Releases: aquasecurity/trivy-action
Release: v0.35.0
This release is a duplicate of 0.35.0 which was not compromised.
As part of our response to the recent supply chain attack, we have migrated all tags to use the v prefix (e.g., v0.35.0 instead of 0.35.0). Going forward, all new releases will use the v prefix convention.
We have intentionally kept the 0.35.0 tag intact to avoid breaking existing workflows that depend on it.
If you are currently using 0.35.0, your workflows are safe — no action is required.
Release: 0.35.0
What's Changed
Full Changelog: 0.34.2...0.35.0
Release: v0.34.0
Full Changelog: v0.33.1...v0.34.0
Release: v0.33.1
What's Changed
- Update setup-trivy action to version v0.2.4 by @martincostello in #486
Full Changelog: v0.33.0...v0.33.1
Release: v0.33.0
What's Changed
- Update dependencies in README by @ibakshay in #378
- doc: correct sbom fs scan by @yxtay in #458
- Pin actions/cache by SHA by @martincostello in #480
- chore(ci): Add oras to correctly setup sync jobs by @simar7 in #482
- chore(deps): Update trivy to v0.65.0 by @aqua-bot in #481
New Contributors
Full Changelog: v0.32.0...v0.33.0
Release: v0.32.0
What's Changed
Full Changelog: v0.31.0...v0.32.0
Release: v0.31.0
What's Changed
- docs: add info that
unix:/prefix is required fordocker-hostinput by @DmitriyLewen in #455 - Fix Trivy action inputs leaking between invocations (#422) by @rvesse in #454
- Pin aquasecuriy/setup-trivy to hash instead of tag by @lhotari in #456
- Bump Trivy version to fix GitHub actions by @maximmasiutin in #460
- refactor: use ubuntu 24.04 in example code by @simar7 in #465
- ci: fix workflow to bump Trivy by @nikpivkin in #466
- chore(deps): Update trivy to v0.63.0 by @aqua-bot in #467
New Contributors
- @lhotari made their first contribution in #456
- @maximmasiutin made their first contribution in #460
Full Changelog: v0.30.0...v0.31.0
Release: v0.30.0
What's Changed
- fix: Update default trivy version in README by @derrix060 in #444
- fix: typo in description of an input for action.yaml by @yutatokoi in #452
- Improve README/SBOM by @AB-xdev in #439
- chore: bump trivy to v0.60.0 by @nikpivkin in #453
New Contributors
- @derrix060 made their first contribution in #444
- @yutatokoi made their first contribution in #452
- @AB-xdev made their first contribution in #439
Full Changelog: v0.29.0...v0.30.0
Release: v0.29.0
What's Changed
- feat: Allow skipping setup by @rvesse in #414
- Fix oras command not found in "Update Trivy Cache" action by @Tiryoh in #413
- Update README.md by @simar7 in #420
- feat: add token for
setup-trivyby @DmitriyLewen in #421 - fix: bump
setup-trivyand add newcontribdirectory path info by @DmitriyLewen in #424 - docs: remove ignore-unfixed from IaC scan example by @nikpivkin in #429
- chore(deps): Bump trivy to v0.57.1 by @simar7 in #434
New Contributors
Full Changelog: v0.28.0...v0.29.0
Release: v0.28.0
What's Changed
- chore(deps): bump setup-trivy to v0.2.1 by @DmitriyLewen in #411
Full Changelog: v0.27.0...v0.28.0