v0.26.0 #2001
aqua-bot
announced in
Announcements
v0.26.0
#2001
Replies: 0 comments
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
Uh oh!
There was an error while loading. Please reload this page.
-
🚀 What's new? 🚀
🦍 Scan go.mod in Go 1.17+
Trivy now scans go.mod in Go 1.17+ projects. It detects only transitively-imported packages and provides more accurate detection. It used to include all transitive packages that are actually not imported in Go 1.16 or less projects.
https://go.dev/doc/go1.17#go-command
$ head -n 7 go.mod module github.com/aquasecurity/trivy go 1.18 require ( github.com/CycloneDX/cyclonedx-go v0.5.0 github.com/Masterminds/sprig/v3 v3.2.2 $ trivy fs ./go.mod 2022-04-14T14:45:15.768+0300 INFO Number of language-specific files: 1 2022-04-14T14:45:15.768+0300 INFO Detecting gomod vulnerabilities... go.mod (gomod) ============== Total: 2 (UNKNOWN: 1, LOW: 0, MEDIUM: 0, HIGH: 1, CRITICAL: 0) +----------------------------------+------------------+----------+--------------------+-----------------------+---------------------------------------+ | LIBRARY | VULNERABILITY ID | SEVERITY | INSTALLED VERSION | FIXED VERSION | TITLE | +----------------------------------+------------------+----------+--------------------+-----------------------+---------------------------------------+ | github.com/containerd/containerd | CVE-2022-23648 | HIGH | 1.5.9 | 1.4.13, 1.5.10, 1.6.1 | containerd: insecure | | | | | | | handling of image volumes | | | | | | | -->avd.aquasec.com/nvd/cve-2022-23648 | +----------------------------------+------------------+----------+--------------------+-----------------------+---------------------------------------+Note: Go 1.17+ must be specified in your go.mod, not your Go CLI version.
In Go 1.16 or less projects, Trivy takes direct dependencies from go.mod and indirect dependencies from go.sum.
For more detail, see here.
Kudos to @jerbob92
🦙 Support distroless images based on Alpine LInux
Trivy uses the repository version in
/etc/apk/repositoriesso that it can scan distroless images based on Alpine Linux.🐞 Bug fixes 🐛
Changelog
containerd/containerdversion to fix CVE-2022-23648 (chore(deps): replacecontainerd/containerdversion to fix CVE-2022-23648 #1994)This discussion was created from the release v0.26.0.
Beta Was this translation helpful? Give feedback.
All reactions