest licenses (#10939) (f065203)
  • java: support user-defined Maven mirrors in trivy.yaml (#11006) (8e5509c)
  • seal: detect no-prefix packages by version suffix (#10911) (69da733)
  • vex: discover OpenVEX in generic in-toto OCI referrers (#10986) (990d765)
  • vex: native discovery of VEX documents stored as OCI artifacts (#10932) (38d5dbd)

Bug Fixes

  • conda: avoid panic on an all-operator dependency line (#10955) (f964fa2)
  • dotnet: identify deps.json root project from dependency graph (#10954) (3c6a1a2)
  • java: set per-file digest for nested JARs (#10855) (c3c7d17)
  • misconf: guard nil Healthcheck when building Dockerfile from history (#10899) (824e2ed)
  • nodejs: support pnpm workspaces with overlapping packages (#10894) (19f2ddc)
  • vex: handle 304 status code (#10307) (e73c76d)
  • vex: reject non-local VEX repository names (#10987) (2c64b8f)
  • vuln: don't skip packages covered by a driver's own advisory feed (#10980) (86acabe)
Commits
  • 40c73e5 release: v0.73.0 [main] (#11012)
  • 7f33604 docs: clarify debug logs when version check or telemetry is disabled (#10984)
  • 8e5509c feat(java): support user-defined Maven mirrors in trivy.yaml (#11006)
  • a525f55 chore(deps): bump the common group across 1 directory with 17 updates (#11025)
  • 88ee124 chore(deps): bump the docker group across 1 directory with 2 updates (#10991)
  • 62bc7c9 chore(deps): bump the aws group across 1 directory with 6 updates (#10947)
  • 9321f90 refactor(alpine): remove type assertion when reading the APKINDEX archive (#1...
  • 6740bb8 chore(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.1 (#10995)
  • 990d765 feat(vex): discover OpenVEX in generic in-toto OCI referrers (#10986)
  • c9f5c85 refactor(vuln): add OS.Supplier field and unify supplier terminology (#11007)
  • Additional commits viewable in compare view

Most Recent Ignore Conditions Applied to This Pull Request
Dependency Name Ignore Conditions
github.com/aquasecurity/trivy [>= 0.50.2.a, < 0.50.3]
github.com/aquasecurity/trivy [< 0.51, > 0.50.1]

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Aug 7, 2026
Bumps the trivy group with 1 update in the / directory: [github.com/aquasecurity/trivy](https://github.com/aquasecurity/trivy).


Updates `github.com/aquasecurity/trivy` from 0.72.0 to 0.73.0
- [Release notes](https://github.com/aquasecurity/trivy/releases)
- [Changelog](https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md)
- [Commits](aquasecurity/trivy@v0.72.0...v0.73.0)

---
updated-dependencies:
- dependency-name: github.com/aquasecurity/trivy
  dependency-version: 0.73.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: trivy
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title chore(deps): bump github.com/aquasecurity/trivy from 0.72.0 to 0.73.0 in the trivy group chore(deps): bump github.com/aquasecurity/trivy from 0.72.0 to 0.73.0 in the trivy group across 1 directory Aug 10, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/master/trivy-6aba48435a branch from 508623e to 4a76861 Compare August 10, 2026 00:08
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants