Skip to content
CAI
Software that uses CAICheck a score

aquasecurity/trivy

73.6

Strong · 6 August 2026

108.8k

lines of production code

Go

primary language

3

measurements over time

CAI band scale
CAI trend line
CAI lens gauges

What this system is

Trivy is a comprehensive, multi-format security scanner that analyzes container images, file systems, Git repositories, and virtual machines for vulnerabilities, misconfigurations, and license issues. It supports a wide array of programming languages, package managers, and operating systems, while also providing infrastructure-as-code scanning for platforms like Kubernetes, AWS, and Oracle Cloud. The system features a modular architecture that allows for extensible reporting, caching, and plugin-based execution.

How it got here

2019–2022 — Architecture modernization and platform expansion

131 changes.

This period focused on a comprehensive architectural refactoring, including a migration to the Cobra CLI framework, the introduction of a modular plugin and module system, and the adoption of standard libraries for logging and caching. Concurrently, the project significantly expanded its scanning capabilities by adding support for numerous Linux distributions, container runtimes, and virtual machine images, while also introducing new reporting formats and compliance features.

2023–2024 — IaC and dependency scanning expansion

148 changes.

This period focused on significantly expanding infrastructure-as-code scanning capabilities, particularly for Azure ARM templates, CloudFormation, and Terraform plan snapshots, while introducing a generic scanner for JSON/YAML/TOML files. Simultaneously, the codebase added support for a wide array of new package managers and lockfile formats, including Bun, Conda, Julia, Swift, and various Python and Node.js tools, alongside a complete rewrite of the Terraform parser and Rego scanning architecture.

2025–2026 — scanning expansion and infrastructure hardening

26 changes.

This period focused on broadening vulnerability detection capabilities by adding support for new operating systems, language ecosystems, and infrastructure-as-code formats. Concurrently, the codebase underwent significant architectural refactoring to improve modularity, testability, and security, including the introduction of centralized HTTP clients, process-safe file utilities, and robust end-to-end testing frameworks.

Features

Add .NET Core .deps.json dependency analysis

Users can now scan .NET Core projects that use .deps.json files to identify their dependencies. The new analyzer in the \pkg/fanal/analyzer/language/dotnet/deps\ directory parses these JSON files to extract package names and versions, enabling vulnerability and license checks for .NET Core applications.

pkg/fanal/analyzer/language/dotnet/deps · high confidence

Add .NET Packages.props analyzer

The tool now supports analyzing .NET projects that use the Packages.props file format. This new analyzer detects package dependencies defined in these project files, enabling the scanner to identify and report on NuGet package versions used in the application.

pkg/fanal/analyzer/language/dotnet/packagesprops · high confidence

Add .NET deps.json and WordPress version parsers

Added a new parser for .NET \\*.deps.json\ files, enabling the detection of dependencies and the bundled runtime in self-contained deployments. Also added a parser to extract the WordPress version from \version.php\. Both parsers include corresponding test cases.

pkg/dependency/parser/dotnet · high confidence

Add APK repository analyzer for Alpine Linux

A new analyzer has been added to detect and parse Alpine Linux repository configurations from /etc/apk/repositories. The implementation extracts the OS family and release version, supporting HTTP, HTTPS, and FTP URL schemes, and correctly identifies the highest version or 'edge' when multiple repositories are present. A corresponding test suite validates the parsing logic across various repository formats and edge cases.

pkg/fanal/analyzer/repo · high confidence

Add ARM template adapter for Azure network resources

Users can now have Azure network resources—specifically network security groups, network watchers (flow logs), and network interfaces—parsed from ARM templates. The new adapter in pkg/iac/adapters/arm/network extracts security group rules (including port ranges and address prefixes), flow log configurations, and network interface details, enabling existing Azure network checks to run against ARM-based IaC configurations.

pkg/iac/adapters/arm/network · high confidence

Add ARM template adapters for Azure Data Factory, Data Lake, and Synapse

New adapters have been added to parse Azure Resource Manager (ARM) templates for Azure Data Factory, Azure Data Lake, and Azure Synapse workspaces. Each adapter extracts specific security-relevant properties (public network access, encryption state, and managed virtual network status) and maps them to the internal IAC provider models, accompanied by corresponding unit tests.

pkg/iac/adapters/arm/datafactory, pkg/iac/adapters/arm/datalake, pkg/iac/adapters/arm/synapse · high confidence

Add AlmaLinux vulnerability detection support

Users can now scan for vulnerabilities on AlmaLinux operating systems. The new \alma\ package implements the \Scanner\ interface, enabling vulnerability detection for AlmaLinux 8, 9, and 10, with end-of-life dates configured for each. The implementation includes logic to handle modular packages by skipping those without a \MODularitylabel\ and correctly formatting modular package names for lookup. Tests verify the detection of standard and modular package vulnerabilities, as well as error handling for invalid advisory data.

pkg/detector/ospkg/alma · high confidence

Add Alpine APK index archive analyzer for image configuration

A new analyzer has been introduced to parse Alpine Linux package history from image configuration files. By fetching and decoding an APKINDEX archive (a JSON file containing package metadata, dependencies, and versions), the system can now identify which packages were installed or removed during the image build process. This enables more accurate tracking of installed software and their dependencies in Alpine-based images.

pkg/fanal/analyzer/imgconf/apk · high confidence

Add Alpine Linux (APK) package analysis

The tool now supports analyzing Alpine Linux packages by parsing the \lib/apk/db/installed\ database file. This new analyzer extracts package metadata including name, version, architecture, maintainer, license, and SHA1 digest, while also tracking installed files and dependency relationships to support vulnerability scanning and license compliance for Alpine-based systems.

pkg/fanal/analyzer/pkg/apk · high confidence

Add Alpine Linux OS version detection

Users can now detect the specific version of Alpine Linux from container images. This change introduces a new analyzer that reads the /etc/alpine-release file to identify the Alpine OS family and version, enabling more accurate vulnerability scanning for Alpine-based images.

pkg/fanal/analyzer/os/alpine · high confidence

Add Amazon Linux 2022 and 2023 OS detection

Users can now have their Amazon Linux 2022 and 2023 distributions correctly identified during vulnerability scanning. The new analyzer parses the \usr/lib/system-release\ file to detect these newer versions, while maintaining support for legacy Amazon Linux 1 and 2 via \etc/system-release\. This change ensures that security scans accurately reflect the operating system version for these specific Amazon Linux releases.

pkg/fanal/analyzer/os/amazonlinux · high confidence

Add Azure ARM adapter for Kubernetes clusters

Added the \pkg/iac/adapters/arm/container\ package to parse Azure Resource Manager (ARM) templates for managed Kubernetes clusters. The new adapter extracts cluster configuration including network policies, private cluster settings, RBAC status, addon profiles (OMS Agent, Azure Policy), and agent pool details, enabling security scanning of these resources.

pkg/iac/adapters/arm/container · high confidence

Add Azure App Service and Function App adapters

The system now includes new adapters for Azure App Service and Function App resources. This adds support for parsing and adapting Azure Web App and Function App configurations, including properties such as HTTPS enforcement, client certificate settings, identity types, authentication status, and site configuration details like TLS version, PHP/Python versions, and FTPS state.

pkg/iac/adapters/arm/appservice · high confidence

Add Azure Key Vault ARM adapter

Users can now have Azure Key Vault resources in their Infrastructure-as-Code (ARM) templates scanned for security and compliance. The new adapter parses ARM deployments to extract Key Vault configurations, including vault settings (purge protection, soft delete), keys, and secrets, mapping them to the internal provider model for evaluation.

pkg/iac/adapters/arm/keyvault · high confidence

Add Azure Security Center adapter for Infrastructure-as-Code scanning

Users can now scan Azure Resource Manager (ARM) templates for Microsoft.Security/securityContacts and Microsoft.Security/pricings resources. The new adapter extracts contact details (email, phone, alert settings) and subscription pricing tiers, enabling security and compliance checks on these specific Azure configurations during IaC analysis.

pkg/iac/adapters/arm/securitycenter · high confidence

Add Azure Storage Account ARM adapter

Introduces a new adapter in pkg/iac/adapters/arm/storage that converts Azure Resource Manager (ARM) deployment templates for storage accounts into the internal provider model. The implementation parses network ACLs, TLS versions, HTTPS enforcement, public network access, and related properties, and includes corresponding unit tests to verify the mapping logic.

pkg/iac/adapters/arm/storage · high confidence

Add Azure database and monitoring resource adapters

New ARM adapters have been introduced to parse Azure Resource Manager templates for Azure SQL, MySQL, MariaDB, and PostgreSQL database servers, as well as Azure Monitor log profiles. The database adapters extract security and configuration settings such as SSL enforcement, TLS versions, public network access, firewall rules, auditing policies, and threat detection policies. The monitor adapter extracts log profile categories, locations, and retention policies. Corresponding unit tests validate the adaptation of these resources from their JSON representations.

pkg/iac/adapters/arm/database · high confidence

Add Azure template function support for IAC scanning

The Azure scanner now supports a comprehensive set of template functions (e.g., \add\, \concat\, \base64\, \dateTimeAdd\, \createObject\) and a new expression lexer/parser. This enables the scanner to evaluate complex expressions within Azure Resource Manager (ARM) templates, allowing for more accurate detection of security issues in infrastructure-as-code configurations.

pkg/iac/scanners/azure/functions · high confidence

Add Bun package manager support

Users can now analyze Bun projects by scanning the \bun.lock\ file to identify dependencies and their licenses. This new analyzer registers under the \bun\ type, parses the lockfile for package details, and traverses \node\_modules\ directories to collect license information for each dependency.

pkg/fanal/analyzer/language/nodejs/bun, pkg/fanal/analyzer/language/python/uv · high confidence

Add Cargo lockfile parser for Rust dependencies

Introduced a new parser for Rust Cargo lockfiles (Cargo.lock), enabling the extraction of package names, versions, and dependency relationships. The implementation includes a naive line-number tracker to map package locations within the lockfile, supporting both legacy formats (with registry URLs in dependencies) and the newer v3 format (with checksums and simplified dependency lists). Test cases cover normal, mixed, and invalid lockfiles.

pkg/dependency/parser/rust/cargo · high confidence

Add CloudFormation adapters for AWS services

The CloudFormation scanner now supports parsing and adapting a wide range of AWS resources, including Access Analyzer, API Gateway (v1 and v2), Athena, CloudFront, CloudTrail, CloudWatch, CodeBuild, Config, DocumentDB, DynamoDB, EC2, and more. Each service has a dedicated adapter that converts CloudFormation template resources into internal data structures, enabling security and compliance checks on Infrastructure-as-Code templates.

pkg/iac/adapters/cloudformation/aws · high confidence

Add Conda environment file analysis with license detection

The Conda environment analyzer now parses \environment.yaml\ and \environment.yml\ files to detect installed packages. Additionally, it extracts license information by reading the corresponding \.json\ metadata files from the \conda-meta\ directory, enabling license tracking for Conda packages.

pkg/fanal/analyzer/language/conda/environment · high confidence

Add Conda meta parser for environment metadata

Added a new parser for Anaconda/Conda environment metadata (conda-meta/\*.json) that extracts package name, version, and license information. This enables Trivy to analyze dependencies in Conda environments by parsing the JSON metadata files found in the conda-meta directory.

pkg/dependency/parser/conda/meta · high confidence

Add Conda package metadata analyzer

A new analyzer has been added to parse Conda package metadata files (JSON files in the conda-meta directory). This enables the tool to detect and report Conda packages, including their names, versions, and licenses, as part of the software bill of materials (SBOM). The implementation includes the analyzer logic, unit tests, and test data fixtures.

pkg/fanal/analyzer/language/conda/meta · high confidence

Add CycloneDX SBOM report writer

A new CycloneDX report writer has been added to the product, enabling users to export Software Bill of Materials (SBOM) data in the CycloneDX format. The implementation introduces a \Writer\ struct that marshals internal report data into a CycloneDX \BOM\ object and encodes it as JSON, with HTML escaping explicitly disabled for the output.

pkg/report/cyclonedx · high confidence

Add DigitalOcean Terraform adapter for compute and spaces resources

The system now adapts DigitalOcean Terraform configurations, enabling the detection of security issues in DigitalOcean infrastructure-as-code. This includes parsing compute resources such as Droplets, Firewalls, Load Balancers, and Kubernetes Clusters, as well as Spaces bucket configurations including ACL, versioning, and object associations. The adapter maps these Terraform structures into internal models for subsequent security scanning.

pkg/iac/adapters/terraform/digitalocean · high confidence

Add EOL date data for Debian and Ubuntu releases

Added CSV data files and a Go script to track end-of-life dates for Debian and Ubuntu releases. The new \misc/eol/data/debian.csv\ and \misc/eol/data/ubuntu.csv\ files contain historical and current release information, enabling the system to identify when operating systems have reached their end-of-life status.

misc/eol · high confidence

Add GitHub Dependency Snapshots report format

A new \github\ report writer has been added to generate JSON output compatible with GitHub Dependency Snapshots. This format includes package URLs (PURLs), direct/indirect relationship types, and scope information for each dependency. For container images, the source location is replaced with the image name, tag, and hash; for other targets, the original file path is preserved. Tests confirm correct serialization of OS packages, npm, and Maven dependencies.

pkg/report/github · high confidence

Add Go binary analyzer for executable files

A new Go binary analyzer has been introduced to detect and parse dependencies from compiled Go executables. The \binary.go\ file registers a \gobinaryLibraryAnalyzer\ that identifies executable files and extracts their Go module dependencies. The accompanying \binary\_test.go\ provides unit tests for the analyzer's logic, including happy path scenarios, handling of non-Go binaries, and file permission checks.

pkg/fanal/analyzer/language/golang/binary · high confidence

Add Go module parser for Go 1.21+ toolchain and replace directives

Introduces a new Go module parser that parses go.mod files to extract package dependencies, including support for the \toolchain\ directive to identify the standard library version, handling of the \replace\ directive to resolve local or versioned replacements, and generation of direct/indirect dependency relationships for the main module.

pkg/dependency/parser/golang/mod · high confidence

Add Google Cloud KMS adapter to parse key ring and crypto key configurations

A new adapter has been added to map Terraform configurations for Google Cloud KMS resources, specifically \google\_kms\_key\_ring\ and \google\_kms\_crypto\_key\. The implementation parses the \rotation\_period\ attribute for crypto keys, safely handling cases where the attribute is missing, invalid, or absent, defaulting to -1 when the period cannot be determined. Corresponding tests verify the correct extraction of key rings, associated keys, and rotation periods from Terraform source code.

pkg/iac/adapters/terraform/google/kms · high confidence

Add Google Cloud SQL adapter with SSL mode support

The system now includes a new adapter for Google Cloud SQL database instances, enabling the detection of security misconfigurations for this cloud provider. The adapter parses Terraform configurations to extract database settings, including backup status, IP configuration, and various database flags. Notably, the adapter now supports the 'ssl\_mode' attribute for GCP SQL DB instances, allowing for more granular security checks regarding SSL/TLS requirements and client certificate validation.

pkg/iac/adapters/terraform/google/sql · high confidence

Add Google Cloud Storage adapter to parse Terraform configurations

The adapter now extracts Google Cloud Storage bucket details from Terraform configurations, including name, location, and uniform bucket-level access settings. It also parses IAM bindings and members associated with each bucket. Additionally, the adapter now supports reading logging configurations (log bucket and object prefix) and versioning settings from the Terraform resource blocks, allowing the security scanner to evaluate these specific bucket properties.

pkg/iac/adapters/terraform/google/storage · high confidence

Add Google Compute resource adapters

Added new adapters to parse Terraform configurations for Google Cloud Platform (GCP) compute resources, including instances, disks, networks, SSL policies, and project metadata. The implementation maps Terraform resource blocks to internal data structures, handling attributes such as encryption keys, shielded VM configurations, firewall rules, and metadata flags. Tests verify the correct parsing of these resources and their attributes.

pkg/iac/adapters/terraform/google/compute · high confidence

Add Google Container Registry authentication support

Users can now authenticate with Google Container Registry (GCR) and Google Artifact Registry (GAR) images. The system detects GCR and GAR domains and uses the docker-credential-gcr helper to retrieve credentials, with an option to specify a custom GCP credential path for authentication.

pkg/fanal/image/registry/google · high confidence

Add Google IAM adapter for Terraform

Added a new adapter in the \pkg/iac/adapters/terraform/google/iam\ package that translates Terraform configurations for Google Cloud IAM resources into a structured internal representation. The implementation covers organizations, folders, and projects, extracting IAM members, bindings, and audit configurations. It also supports workload identity pool providers. This enables the platform to analyze and report on Google Cloud IAM policies defined in Terraform code.

pkg/iac/adapters/terraform/google/iam · high confidence

Add Gradle lockfile parser to detect dev dependencies

A new parser for Gradle lockfiles has been introduced, enabling the system to parse dependency lockfiles and distinguish between production and development dependencies. The parser reads the lockfile format (group:artifact:version=classPaths) and sets a 'Dev' flag on packages whose classpaths contain 'test' configurations, allowing users to differentiate between runtime and test dependencies in their reports.

pkg/dependency/parser/gradle · high confidence

Add JSON and summary table output formats for compliance reports

The compliance report module now supports generating reports in JSON and summary table formats. Users can now export compliance scan results as structured JSON or as a summarized table view, providing more flexible ways to consume and analyze security and configuration findings.

pkg/compliance/report · high confidence

Add Java POM.xml analyzer to detect dependencies, licenses, and line numbers

The Java POM.xml analyzer is now available to scan pom.xml files for dependency information, including package names, versions, and license data. The analyzer also captures line number locations for dependencies and supports user-defined Maven mirrors via the trivy.yaml configuration. Additionally, dependencies from maven-invoker-plugin integration tests are marked as 'Dev' to be skipped by default.

pkg/fanal/analyzer/language/java/pom · high confidence

Add Java library post-analyzer for JAR/WAR/EAR/PAR files

A new post-analyzer has been introduced to process Java archive files (.jar, .war, .ear, .par). It leverages the trivy-java-db client to resolve library dependencies and extract license information from embedded POM files and packaged LICENSE files. The analyzer also ensures that each nested artifact carries its own file digest, preventing the enclosing archive's digest from overwriting it.

pkg/fanal/analyzer/language/java/jar · high confidence

Add Julia language analyzer support

Added a new post-analyzer for the Julia language that parses \Manifest.toml\ and \Project.toml\ files to identify direct and indirect dependencies, including support for dev dependencies and extension packages.

pkg/fanal/analyzer/language/julia · high confidence

Add Kubernetes manifest scanner for YAML and JSON

A new Kubernetes scanner is introduced in the \pkg/iac/scanners/kubernetes\ package, enabling the scanning of Kubernetes manifests in both YAML and JSON formats. The implementation provides a \NewScanner\ function that wraps a generic scanner with a parser for Kubernetes manifests, and includes tests verifying the scanning of multi-document YAML files and JSON payloads.

pkg/iac/scanners/kubernetes · high confidence

Add MinimOS vulnerability detection support

Users can now scan MinimOS packages for vulnerabilities. A new scanner has been added to detect vulnerabilities in MinimOS-based images by querying the trivy-db for relevant advisories and comparing installed package versions against fixed versions.

pkg/detector/ospkg/minimos · high confidence

Add NuGet dependency parsing for config, lock, and props files

The NuGet dependency parser now supports three new file formats to improve .NET project analysis. It can parse \packages.config\ XML files to extract package names and versions, ignoring development dependencies. It also parses \packages.lock.json\ files to identify direct and transitive dependencies, including multi-targeting scenarios. Finally, it reads \\*.props\ files (such as \Directory.Packages.props\) to capture centrally managed package versions, while correctly skipping entries with unresolved variables or empty values.

pkg/dependency/parser/nuget · high confidence

Add NuGet lock file and license analysis for .NET dependencies

The NuGet analyzer now parses \packages.lock.json\ files to extract direct dependencies, their versions, and dependency relationships. It also scans \.nuspec\ files in the local NuGet package cache to determine package licenses, which are now included in the analysis results. This enables visibility into both the dependency graph and licensing information for .NET projects.

pkg/fanal/analyzer/language/dotnet/nuget · high confidence

Add OCI artifact download and referrer listing capabilities

Users can now download single-layer OCI artifacts and list OCI 1.1 referrers by artifact type. The new \pkg/oci\ package introduces an \Artifact\ struct to handle downloading OCI artifacts, including support for CycloneDX, SPDX, Sigstore bundles, and DSSE envelopes. It also provides a \Referrers\ function to list OCI referrers matching specific artifact types, enabling discovery of SBOMs and attestations stored as OCI artifacts.

pkg/oci · high confidence

Add OS detection for AlmaLinux, CentOS, Fedora, Oracle Linux, and Rocky Linux

The fanal package now includes new analyzers for AlmaLinux, CentOS, Fedora, Oracle Linux, and Rocky Linux, each parsing their respective release files to identify the operating system family and version. Additionally, a new Debian OS analyzer has been added to detect Debian-based systems. These changes expand Trivy's capability to accurately identify and report on a broader range of Linux distributions during vulnerability scanning.

pkg/fanal/analyzer/os/redhatbase · high confidence

Add Oracle Linux vulnerability detection

Introduced a new Oracle Linux package scanner that detects vulnerabilities by querying the Oracle OVAL database. The implementation includes end-of-life date tracking for Oracle Linux versions 3 through 9, supports architecture-specific advisory matching, and filters advisories by package flavor to ensure accurate vulnerability reporting.

pkg/detector/ospkg/oracle · high confidence

Add PHP Composer lock file parser

The PHP dependency parser now supports parsing \composer.lock\ files. The new \pkg/dependency/parser/php/composer\ module extracts both production and development dependencies, preserving the distinction between them, and resolves the dependency graph to identify direct and indirect relationships.

pkg/dependency/parser/php · high confidence

Add Pipenv dependency analyzer

A new analyzer for Python Pipenv projects has been added to the fanal package. This change enables the tool to detect and analyze dependencies from Pipfile.lock files, integrating the Pipenv parsing logic into the standard analyzer registration process.

pkg/fanal/analyzer/language/python/pipenv · high confidence

Add Pipenv lock file parser for Python dependencies

A new parser has been added to Trivy to analyze Python dependencies from Pipenv lock files (Pipfile.lock). The implementation in \pkg/dependency/parser/python/pipenv\ includes the core parsing logic, test cases, and sample lock files, enabling the detection of Python packages and their versions directly from Pipenv's lock file format.

pkg/dependency/parser/python/pipenv · high confidence

Add Python package name normalization utility

Added a new utility function to normalize Python package names according to PEP 0503, which replaces runs of hyphens, underscores, or dots with a single hyphen and optionally converts the name to lowercase. This ensures consistent package name handling in the Python dependency parser.

pkg/dependency/parser/python · high confidence

Add Python packaging metadata parser

The Python dependency parser now reads package metadata from .egg-info/PKG-INFO and dist-info/METADATA files. It extracts the package name, version, and license information, prioritizing the 'License-Expression' field, then falling back to 'Classifier: License' entries and the 'License' field, with a debug log for packages where classifiers may be subject to additional terms.

pkg/dependency/parser/python/packaging · high confidence

Add Python pip requirements.txt parser

The tool now includes a new parser for Python \requirements.txt\ files, enabling the detection of Python package dependencies from this common configuration format. The parser supports multiple version specifiers, handles comments and extra dependencies, and can optionally use minimum versions for compatible releases.

pkg/dependency/parser/python/pip · high confidence

Add Python pyproject.toml parser with Poetry v2 and optional dependency support

A new parser for Python's pyproject.toml files has been introduced, enabling the extraction of project dependencies from both standard PEP 518 project sections and Poetry-specific tool configurations. The implementation supports Poetry v2's array-based dependency format alongside the legacy map format, and correctly aggregates main dependencies while handling optional dependencies and Poetry groups. This change improves dependency detection accuracy for modern Python projects using Poetry and standard pyproject.toml structures.

pkg/dependency/parser/python/pyproject · high confidence

Add RPM package analysis for archives, RPM databases, and rpmqa manifests

Users can now scan RPM archives (.rpm files), read installed packages from RPM databases (Packages, Packages.db, rpmdb.sqlite), and parse rpmqa manifests (e.g., for CBL-Mariner Distroless). The analyzer extracts package metadata including name, version, release, architecture, source package information, licenses, maintainer/vendor, and modularity labels. For RPM archives, it generates a Package URL (PURL) with namespace based on the vendor (e.g., redhat, fedora, suse). For RPM databases, it identifies official vs third-party packages and tracks installed files. This enables comprehensive RPM-based package detection across different sources.

pkg/fanal/analyzer/pkg/rpm · high confidence

Add Rekor client for querying Sigstore transparency log

Introduced a new Rekor client in pkg/rekor that implements search and bulk retrieval of entries from the Sigstore transparency log. The client supports both 80-character (TreeID + UUID) and 64-character (UUID-only) entry IDs, enforces a 10-entry limit per bulk fetch, and sets a 'trivy/' User-Agent header on requests. The change includes the client implementation, unit tests, and test data fixtures.

pkg/rekor · high confidence

Add Rekor client for retrieving SBOM attestations

A new Rekor client implementation has been added to the SBOM attestation package, enabling the system to query Rekor for SBOM attestations. The client searches for records by digest, retrieves the entries, and parses the in-toto attestation to extract the CycloneDX SBOM data. A corresponding test suite verifies the happy path and error handling for the retrieval process.

pkg/attestation/sbom · high confidence

Add Root.io vulnerability scanning for Debian, Ubuntu, and Alpine

Users can now scan container images for vulnerabilities using the Root.io security patch feed. The new scanner detects packages with Root.io version suffixes (e.g., \.root.io\ for Debian/Ubuntu, \-r\ patterns for Alpine) and reports vulnerabilities from Root.io, including severity levels and fixed versions. This adds a new data source for security patches on supported Linux distributions.

pkg/detector/ospkg/rootio · high confidence

Add Rust binary analysis for compiled executables

Users can now have Trivy analyze compiled Rust binaries to extract dependency information directly from the executable file. This new analyzer detects Rust executables by checking file permissions and content, then parses them to identify the root crate and its dependencies, enabling vulnerability scanning of pre-compiled Rust applications without requiring source code or Cargo.toml files.

pkg/fanal/analyzer/language/rust/binary · high confidence

Add SPDX SBOM report generation support

Users can now generate Software Bill of Materials (SBOM) reports in SPDX format. The new \pkg/report/spdx\ package provides a writer that converts internal report data into SPDX documents, supporting both the tag-value and JSON output formats. This enables users to export vulnerability and dependency data in the standardized SPDX format for compliance and supply chain analysis.

pkg/report/spdx · high confidence

Add Spring4Shell detection module for Java/Tomcat environments

A new Spring4Shell detection module has been added to the examples directory, providing in-depth investigation of the Spring4Shell vulnerability ([CVE redacted]). The module is implemented as a WebAssembly (WASM) Go module that parses Java release files and Tomcat release notes to extract version information. It then adjusts the severity of the [CVE redacted] finding from CRITICAL to LOW if the detected Java version is not affected by the vulnerability. This allows users to more accurately assess risk in environments running specific Java and Tomcat versions.

examples/module · high confidence

Add Swift CocoaPods dependency parser

A new parser for Swift CocoaPods lock files has been added to the dependency scanning engine. This change introduces the \pkg/dependency/parser/swift/cocoapods\ module, which parses \Podfile.lock\-style YAML files to extract package names, versions, and dependency relationships. The implementation includes the core parsing logic, unit tests, and sample lock files for validation, enabling the tool to analyze dependencies in Swift projects managed by CocoaPods.

pkg/dependency/parser/ruby/gemspec, pkg/dependency/parser/rust/binary, pkg/dependency/parser/swift/cocoapods · high confidence

Add Swift CocoaPods lock file analysis

Users can now have Swift CocoaPods lock files (Podfile.lock) analyzed for dependencies. This new analyzer registers to detect and parse CocoaPods lock files, extracting package names, versions, and dependency relationships from the lock file content.

pkg/fanal/analyzer/language/swift/cocoapods · high confidence

Add Swift Package Manager dependency parser

Users can now scan Swift projects by parsing \Package.resolved\ lock files. The new parser in \pkg/dependency/parser/swift\ extracts package names and versions from both v1 and v2 lock file formats, supporting resolution via version strings or git branches.

pkg/dependency/parser/swift/swift · high confidence

Add Terraform Plan protobuf schema for variable support

The codebase now includes a new Protocol Buffers definition (planfile.proto) and its Go implementation (planfile.pb.go) within the Terraform plan snapshot package. This change introduces the \DynamicValue\ and \Plan\ message structures, enabling the system to serialize and deserialize Terraform plan data in a structured format, which supports the new capability to handle variables in Terraform plan snapshots.

pkg/iac/scanners/terraformplan/snapshot/planproto · high confidence

Add Terraform Plan snapshot scanning support

Users can now scan Terraform plan files (tfplan) for misconfigurations. The new \snapshot\ package in \pkg/iac/scanners/terraformplan/snapshot\ parses the plan's state and configuration, converting it into a virtual filesystem that is then scanned by the existing Terraform scanner. This enables detection of issues in planned infrastructure changes.

pkg/iac/scanners/terraformplan/snapshot · high confidence

Add Terraform adapter support for GitHub repository, branch protection, and environment secrets

Users can now scan Terraform configurations for GitHub-specific resources, including \github\_repository\, \github\_branch\_protection\, and \github\_actions\_environment\_secret\. The new adapters extract key security and configuration attributes: for repositories, it detects public/private status, vulnerability alert settings (including the newer \github\_repository\_vulnerability\_alerts\ resource), and archive state; for branch protections, it identifies whether signed commits are required; and for environment secrets, it captures secret names, environments, and values. This enables security and compliance checks against these GitHub infrastructure-as-code patterns.

pkg/iac/adapters/terraform/github · high confidence

Add Terraform adapters for CloudStack, Google (BigQuery, DNS), and OpenStack

The codebase now includes new Terraform adapters for CloudStack, Google (BigQuery and DNS), and OpenStack, enabling the scanning of infrastructure-as-code for these platforms. Each adapter parses the relevant Terraform resources and maps them to internal security models, with corresponding test files verifying the adaptation logic.

(repo-wide) · high confidence

Add Terraform plan JSON parser to convert plan data into HCL format

A new parser in the \pkg/iac/scanners/terraformplan/tfjson/parser\ package enables scanning of Terraform plan JSON files. It parses the \planned\_values\, \resource\_changes\, and \configuration\ sections of a Terraform plan, reconstructing the resource definitions into a virtual file system containing HCL (HashiCorp Configuration Language) code. This allows downstream scanners to analyze the planned state of infrastructure as if it were a standard Terraform configuration file.

pkg/iac/scanners/terraformplan/tfjson/parser · high confidence

Add VEX support for filtering vulnerabilities

Introduced a new VEX (Vulnerability Exploitability eXchange) filtering system that allows users to suppress or mark vulnerabilities as not affected based on external VEX documents. The implementation supports multiple VEX formats including OpenVEX, CSAF, and CycloneDX, and can load VEX documents from local files, OCI registry attestations, SBOM external references, and configured VEX repositories. The system integrates with the vulnerability scanning pipeline to modify findings based on VEX statements, supporting complex product and sub-product relationship matching.

pkg/vex · high confidence

Add Yarn lockfile parser

The Trivy scanner now includes a new parser for Yarn lockfiles (yarn.lock), enabling the detection of direct dependencies and version information from Yarn's lockfile format. This addition allows the tool to correctly identify and report Node.js dependencies managed by Yarn, including support for various protocols like npm, git, and local file references, as well as handling of Yarn v1 and v2 lockfile structures.

pkg/dependency/parser/nodejs/yarn, pkg/dependency/parser/ruby/bundler, pkg/dependency/parser/sbt · high confidence

Add \`trivy auth\` CLI commands for registry authentication

Users can now use the \trivy auth\ command to log in to and out of container registries. The new \Login\ function validates credentials, authenticates against the registry, and stores the credentials in the Docker configuration file, while \Logout\ removes stored credentials. Tests confirm that only a single set of credentials is allowed and that invalid registries or missing credentials are properly rejected.

pkg/commands/auth · high confidence

Add bounded read helpers to the io utility package

The io utility package now includes new helpers for bounded reads and byte counting. A CountingReader wraps an io.Reader to track the number of bytes read. A MaxBytesReader enforces a byte limit on reads, returning a MaxBytesError when the limit is exceeded. A ReadAllWithLimit function reads all data up to a specified byte limit. Additionally, the package provides a context-aware Copy function that supports cancellation, and utility functions to convert readers into ReadSeekerAt interfaces.

pkg/x/io · high confidence

Add clean subcommand to remove local cache and database files

A new \clean\ subcommand has been added to the CLI, allowing users to selectively remove local scan cache, vulnerability database, Java database, check bundles, and VEX repositories. The command supports a \--all\ flag to clear all local data at once, or individual flags to target specific components. This provides a way to free up disk space and reset local state without deleting the entire cache directory.

pkg/commands/clean · high confidence

Add container image configuration secret scanning

A new secret analyzer has been introduced for container image configurations, enabling the detection of sensitive data such as GitHub Personal Access Tokens within the image's environment variables. The implementation registers a config analyzer that marshals the image config to JSON and scans it for secrets, returning findings with specific line numbers and byte offsets. A corresponding test suite verifies the analyzer's ability to detect secrets and handle nil or empty configurations.

pkg/fanal/analyzer/imgconf/secret · high confidence

Add convert command to transform JSON reports

A new 'convert' command has been added to the CLI, allowing users to read a Trivy JSON report and write it out in a different format. The command handles compatibility by populating missing package UIDs in older reports and supports filtering and summary table generation. It also respects custom exit codes from plugins.

pkg/commands/convert · medium confidence

Add executable file analyzer to compute SHA-256 digests

The system now includes a new analyzer for unpackaged binaries. This analyzer detects executable files that are not managed by package managers and computes their SHA-256 digest. This capability enables the system to search for SBOM (Software Bill of Materials) attestations for these binaries in a subsequent processing step.

pkg/fanal/analyzer/executable · high confidence

Add file utility functions for path skipping and binary detection

Added new utility functions in pkg/fanal/utils to support file scanning operations. The changes introduce helpers for detecting Gzip files, identifying executable files (including Windows .exe and unpackaged binaries), and filtering file paths against skip patterns using the doublestar library. Additionally, a function is added to extract printable bytes from file content, which supports secret scanning and misconfiguration detection workflows by isolating text segments from binary data.

pkg/fanal/utils · high confidence

Add filesystem utility functions for file and directory operations

A new fsutils package was introduced, providing safe helpers for file and directory checks (DirExists, FileExists), a CopyFile utility, and a WalkDir function that filters by extension. These utilities allow the application to more reliably and safely interact with the local filesystem, reducing the need for ad-hoc file handling throughout the codebase.

pkg/utils · high confidence

Add generic and case-insensitive set implementations

The \pkg/set\ package now provides a generic \Set\ interface and an \unsafeSet\ implementation for standard, case-sensitive set operations. Additionally, a new \caseInsensitiveStringSet\ implementation is introduced, which stores strings with case-insensitive comparison while preserving the original casing of the first occurrence. Both implementations support standard set operations such as \Append\, \Remove\, \Contains\, \Union\, \Intersection\, and \Difference\. Tests have been added to verify the behavior of both the generic and case-insensitive set implementations.

pkg/set · high confidence

Add generic scanner for JSON, YAML, and TOML files

A new generic scanner has been introduced in the IaC scanning pipeline, enabling the scanning of JSON, YAML, and TOML configuration files. This change allows users to apply Rego-based security policies to these common configuration file formats, expanding the scope of infrastructure-as-code scanning beyond Terraform and CloudFormation.

pkg/iac/scanners/generic · high confidence

Add generic thread-safe map utility

A new generic, thread-safe map implementation is introduced in the sync package, wrapping the standard library's sync.Map with type-safe methods for loading, storing, and deleting entries, along with a Len() helper.

pkg/x/sync · high confidence

Add initial support for scanning Ansible playbooks

Users can now scan Ansible playbooks for security issues. This change introduces an adapter that parses Ansible tasks and maps them to internal state structures, specifically supporting the detection of AWS S3 bucket configurations such as encryption, public access blocks, and versioning settings.

pkg/iac/adapters/ansible · high confidence

Add license file header scanning

A new license file analyzer has been introduced to scan source code headers for license information. The analyzer processes text-based files with accepted extensions (such as .c, .java, .js, etc.) and skips specific system directories. It leverages an external licensing library to classify headers and returns license findings with confidence levels. A test file with an AGPL-3.0 header is included to verify the scanning logic.

pkg/fanal/analyzer/licensing · high confidence

Add new report templates and CI integration for GitLab, HTML, JUnit, and AWS Security Hub

Users can now generate security reports in multiple new formats. A GitLab CI configuration file (Trivy.gitlab-ci.yml) is added to integrate Trivy with GitLab Container Scanning. New templates are introduced for the AWS Security Hub (asff.tpl), GitLab code quality (gitlab.tpl and gitlab-codequality.tpl), HTML (html.tpl), and JUnit (junit.tpl) reporting, enabling users to export scan results in these specific formats for integration with their respective platforms.

contrib · high confidence

Add new slice utility functions

The pkg/x/slices package introduces two new utility functions: Map, which transforms a slice of one type to another without providing an index to the transform function, and ZeroToNil, which converts empty slices to nil. These additions provide new capabilities for slice manipulation within the library.

pkg/x/slices · high confidence

Add path utility for subpath detection

A new \path\ package has been introduced, providing a \Contains\ function that checks if a file path string contains a specific subpath component. This utility supports logic for identifying path segments, such as detecting 'node\_modules' within a file path, which is relevant for the fix regarding lock file detection in node\_modules.

pkg/x/path · high confidence

Add pnpm lockfile and license analysis support

Users can now scan projects that use the pnpm package manager. The new pnpm analyzer parses pnpm-lock.yaml files to identify installed packages and their versions, and it also scans the corresponding node\_modules directory to extract license information for each package. Tests confirm that both direct and indirect dependencies are correctly identified and that license data is properly associated with the packages.

pkg/fanal/analyzer/language/nodejs/pnpm · high confidence

Add server mode to run Trivy as an RPC server

A new 'server' command has been introduced, allowing Trivy to run as an RPC server that accepts scan requests. The implementation initializes the HTTP transport, configures the cache, downloads the vulnerability database, initializes the DB, loads WASM modules, and starts the RPC server with support for path prefixes, tokens, and custom CA certificates.

pkg/commands/server · high confidence

Add support for Cosign vulnerability attestation

The system now generates a Cosign vulnerability predicate, allowing users to produce vulnerability reports in a format compatible with the Cosign attestation standard. This new capability is implemented in the predicate package, which defines the necessary data structures and a writer to serialize vulnerability data into the required JSON format.

pkg/report/predicate · high confidence

Add support for Elixir mix.lock files

Users can now scan Elixir projects for dependencies recorded in mix.lock lockfiles. A new mixLockAnalyzer registers to parse mix.lock files, extracting package names and versions (e.g., bunt@0.2.0) from the lockfile, enabling vulnerability and license checks on those dependencies.

pkg/fanal/analyzer/language/elixir · high confidence

Add support for Swift Package.resolved lock files

The Swift analyzer now detects and parses \Package.resolved\ files, extracting the list of Swift package dependencies and their versions. This enables the tool to identify vulnerabilities in Swift dependencies managed via the Swift Package Manager.

pkg/fanal/analyzer/language/swift/swift · high confidence

Add support for Ubuntu ESM (Extended Security Maintenance) status

The Ubuntu OS analyzer now detects whether Ubuntu Extended Security Maintenance (ESM) is enabled by reading the \status.json\ file from the Ubuntu Advantage client. When ESM is active, the OS analysis result will include \Extended: true\, allowing downstream tools to distinguish between standard and extended-support Ubuntu releases. The change also includes the corresponding unit tests for both the ESM and standard Ubuntu OS analyzers.

pkg/fanal/analyzer/os/ubuntu · high confidence

Add support for analyzing Conan lock files

The C language analyzer now supports parsing \conan.lock\ files to identify dependencies and their licenses. The new \conanLockAnalyzer\ walks the Conan cache directories (both v1 and v2) to extract license information for each package, which is then attached to the lock file's dependency graph. This allows users to see license details for C/C++ projects managed by Conan.

pkg/fanal/analyzer/language/c · high confidence

Add support for analyzing Gradle lockfiles

Users can now scan \gradle.lockfile\ files to detect Java dependencies, their licenses, and dependency relationships. The analyzer reads the lockfile to identify packages and then cross-references the Gradle cache to parse corresponding POM files, enriching the results with license information and dependency graphs.

pkg/fanal/analyzer/language/java/gradle · high confidence

Add support for detecting vulnerabilities in Bottlerocket OS packages

Users running containers based on the Bottlerocket OS can now have their installed packages scanned for known vulnerabilities. This change introduces a new analyzer that parses the Bottlerocket application-inventory.json file to identify installed packages, and a corresponding scanner that matches those packages against the vulnerability database to report security advisories.

_pkg/detector/ospkg/bottlerocket, pkg/fanal/analyzer/pkg/bottlerocket\inventory · high confidence

Add support for detecting vulnerabilities in Rocky Linux packages

Users can now scan for vulnerabilities in Rocky Linux operating system packages. The new Rocky Linux scanner detects vulnerabilities by comparing installed package versions against advisory data, including support for modular packages (e.g., nginx:1.16) and architecture-specific fixes. The scanner also enforces end-of-life (EOL) date checks for supported versions.

pkg/detector/ospkg/rocky · high confidence

Add support for parsing C/C++ dependencies from Conan lockfiles

Users can now scan C and C++ projects managed by the Conan package manager. Trivy will parse \conan.lock\ files to identify direct and indirect dependencies, supporting both Conan v1.x and v2.x lockfile formats.

pkg/dependency/parser/c · high confidence

Add support for parsing Julia project manifests

Users can now scan Julia projects for dependencies. The new parser in \pkg/dependency/parser/julia\ extracts package names, versions, and dependency graphs from \Manifest.toml\ files, supporting both legacy (v1.0) and modern (v1.6+) TOML formats. The implementation includes a naive line-number parser to provide source locations for each dependency.

pkg/dependency/parser/julia · high confidence

Add support for parsing Mix lock files in Hex dependencies

Users can now scan for dependencies in Elixir Mix lock files. A new parser has been added to the Hex dependency parser to read \mix.lock\ files, extracting package names and versions from the lockfile format. This enables Trivy to identify and report on Elixir project dependencies managed by Mix.

pkg/dependency/parser/hex · high confidence

Add support for parsing Python Poetry lockfiles

Users can now scan Python projects managed by Poetry, as the tooling now includes a dedicated parser for \poetry.lock\ files. This new capability allows Trivy to extract package names, versions, and dependency relationships directly from Poetry's lockfile, supporting both legacy (v1) and modern (v2) lockfile formats. The implementation handles package name normalization and correctly identifies development dependencies, ensuring accurate vulnerability reporting for Python projects using this dependency manager.

pkg/dependency/parser/nodejs/bun, pkg/dependency/parser/python/poetry, pkg/dependency/parser/python/uv · high confidence

Add support for scanning AWS AMI, EBS snapshots, and local VM image files

Users can now scan virtual machine images directly, including AWS AMI and EBS snapshots via the \ami:\ and \ebs:\ prefixes, as well as local VM image files (e.g., VMDK, raw images) via the \file:\ prefix. This introduces new artifact types that allow Trivy to analyze the contents of virtual machine disks for vulnerabilities and misconfigurations.

pkg/fanal/artifact/vm · high confidence

Add support for scanning Amazon Linux 2023

The Amazon Linux OS package detector now supports scanning for vulnerabilities on Amazon Linux 2023, in addition to the existing support for Amazon Linux 1 and 2. The scanner's logic has been updated to recognize and handle the '2023' version identifier, ensuring that vulnerability advisories for this OS release are correctly retrieved and matched against installed packages.

pkg/detector/ospkg/amazon · high confidence

Add support for scanning Seal packages for vulnerabilities

The vulnerability detector now includes a new scanner for packages from the Seal security database. This addition enables the detection of vulnerabilities in packages identified by the 'seal' prefix across supported operating systems including Debian, Ubuntu, Alpine, Red Hat, and CentOS. The implementation introduces a new \seal\ package in the detector's OS package handling, allowing the system to query the Seal security database for relevant advisories and report them alongside standard OS package vulnerabilities.

pkg/detector/ospkg/seal · high confidence

Add support for scanning Terraform plan JSON files

A new scanner has been introduced to process Terraform plan JSON files. It parses the JSON plan, converts it into a filesystem representation, and delegates the actual scanning to the existing Terraform scanner, enabling users to scan Terraform plan outputs for security issues.

pkg/iac/scanners/terraformplan/tfjson · high confidence

Add support for scanning virtual machine disk images and filesystems

Introduced new packages under pkg/fanal/vm to enable scanning of virtual machine disk images and their internal filesystems. The disk package provides a unified interface for parsing VM disk formats (e.g., VMDK), while the filesystem package adds support for ext4 and xfs filesystems. This change allows the tool to analyze the contents of virtual machine disks by detecting and mounting their filesystems.

pkg/fanal/vm · high confidence

Add support for scanning vulnerabilities in Photon OS packages

Users can now scan for vulnerabilities in Photon OS packages. This change introduces a new scanner for Photon OS that detects vulnerabilities by querying the Trivy database for Photon-specific advisories, including support for version comparison and end-of-life date checks for supported OS versions.

pkg/detector/ospkg/photon · high confidence

Add vulnerability detection for Azure Linux and CBL-Mariner

Introduced a new detector in pkg/detector/ospkg/azure that enables vulnerability scanning for Azure Linux and CBL-Mariner operating systems. The implementation includes the core scanner logic, unit tests, and test fixtures to support these new distributions.

pkg/detector/ospkg/azure · high confidence

Add vulnerability detection support for Wolfi Linux and Chainguard

Users can now scan for vulnerabilities in packages from the Wolfi Linux and Chainguard distributions. This change introduces new scanner implementations for these OS families, enabling Trivy to detect and report security issues specific to these package ecosystems.

pkg/detector/ospkg/wolfi · high confidence

Add vulnerability fingerprinting and unique artifact identification

Scan reports now include a deterministic SHA-256 fingerprint for each vulnerability, enabling external systems to track and deduplicate findings across multiple scans. The ArtifactID, used to uniquely identify the scanned target, now incorporates the registry and repository information for container images, ensuring that the same image in different repositories or registries receives a distinct ID. Additionally, the scan service was refactored from a 'Scanner' to a 'Service' with manual dependency injection, and utility functions were added to format package versions.

pkg/scan · high confidence

Add vulnerability scanning support for the Echo Linux distribution

Users can now scan for vulnerabilities in packages from the Echo Linux distribution. This change introduces a new scanner in the \pkg/detector/ospkg/echo\ package that processes vulnerability data from the Echo advisory feed. The implementation includes the core detection logic, unit tests, and test fixtures to support this new OS type.

pkg/detector/ospkg/echo · high confidence

Added Azure Compute resource adapter

Users can now have Azure Compute resources (virtual machines and managed disks) adapted from ARM templates. The new \adapt.go\ file implements the \Adapt\ function which processes \Microsoft.Compute/disks\ and \Microsoft.Compute/virtualMachines\ resources, mapping them to the internal \compute.Compute\ struct. This includes extracting properties like encryption status for disks, custom data, and Linux/Windows configuration details for virtual machines.

pkg/iac/adapters/arm/compute · high confidence

Added Azure RBAC adapter for ARM templates

Users can now have Azure ARM templates evaluated for Azure RBAC configurations, including role definitions and role assignments. This new adapter extracts role definition details (permissions, assignable scopes) and role assignment details (principal ID, type, and role definition ID) from ARM deployments, enabling security and compliance scanning for these specific Azure resources.

pkg/iac/adapters/arm/authorization · high confidence

Added Conda environment.yml parser

Trivy now parses Conda environment.yml files to extract package names and pinned versions, including support for pip dependencies nested under the 'pip' key. The parser handles standard conda package specifications and gracefully handles edge cases like operator-only dependency lines.

pkg/dependency/parser/conda/environment · high confidence

Added Dart Pub lockfile parser

Users can now scan Dart projects by parsing \pubspec.lock\ files. The new parser extracts package names, versions, and dependency relationships (direct vs. indirect). It also supports resolving SDK constraints to determine minimum acceptable versions when configured.

pkg/dependency/parser/dart · medium confidence

Added GKE adapter to parse Terraform configurations

A new adapter has been introduced in the GKE package to parse Terraform configurations for Google Kubernetes Engine clusters. The implementation maps Terraform resources such as \google\_container\_cluster\ and \google\_container\_node\_pool\ into internal data structures, capturing settings like IP allocation policies, network policies, master authentication, node configurations, and auto-scaling defaults. A corresponding test suite validates the adaptation of these resources, ensuring that attributes like \enable\_shielded\_nodes\, \enable\_legacy\_abac\, and \auto\_provisioning\_defaults\ are correctly interpreted.

pkg/iac/adapters/terraform/google/gke · high confidence

Added Go SDK for WebAssembly modules

A new Go-based SDK has been added to support WebAssembly modules, providing memory management and logging functions that bridge the Go runtime with the host environment via WASI imports and exports.

pkg/module/wasm · high confidence

Added OS package version comparison and constraint checking

Introduced a new \pkg/detector/ospkg/version\ package that provides version comparison and constraint checking for OS package managers. The \compare.go\ file adds \Comparer\ implementations for Debian/Ubuntu (DEB), Alpine (APK), and RedHat (RPM) packages, enabling accurate version sorting and comparison. The \constraint.go\ file introduces a \Constraints\ type that parses and evaluates version constraints (e.g., \\>=1.2.3\, \\<2.0.0\) against package versions, supporting multiple conditions with AND logic. Additionally, \version.go\ provides utility functions to extract major/minor version components and check if an OS version is still supported based on an End-of-Life (EOL) date map.

pkg/detector/ospkg/version · high confidence

Added Red Hat build info analysis for content manifests and Dockerfiles

The buildinfo analyzer now extracts Red Hat-specific build metadata from container images. It parses JSON content manifests located in root/buildinfo/content\_manifests/ and usr/share/buildinfo/ to identify content sets, and parses Dockerfiles in root/buildinfo/ to extract component names, versions, and architecture from labels. This enables Trivy to report detailed build information for Red Hat-based images.

pkg/fanal/analyzer/buildinfo · high confidence

Added Ruby gemspec and Bundler analyzers

The Ruby language analyzer now includes dedicated analyzers for parsing Gemfile.lock (Bundler) and .gemspec files. This enables Trivy to detect Ruby package dependencies and their licenses from these specific file types, with test coverage confirming correct parsing of package names, versions, and multiple licenses.

pkg/fanal/analyzer/language/ruby · high confidence

Added SPDX SBOM import and export capabilities

Users can now import and export Software Bill of Materials (SBOM) in the SPDX format. The \pkg/sbom/spdx\ package provides a \Marshaler\ to convert internal BOM structures into SPDX documents, and an \Unmarshaler\ to parse incoming SPDX JSON or tag-value files into Trivy's internal component and relationship models. This includes support for parsing package metadata, licenses, file hashes, and relationships, enabling seamless integration with tools that use the SPDX standard.

pkg/sbom/spdx · high confidence

Added Terraform adapters for Google, Kubernetes, and Oracle Cloud Infrastructure

New adapter files have been introduced to parse Terraform configurations for Google Cloud (BigQuery, Compute, DNS, GKE, IAM, KMS, SQL, Storage), Kubernetes (Network Policies), and Oracle Cloud Infrastructure (Compute). These adapters map Terraform resource blocks into a unified internal state, enabling Trivy to scan these specific infrastructure-as-code templates for security and compliance issues.

(repo-wide) · high confidence

Added automated build scripts for documentation, schema, and test fixtures

The \magefiles\ directory now contains new Go-based build scripts that automate the generation of the \trivy.yaml\ configuration JSON schema, CLI reference documentation, and integration test fixtures. These scripts replace the previous Makefile-based approach, providing a more integrated way to generate the configuration schema, update Helm chart versions, and manage test data.

magefiles · high confidence

Added compliance spec parsing and result mapping logic

Added new Go files in pkg/compliance/spec to handle compliance specifications. The changes introduce a new spec package that parses compliance specifications from YAML files or embedded libraries, maps check IDs to specific scanners (vulnerability, misconfiguration, or secret), and filters scan results by severity or type. This includes functions to load specs from disk or cache, identify relevant scanners based on check ID prefixes, and map filtered results to compliance check IDs.

pkg/compliance/spec · high confidence

Added dpkg license and package analysis

Added a new dpkg analyzer that parses copyright files to detect package licenses and parses the dpkg status and md5sums files to identify installed files and package metadata. The analyzer distinguishes between official and third-party packages based on maintainer information, allowing the system to properly handle language-specific package scanning for third-party repositories.

pkg/fanal/analyzer/pkg/dpkg · high confidence

Added generic string conversion utilities

A new 'strings' package was introduced containing generic helper functions for converting slices of various types to string slices and vice versa. The 'ToStringSlice' function converts a slice of any type to a string slice, utilizing the 'fmt.Stringer' interface or 'fmt.Sprint' for conversion, while 'ToTSlice' converts a string slice to a specific type T. This change relies on the newly added 'xslices.Map' function.

pkg/x/strings · high confidence

Added gzip file opening utility

A new utility function, OpenFile, has been introduced in the gzip package. This function opens a file and automatically detects and decompresses gzip-compressed files, returning a unified ReadCloser interface. This simplifies file handling by abstracting away the need to manually check file types and wrap readers with gzip decompressors.

pkg/fanal/utils/gzip · high confidence

Added local auth server configuration and TLS certificates for integration testing

The integration test suite now includes a local authentication server configuration and associated TLS certificates. A new \config.yml\ file defines the server's address, token issuer, expiration, and user credentials (admin and test users) along with their access control lists. Additionally, new \cert.pem\ and \key.pem\ files provide the TLS certificate and private key required for secure communication with this local auth server.

integration/data · high confidence

Added process-safe temp file cleanup and path confinement utilities

The pkg/x/os package introduces a new process-specific temporary directory mechanism that uses random suffixes (via os.MkdirTemp) to avoid collisions when multiple processes share the same /tmp, addressing issues with Kubernetes emptyDir volumes where all containers run as PID 1. This includes functions CreateTemp, MkdirTemp, TempDir, and Cleanup to manage this isolated temp directory. Additionally, a new Root type is provided, embedding os.Root to offer traversal-resistant directory handling with a Join method that validates names to prevent path escapes, supporting safer file operations within a confined directory.

pkg/x/os · high confidence

Added registry mirror support and centralized remote access logic

The \pkg/remote\ package was refactored to support registry mirrors, allowing the system to attempt image downloads from configured mirror registries before falling back to the primary host. This change introduces a new \remote.go\ file that wraps \go-containerregistry\ calls, implementing a retry loop over mirrors and multiple authentication methods (basic auth, tokens, and GitHub tokens). Corresponding tests were added to verify mirror fallback behavior and credential handling.

pkg/remote · high confidence

Added semaphore package for concurrency control

A new 'semaphore' package has been introduced in 'pkg/semaphore/semaphore.go' to manage concurrent access using a weighted semaphore. This provides a configurable parallelism limit, defaulting to 5, which can be adjusted via the 'parallel' parameter in the 'New' function.

pkg/semaphore · high confidence

Added utility functions for deduplicating and merging package data

New utility functions were added to the dependency parser utils package to handle package deduplication and map merging. The \UniquePackages\ function consolidates duplicate package entries by merging their location data and preserving the non-dev dependency status, addressing issues where the same package appears as both a root and dev dependency. Additionally, the \MergeMaps\ function provides a safe way to merge string maps by cloning the parent map before copying, preventing unintended overwrites. A corresponding test suite was added to verify the correct merging of locations and dependency types.

pkg/dependency/parser/utils · high confidence

Analyze Composer lock and vendor files for PHP dependencies

The PHP analyzer now parses \composer.lock\ and \composer.json\ to identify direct and transitive dependencies, including support for dev dependencies. It also analyzes \installed.json\ files from the \vendor\ directory. The analyzer skips \composer.lock\ files located inside the \vendor\ folder to avoid duplicate or incorrect analysis. Test coverage has been added for these new capabilities.

pkg/fanal/analyzer/language/php · high confidence

Automated backporting script added

A new shell script, misc/backport/backport.sh, has been introduced to automate the process of creating backport pull requests. The script fetches a pull request's merge commit, creates a new branch, attempts to cherry-pick the changes to a target branch, and opens a new pull request with an appropriate title and description, including a warning if conflicts occur.

misc/backport · high confidence

Automated deployment scripts for Debian/Ubuntu and RHEL/CentOS packages

Added new CI scripts (deploy-deb.sh and deploy-rpm.sh) that automate the process of uploading Debian and RPM packages to the official repositories. The Debian script handles generic, Ubuntu, and ESM releases for i386, amd64, and arm64 architectures. The RPM script manages repository updates for RHEL/CentOS versions 5 through 9, supporting both x86\_64 and aarch64 architectures.

ci · high confidence

Centralized Package URL (PURL) generation and mapping logic

The \pkg/purl\ package now provides a centralized, unified implementation for generating Package URLs (PURLs) and mapping them to internal language types. This change consolidates PURL creation logic that was previously scattered across various analyzers, ensuring consistent handling of package identifiers for diverse ecosystems including Maven, Gradle, NPM, PyPI, and others. The new \New\ function in \purl.go\ handles the transformation of package metadata into standardized PURLs, while \LangType\ maps PURL types back to Trivy's internal language types, improving maintainability and correctness in vulnerability scanning and SBOM generation.

pkg/purl · high confidence

Centralized download and initialization logic for vulnerability DB, VEX repositories, and built-in checks

The operation package now consolidates the logic for downloading the vulnerability database, updating VEX repositories, and initializing built-in policy checks into a single, thread-safe module. Users benefit from a unified, synchronized download process that prevents race conditions when updating the DB, VEX sources, and misconfiguration checks, ensuring consistent state across all components.

pkg/commands/operation · high confidence

Centralized result filtering and ignore configuration

The result package now provides a unified filtering mechanism for vulnerabilities, misconfigurations, secrets, and licenses. Users can apply severity, status, and ignore-file-based exclusions to all finding types through a single \Filter\ function. The new \ignore.go\ and \filter.go\ files introduce structured YAML-based ignore configurations (\.trivyignore.yaml\) that support path and PURL matching, expiration dates, and statement tracking. This replaces the previous scattered filtering logic with a consistent, policy-driven approach that also supports Rego-based filtering for licenses and secrets.

pkg/result · high confidence

Centralized type definitions for scanning targets and artifacts

The scanning types are consolidated into the pkg/fanal/types package, introducing structured types for artifacts, OS detection, and misconfigurations. This includes new constants for operating systems, language types, and configuration types, alongside structs for package relationships, license findings, and secret scanning results. The changes also introduce support for image sources, registry options, and dependency graph relationships, providing a unified foundation for all scanner components.

pkg/fanal/types · high confidence

Dart: Add support for analyzing pubspec.lock files

The Dart analyzer now processes \pubspec.lock\ files to extract package dependencies and their relationships. By reading the system cache directory (via \PUB\_CACHE\ or default paths), the analyzer resolves direct and indirect dependencies, allowing users to see the full dependency graph for Dart projects.

pkg/fanal/analyzer/language/dart · high confidence

Enable misconfiguration scanning for container image history

A new analyzer has been added to the image configuration scanning pipeline. It reconstructs a Dockerfile from the image's layer history and runs the standard Dockerfile misconfiguration scanner against it. This allows the tool to detect issues such as using ADD instead of COPY, improper HEALTHCHECK configurations, and other Dockerfile-style security and best-practice checks against existing container images, not just source Dockerfiles.

pkg/fanal/analyzer/imgconf/dockerfile · high confidence

Expanded CloudFormation intrinsic function support

The CloudFormation parser now resolves a broader set of intrinsic functions, including Fn::And, Fn::Base64, Fn::Cidr, Fn::Condition, Fn::Equals, Fn::FindInMap (with default values and list support), Fn::GetAtt, Fn::If, Fn::Join, Fn::Length, Fn::Not, Fn::Or, Fn::Ref, Fn::Select, Fn::Split, and Fn::Sub. This allows the scanner to correctly evaluate template properties that rely on these functions, such as dynamic resource references, conditional logic, and string manipulation, leading to more accurate security scanning of CloudFormation templates.

pkg/iac/scanners/cloudformation/parser · high confidence

Expanded IaC provider models for AWS and Azure

The IaC provider models have been expanded to include new resource types and attributes, enabling more comprehensive security checks. For AWS, new models were added for Access Analyzer, API Gateway (v1 and v2), Athena, CloudFront (including v2 logging), CloudTrail, CloudWatch, CodeBuild, Config, DocumentDB, DynamoDB, EC2 (including AMIs, instances, and VPCs), ECR, ECS, EFS, EKS, ElastiCache, Elasticsearch, ELB, EMR, IAM (including password policies), Kinesis, KMS, Lambda, MQ, MSK, Neptune, RDS (including classic and new instances), Redshift, S3 (including public access blocks and grants), SAM (APIs, functions, state machines), SNS, SQS, SSM, and WorkSpaces. For Azure, new models were added for App Service and Authorization. These additions allow the tool to parse and evaluate a broader range of infrastructure-as-code configurations for security and compliance.

pkg/iac/providers · high confidence

Expanded package and configuration analysis capabilities

The analyzer package now supports a broader range of package managers and configuration files, including Python pylock, SBT lockfiles, and various language-specific lockfiles (e.g., Bun, pnpm, uv, pylock.toml). It also introduces a new config analyzer interface for scanning container image configurations for secrets and misconfigurations, alongside a post-analyzer framework that allows for more flexible, file-pattern-based analysis of existing files. The changes also add support for non-packaged binaries, Swift CocoaPods, and improved license detection for Java and Debian packages.

pkg/fanal/analyzer · high confidence

Improved Go binary version detection via ELF symbol table fallback

The Go binary parser now extracts module versions from the ELF symbol table as a fallback when the standard build info is missing or incomplete. This addresses a known Go issue where the \-trimpath\ flag prevents \-ldflags\ from being recorded in the build info, making version detection unreliable. The new logic parses \.str\-suffixed symbols in the ELF symbol table to recover version information that would otherwise be lost, ensuring more accurate dependency reporting for stripped or trimmed Go binaries.

pkg/dependency/parser/golang/binary · high confidence

Initial project structure and build configuration

The repository was initialized with essential build and configuration files, including a GoReleaser setup for multi-platform releases, Dockerfiles for container images, and a MkDocs configuration for documentation. The project also includes a golangci-lint configuration to enforce code quality standards, a CHANGELOG for release notes, and standard repository files like .gitignore and .gitattributes.

(repo-wide) · high confidence

Initial release of the Trivy Helm chart templates

The Helm chart for Trivy is now fully templated, providing a complete set of Kubernetes manifests including a StatefulSet, Service, Ingress, ConfigMap, and RBAC resources. Users can now deploy Trivy in server mode with configurable service names, session affinity, and environment variables, while also supporting custom labels, pod annotations, and TLS/SSL certificate directories.

helm/trivy, helm/trivy/templates · high confidence

Initial support for scanning Ansible playbooks and inventories

Users can now scan Ansible projects for misconfigurations. The scanner supports parsing YAML and INI inventory files, resolving variable precedence (host\_vars, group\_vars, and external variables), and discovering project roots by detecting ansible.cfg, playbooks, and roles. This includes a new file system abstraction for consistent access to virtual and real filesystems, an ordered map for preserving YAML key order, and a parser for Ansible configuration files.

pkg/iac/scanners/ansible · high confidence

Introduce CloudFormation IaC scanner with inline ignore support

A new CloudFormation scanner has been added to the IaC scanning pipeline, enabling the detection of misconfigurations in AWS CloudFormation templates. The implementation parses YAML/JSON CloudFormation files, adapts them for the Rego-based scanning engine, and supports inline ignore comments (e.g., \\#trivy:ignore:RULE\_ID\) to suppress specific findings directly in the template.

pkg/iac/scanners/cloudformation · high confidence

Introduce OS release analyzer to detect Linux distributions

A new OS release analyzer has been added to the fanal package, enabling Trivy to identify the specific Linux distribution and version from standard release files (e.g., /etc/os-release). This change introduces a centralized mechanism to parse OS metadata, supporting a wide range of distributions including RHEL, CentOS, Ubuntu, SUSE, Alpine, and others. The analyzer registers itself to scan for these files and returns structured OS information, which is essential for accurate vulnerability scanning and package analysis across different Linux environments.

pkg/fanal/analyzer/os/release · high confidence

Introduce RPC client for remote scanning

Added a new RPC client implementation in pkg/rpc/client that enables Trivy to communicate with a remote scanning server. The client supports passing custom HTTP headers (such as authentication tokens) and a path prefix for the server, and it fetches the server version information in the background during scans. The implementation includes comprehensive unit tests for the client and header injection logic.

pkg/rpc/client · high confidence

Introduce SBOM file analysis for container images

The SBOM analyzer now processes Software Bill of Materials files (SPDX and CycloneDX formats) embedded in container images. This enables the detection of vulnerabilities and dependencies directly from these manifests. The implementation includes specific handling for Bitnami images, where component paths are correctly mapped to application file paths, and ensures that OS packages from multiple SBOM files are preserved without overwriting each other. Additionally, the analyzer excludes PEP 770 SBOMs located in \.dist-info/sboms/\ directories, as these are handled by the Python packaging analyzer.

pkg/fanal/analyzer/sbom · high confidence

Introduce Terraform context wrapper for variable management

Added a new \Context\ wrapper in \pkg/iac/terraform/context\ that provides a structured way to get, set, and merge HCL evaluation context variables. This includes support for dot-notation paths, child context inheritance, and deep merging of object values, which improves how the system handles Terraform variable scopes and nested attributes.

pkg/iac/terraform/context · high confidence

Introduce UUID generation with support for UUIDv7

The pkg/uuid package now provides a New() function for standard UUID generation and introduces a new NewV7() function that generates UUIDv7 identifiers, which are time-ordered and suitable for use cases requiring ordering and database performance. The package also includes helper functions SetFakeUUID and SetFakeUUIDV7 for testing purposes.

pkg/uuid · high confidence

Introduce VEX repository management

Added a new VEX repository manager that handles configuration, initialization, and downloading of VEX repositories. The manager reads repository configurations from a YAML file, validates that repository names are local relative paths to prevent path traversal vulnerabilities, and supports downloading repository metadata and indexes from remote URLs.

pkg/vex/repo · high confidence

Introduce a new module system for extensible analysis and scanning

A new module system is introduced in the \pkg/module\ package, enabling the loading and execution of WebAssembly (WASM) plugins. The \module\ package now provides a \Manager\ that scans a directory for \.wasm\ files, instantiates them, and registers their \Analyzer\ and \PostScanner\ implementations with the core scanning pipeline. This allows third-party or custom logic to extend Trivy's capabilities by implementing the \Analyzer\ or \PostScanner\ interfaces defined in \pkg/module/api/api.go\. The system supports enabling/disabling specific modules via configuration and provides a memory filesystem (\memFS\) to handle module state. Test fixtures (\testdata\) demonstrate the integration of analyzer and post-scanner modules.

pkg/module · high confidence

Introduce a unified image source abstraction for container images

The \pkg/fanal/image\ package has been restructured to support multiple image sources (Docker, Podman, containerd, remote registries, and local archives) through a new \NewContainerImage\ entry point. This change introduces a \ImageSource\ option that allows users to specify which runtime or source to use for image retrieval. The implementation adds support for loading images from local archives (Docker and OCI formats) and provides a consistent interface for \RepoTags\ and \RepoDigests\ across all sources. Users can now control image retrieval behavior by selecting specific sources, improving flexibility for different scanning environments.

pkg/fanal/image · high confidence

Introduce centralized HTTP client and transport configuration

The HTTP client and transport configuration has been centralized into the \pkg/x/http\ package. Users can now create HTTP clients with custom timeouts, context, and transport options. The transport layer supports TLS settings (insecure skip verify, custom CA certs), proxy configuration, and user-agent headers. Additionally, HTTP request and response tracing is now available, which logs headers and body content while automatically redacting sensitive information such as authorization headers, cookies, and private keys.

pkg/x/http · high confidence

Introduce clock package for time management

A new 'clock' package has been added to manage time-related operations. This package provides a 'With' function to inject a specific time into a context and a 'Now' function to retrieve the current time from that context, defaulting to the real system clock if no time is specified.

pkg/clock · high confidence

Introduce config file schema loading for misconfiguration scanning

The misconfiguration scanning subsystem now supports loading and validating configuration files against JSON schemas. A new \ConfigFileSchema\ type and \LoadConfigSchemas\ function parse \.json\ schema files, handling Go's regex limitations by replacing \\\Z\ with \$\ and removing unsupported negative lookaheads. The \Scanner\ struct now accepts a \ConfigFileSchemas\ option, allowing the scanner to validate configuration files during the scan process. Test coverage is added for schema loading and scanner initialization.

pkg/misconf · high confidence

Introduce data-source configuration for Ubuntu vulnerability scanning

Added new test fixtures (data-source.yaml, invalid.yaml, ubuntu.yaml) and the corresponding Go implementation (ubuntu.go) to support Ubuntu OS package detection. The changes introduce a data-source configuration mechanism that maps Ubuntu versions to their respective CVE trackers, enabling the scanner to retrieve and process vulnerability advisories for supported Ubuntu releases.

pkg/detector/ospkg/ubuntu · high confidence

Introduce digest package for computing file and data hashes

A new 'digest' package has been added to the codebase, providing a centralized way to compute and manage cryptographic hashes. It supports SHA-1, SHA-256, SHA-512, and MD5 algorithms, offering functions to calculate these hashes from byte slices or readers. This enables consistent hash generation for files and data across the application, such as for SBOMs, package verification, and vulnerability fingerprinting.

pkg/digest · high confidence

Introduce filesystem-based scanning interface for Azure ARM templates

A new \FSScanner\ interface and a dedicated \Scanner\ implementation for Azure ARM templates are added to the IaC scanning pipeline. This enables scanning Azure Resource Manager (ARM) templates directly from the filesystem, integrating with the existing Rego-based scanning engine to produce security results.

pkg/iac/scanners/azure/arm · high confidence

Introduce in-memory filesystem implementation

Added a new in-memory filesystem implementation in the \pkg/mapfs\ package. This provides an in-memory representation of a file system, supporting operations such as creating directories, writing files (both real and virtual), filtering file lists, and copying directories. The implementation includes test coverage for these core functionalities.

pkg/mapfs · high confidence

Introduce intermediate representation for SBOM processing

The SBOM core package now utilizes a new intermediate representation (BOM struct) to manage components, relationships, and vulnerabilities. This change introduces a unified internal model for SBOM data, which supports features such as preserving SBOM structure during scanning, adding image labels to reports, and supporting SHA-512 hash algorithms in SPDX serialization. The diff shows the definition of the \BOM\ struct and \Component\ struct, indicating a shift from previous data handling mechanisms to this new intermediate format.

pkg/sbom/core · medium confidence

Introduce k8s scanner implementation with Windows-safe temp file handling

The k8s scanner now generates temporary YAML files from Kubernetes artifacts to scan misconfigurations and vulnerabilities. The implementation includes a new \io.go\ module that creates temporary directories and files, with specific handling for Windows file systems by sanitizing filenames to remove characters that are invalid in Windows paths (e.g., \:\, \\*\, \?\, \\<\, \\>\, \\\\). The \scanner.go\ file implements the core scanning logic, supporting both misconfiguration and vulnerability scanning in parallel, and handles CycloneDX output generation. Tests in \io\_test.go\ and \scanner\_test.go\ verify the filename sanitization and scanning behavior.

pkg/k8s/scanner · high confidence

Introduce k8s subcommand for Kubernetes cluster scanning

Added new Go source files (cluster.go, run.go) that implement the core logic for scanning Kubernetes clusters. This includes the \Run\ entry point, cluster connection handling, and artifact listing for both standard scans and node-collector-based scans. The implementation supports CycloneDX, JSON, and Table formats, and integrates with the compliance reporting system to build and write compliance reports. It also enforces validation to prevent accidental terminal clutter by requiring explicit \--report all\ for table output.

pkg/k8s/commands · high confidence

Introduce language analyzer core for parsing lock files and package files

A new 'language' analyzer package has been added to the fanal analyzer, providing a unified interface (Parser) and helper functions (Analyze, Parse, AnalyzePackage) for processing language-specific dependency files. This change introduces a standardized way to parse lock files and package files, calculating file digests and mapping dependencies, which will be used by specific language analyzers (like npm, yarn, Java, etc.) to extract package and dependency information.

pkg/fanal/analyzer/language · high confidence

Introduce language package scanning for vulnerability detection

Added a new langpkg scanner that detects vulnerabilities in language-specific packages (Python, Conda, Ruby, Node.js, Java, and Kubernetes) by iterating through application targets, sorting packages, and invoking the library.Detect function to identify vulnerabilities. This new component integrates with the existing scanning pipeline, allowing users to receive vulnerability results for these specific package types.

pkg/scan/langpkg · high confidence

Introduce modular cache backend support

The cache package has been refactored to support multiple storage backends. The new \client.go\ acts as a factory that initializes either a local filesystem cache (using BoltDB), a Redis cache (with TLS support), or an in-memory cache, depending on the configuration. A \RemoteCache\ implementation was also added to handle caching via a remote server using the Twirp RPC protocol. Corresponding unit tests were added for each backend type.

pkg/cache · high confidence

Introduce new Debian OS package vulnerability scanner

Added a new scanner implementation for detecting vulnerabilities in Debian-based operating systems. The new \pkg/detector/ospkg/debian\ package provides the \Scanner\ and \IsSupportedVersion\ logic, including an End-of-Life (EOL) date map for all Debian releases from 1.1 to 13. The implementation integrates with the \trivy-db\ to fetch Debian security advisories, compare package versions against fixed versions, and return detected vulnerabilities with full metadata (including vendor IDs, severity, and data source). Unit tests and test fixtures are included to validate the scanning logic and EOL version support.

pkg/detector/ospkg/debian · high confidence

Introduce new IaC file-type detection system

The IaC scanning pipeline now uses a new detection package (pkg/iac/detection) to identify file types and content formats. This introduces support for scanning Terraform plan JSON and snapshots, OpenTofu files, YAML/JSON content, Helm charts, Azure ARM templates, CloudFormation, Dockerfiles, Kubernetes manifests, and Ansible playbooks. The system also adds a new severity classification (Critical, High, Medium, Low) and framework definitions (Default, Experimental, CIS AWS) to standardize how scanned resources are categorized and reported.

pkg/iac/detection · high confidence

Introduce new ignore rule parsing and matching logic

Added new files in pkg/iac/ignore (parse.go, rule.go, rule\_test.go) that implement a structured parser for ignore rules (e.g., \#trivy:ignore:rule-id) and a pattern-matching engine that supports wildcards and case-insensitive ID matching. This replaces or supplements the previous ad-hoc parsing, enabling features like expiry dates and wildcard-based rule matching.

pkg/iac/ignore · high confidence

Introduce new k8s report package with structured report types and writers

The \pkg/k8s/report\ package has been introduced to handle Kubernetes scan reporting. This includes new data structures for \Report\ and \ConsolidatedReport\, along with dedicated writers for JSON, CycloneDX, table, and summary formats. The implementation consolidates findings, separates workload, infrastructure, and RBAC assessments, and supports both detailed and summary output modes for Kubernetes resources.

pkg/k8s/report · high confidence

Introduce new policy client for managing check bundles

A new \policy\ package has been added to manage the download, caching, and versioning of policy bundles. The \Client\ struct handles fetching check bundles from OCI registries, tracking metadata such as the bundle's major version and digest, and determining if an update is needed. This includes test coverage for the client's logic.

pkg/policy · high confidence

Introduce parallel processing abstractions for pipeline and directory walking

Added a new \Pipeline\ type in \pkg/parallel\ that enables configurable parallel processing of items using a worker pool pattern, along with a \WalkDir\ function that performs parallel directory walking. The \Pipeline\ implementation leverages \errgroup\ and channels to manage concurrent execution, while \WalkDir\ handles concurrent file processing with support for progress tracking. Tests were added to verify the correct behavior of the pipeline, including error handling and result aggregation.

pkg/parallel · high confidence

Introduce plugin index and manager for plugin discovery and installation

Adds a plugin index and manager to the plugin subsystem, enabling users to discover, install, and manage plugins. The new index (fetched from a remote YAML file) allows the 'trivy plugin search' command to list available plugins and their metadata. The manager handles installing plugins from various sources (HTTP, Git, local paths, archives) and executing them, supporting platform-specific binaries and respecting the --insecure flag for downloads.

pkg/plugin · high confidence

Introduce post-analysis handler manager for extensible blob processing

A new handler manager has been added to the fanal package, providing a pluggable system for post-analysis processing of blob information. The implementation registers post-handlers that can modify analysis results, with support for disabling specific handlers and ordering them by priority. Tests confirm that the manager correctly invokes registered handlers and respects disabled handler configurations.

pkg/fanal/handler · high confidence

Introduce registry client interface

A new interface for registry clients has been added, defining methods to retrieve credentials and check registry options. This provides a standardized way to interact with different registry implementations, such as AWS ECR repositories in various regions.

pkg/fanal/image/registry/intf · medium confidence

Introduce serialization types for module analysis results

Added new types in the serialize package to define the structure for module analysis results. The \AnalysisResult\ struct now holds \CustomResources\ from the fanal types, with other fields like OS, Repository, and PackageInfos marked as TODOs for future support. Additionally, \PostScanSpec\ was introduced to specify post-scan actions (INSERT, UPDATE, DELETE) and associated IDs, enabling modules to perform specific actions after scanning.

pkg/module/serialize · high confidence

Introduce structured Rego schemas for IaC analysis

The \pkg/iac/rego/schemas\ package now provides structured JSON schemas for Dockerfile, Kubernetes, RBAC, Cloud, and Terraform-raw data. These schemas are embedded into the Go codebase and mapped to their respective sources, enabling the Rego engine to validate and analyze Infrastructure-as-Code configurations with a consistent, typed structure.

pkg/iac/rego/schemas · high confidence

Introduce structured flag groups and extension hooks

The flag system has been refactored to use a structured group-based architecture, introducing dedicated flag groups for global, image, Kubernetes, database, cache, clean, AWS, and license options. This change organizes CLI flags into logical categories, each with their own options struct and validation logic. Additionally, a new extension hook system has been added, allowing external code to register hooks that can modify scan targets, results, and reports at various stages of the scanning process.

pkg/flag · high confidence

Introduce unified artifact scanning interface

The artifact scanning logic has been refactored into a new \pkg/commands/artifact\ package, introducing a \Runner\ interface that unifies scanning for container images, filesystems, repositories, SBOMs, VMs, and K8s. This change consolidates the entry points for all scan types, supporting both standalone and client/server modes, and integrates WASM module loading and version checking into a single initialization flow.

pkg/commands/artifact · high confidence

Introduce unified state merging and typed value wrappers for IaC data

The IaC state model now supports merging multiple scan results into a single state, with later scans taking precedence over earlier ones. Additionally, the codebase introduces a generic \BaseValue\ wrapper and specific typed value types (e.g., \BoolValue\, \StringValue\, \IntValue\) that carry metadata about their origin and resolution status, enabling more robust handling of unresolvable or default values during scanning and Rego export.

pkg/iac/types · high confidence

Introduce version check and announcement system

Added a new notification subsystem that performs background version checks against the Trivy updates API and displays announcements or update notices to the user. The system generates a unique machine identifier for anonymous telemetry, respects the --skip-version-check and --disable-telemetry flags to control what is sent and displayed, and supports version-constrained announcements that are only shown when the user's current version falls within the specified date and version ranges.

pkg/notification · high confidence

Introduces a modular version-comparison and supplier-detection framework for library vulnerability scanning

The library vulnerability detection logic has been refactored into a modular architecture that separates version comparison from scanning logic. A new \compare\ package provides ecosystem-specific version comparers (for Bitnami, Maven, npm, PEP 440, and RubyGems) that handle complex version constraints. The \Driver\ now selects the appropriate comparer based on the package's ecosystem. Additionally, a \Supplier\ interface and registration system allow third-party security providers (such as Seal Security) to inject their own version comparers and advisory buckets, enabling Trivy to scan for vulnerabilities in patched packages from external suppliers.

pkg/detector/library · high confidence

Introduces caching for Terraform modules

The resolvers package now includes a new cache resolver that stores downloaded Terraform modules in a local directory (defaulting to .aqua/cache in the system temp directory). This allows subsequent scans to resolve modules from the local cache rather than re-downloading them, which should improve scan performance. The change adds cache.go and cache\_integration\_test.go to implement this caching logic, alongside supporting files (local.go, options.go, registry.go, remote.go, source.go, writable.go) that define the resolver interface and platform-specific writability checks.

pkg/iac/scanners/terraform/parser/resolvers · high confidence

Native discovery of VEX documents as OCI artifacts

The Trivy scanner now natively discovers and retrieves OpenVEX (Vulnerability Exploitability eXchange) documents attached to container images as OCI artifacts. This new capability allows the scanner to fetch VEX attestations from OCI 1.1 referrers and legacy \.att\ tags, enabling more accurate vulnerability reporting by leveraging standardized security metadata. The implementation includes safeguards against unbounded fetches and decompression bombs, and supports both standard and in-toto predicate types for VEX documents.

pkg/vex/oci · high confidence

New Azure Terraform adapters for infrastructure-as-code scanning

The system now adapts Terraform configurations for a broad set of Azure services, including App Service, Compute (VMs and managed disks), Container (Kubernetes clusters), Cosmos DB, Database (PostgreSQL, MariaDB, MySQL, MSSQL), and Authorization (role definitions and assignments). This enables the detection of misconfigurations and security issues in these specific Azure resources during infrastructure scans.

pkg/iac/adapters/terraform/azure · high confidence

New Azure deployment template and expression resolver

The Azure scanner now includes a new \Deployment\ struct and associated types in \pkg/iac/scanners/azure\ to represent Azure Resource Manager (ARM) template structures, along with a new \Resolver\ component in \pkg/iac/scanners/azure/resolver\ that evaluates expressions against the deployment context. This enables the scanner to resolve dynamic values and parameters within Azure configuration files, improving the accuracy of security checks that depend on template evaluation.

pkg/iac/scanners/azure · medium confidence

New Cargo analyzer for Rust projects

The Rust Cargo analyzer has been implemented to parse \Cargo.lock\ and \Cargo.toml\ files, identifying direct and indirect dependencies, workspace members, and root packages. It supports workspace member resolution (including glob patterns) and version inheritance from the workspace root. The analyzer filters out dev dependencies and correctly classifies packages as direct, indirect, root, or workspace members based on the project structure.

pkg/fanal/analyzer/language/rust/cargo · high confidence

New Helm chart scanner implementation

A new Helm scanner has been introduced to the IaC scanning pipeline. This change replaces the previous custom Helm archive parsing with the official Helm SDK loaders, enabling more robust chart processing. The scanner now supports passing values via files or strings, allows configuration of API and Kubernetes versions, and ensures that subcharts are scanned exactly once to prevent duplicate results. The implementation includes a new options layer for configuring the scanner and comprehensive test coverage for various chart structures.

pkg/iac/scanners/helm · high confidence

New Java JAR dependency parser

Added a new Java JAR dependency parser that extracts package information and license data from JAR files. The parser reads embedded pom.xml and pom.properties files, MANIFEST.MF attributes, and LICENSE files to identify Java artifacts. It also integrates with the Sonatype Maven Central API to resolve artifacts by SHA-1 digest or artifact ID, and includes test data and unit tests for Maven and Gradle projects.

pkg/dependency/parser/java/jar · high confidence

New Node.js package.json parser with enhanced workspace and license handling

A new parser for \package.json\ files has been introduced, enabling the extraction of dependencies, optional dependencies, and dev dependencies. The parser now supports parsing the \workspaces\ field in both array and object (map) formats, allowing for better handling of monorepo structures. Additionally, it handles legacy license formats, including string, object, and array-of-objects representations, ensuring robust license detection. Input validation is also added to reject invalid package names.

pkg/dependency/parser/nodejs/packagejson · high confidence

New RPC service definitions for cache and scanner

The RPC layer introduces new Protobuf service definitions for the cache and scanner components. The cache service now supports storing and retrieving artifact and blob information, including package, secret, and license data. The scanner service defines the interface for initiating scans, with options to filter package types, include development dependencies, and specify vulnerability severity sources. These changes update the client-server communication protocol to support the new scanning and caching capabilities.

rpc · high confidence

New Terraform adapters for AWS resources

Added new Terraform adapters for AWS resources, including API Gateway (v1 and v2), Athena, CloudFront, CloudTrail, and CloudWatch. These adapters parse Terraform configuration files to extract security-relevant attributes such as encryption settings, logging configurations, and access controls, enabling the security scanner to evaluate these resources for compliance and best practices.

pkg/iac/adapters/terraform/aws · high confidence

New code rendering and flat result structures for scan results

The scan package introduces new types and methods to improve how scan results are presented and serialized. A new \Code\ struct and \GetCode\ method on \Result\ allow retrieving highlighted source code lines for a finding, supporting both dark and light themes, truncation, and cause marking. Additionally, a \FlatResult\ struct and \Flatten\ method provide a simplified, flat representation of scan results, including fields for rule metadata, severity, and rendered causes. These changes enhance the user experience by providing better context for findings and a cleaner data structure for output.

pkg/iac/scan · high confidence

New config analyzers for multiple infrastructure and configuration file types

The \pkg/fanal/analyzer/config\ package has been refactored to introduce dedicated post-analyzers for detecting misconfigurations in various configuration and infrastructure-as-code files. This includes support for Ansible, Azure ARM templates, AWS CloudFormation, Dockerfiles, Helm charts, JSON, Kubernetes manifests, Terraform, Terraform Plan (JSON and snapshot formats), and YAML/JSON files. Each analyzer registers itself via \analyzer.RegisterPostAnalyzer\ and implements the \Required\ method to filter relevant files, enabling the system to scan these file types for security and compliance issues.

pkg/fanal/analyzer/config · high confidence

New example policies for ignoring vulnerabilities and checks

Added three new Rego policy examples in the \examples/ignore-policies\ directory to demonstrate how to configure ignore rules. \basic.rego\ provides a template for ignoring specific packages, severities, attack vectors, and specific CWE/AVD IDs. \advanced.rego\ offers more complex logic for ignoring vulnerabilities based on CVSS vectors and package names. \whitelist.rego\ demonstrates how to allow specific check IDs. These files serve as reference implementations for users to customize their scanning results.

examples/ignore-policies · high confidence

New internal conversion utilities for transforming Go types to Rego-compatible structures

Added new files (anonymous.go, converter.go, slice.go, struct.go) and their corresponding tests in the iac/rego/convert package. These introduce a Converter interface and helper functions (StructToRego, SliceToRego, anonymousToRego) that recursively convert Go structs and slices into maps and arrays suitable for Rego policy evaluation. The conversion logic specifically handles metadata extraction, ensuring that metadata fields are mapped to a dedicated '\_\_defsec\_metadata' key in the output.

pkg/iac/rego/convert · high confidence

New k8s package for scanning and reporting Kubernetes cluster components

The pkg/k8s package introduces a new scanner for Kubernetes core components, implementing the scanning logic in k8s.go and handling output formatting (JSON, table, CycloneDX) in writer.go. This enables the tool to scan and report on misconfigurations, vulnerabilities, and secrets within the Kubernetes control plane and cluster resources.

pkg/k8s · high confidence

New npm post-analyzer for package-lock.json and node\_modules license detection

A new post-analyzer for the npm ecosystem has been introduced to parse \package-lock.json\ files and extract dependency information, including line numbers and external references. The analyzer also traverses \package.json\ files within \node\_modules\ directories to collect license data, ensuring that license information is populated even if it is missing from the lock file. This change improves the accuracy of license detection for npm-based projects.

pkg/fanal/analyzer/language/nodejs/npm · high confidence

New registry test utilities for OCI 1.1 referrers and legacy attestations

Added the internal/registrytest package, providing helper functions for testing OCI registries. This includes NewServer and NewServerWithAuth to spin up test servers with OCI 1.1 referrers support, as well as PushImage, PushRandomImage, PushReferrer, and PushLegacyAttestation to facilitate pushing test artifacts and attestations to the registry.

internal/registrytest · high confidence

New rule registry and provider hierarchy APIs

A new rule registry system has been introduced in the \pkg/iac/rules\ package, providing a centralized way to register, deregister, and query security checks by framework. The \register.go\ file implements a thread-safe registry that maps rules to their associated frameworks, allowing queries for all registered rules or those specific to a given framework. Additionally, \providers.go\ adds new APIs to retrieve a hierarchical view of providers, services, and checks, exposing structured data about the available security rules. These changes enable more flexible rule management and introspection for users and internal components.

pkg/iac/rules · medium confidence

New table-format renderers for licenses, misconfigurations, and secrets

The table report format now includes dedicated renderers for license, misconfiguration, and secret findings. Users will see structured tables for license scanning results, detailed misconfiguration reports with code snippets and cause metadata, and secret detection results including byte offsets and layer information. A new summary table aggregates counts across all enabled scanners (vulnerabilities, misconfigs, secrets, and licenses) for each target. These changes enhance the visibility of non-vulnerability findings in the default table output.

pkg/report/table · high confidence

Node.js license analysis now reads license text from files

The Node.js license analyzer now extracts license information from \package.json\ and, when necessary, reads the referenced license text from the corresponding files (e.g., \LICENSE\, \LICENSE.txt\, or files specified via \LicenseRef-\ or \SEE LICENSE IN\ fields). This enables the tool to classify licenses based on the actual license text found in the project's \node\_modules\ directory, rather than relying solely on the license identifiers listed in \package.json\.

pkg/fanal/analyzer/language/nodejs/license · high confidence

Poetry analyzer now identifies direct, indirect, and dev dependencies

The Python Poetry analyzer has been updated to parse both \poetry.lock\ and \pyproject.toml\ files. This allows the tool to distinguish between direct, indirect, and dev dependencies, providing a more accurate dependency tree for Python projects managed by Poetry.

pkg/fanal/analyzer/language/python/poetry · high confidence

Python packaging analyzer now extracts license information from .egg and .dist-info files

The Python packaging analyzer has been refactored to improve license detection. It now explicitly supports \.egg\ archive files by extracting and parsing \PKG-INFO\ metadata, and processes \.dist-info\ directories (including \METADATA\ and license files) to identify package licenses. This change ensures that license information is correctly identified for both legacy \.egg\ packages and modern \.dist-info\ distributions.

pkg/fanal/analyzer/language/python/packaging · high confidence

Python pip analyzer now detects package licenses

The pip analyzer in the fanal package has been updated to extract license information for Python packages. By reading the METADATA files from site-packages directories, the analyzer now populates the Licenses field for each package found in requirements.txt files, providing users with license visibility for their Python dependencies.

pkg/fanal/analyzer/language/python/pip · high confidence

Red Hat vulnerability scanner implementation

The Red Hat package scanner has been implemented to detect vulnerabilities in RHEL and CentOS systems. The scanner processes package information and cross-references it with Red Hat OVAL data to identify affected packages. It supports modular packages, architecture-specific vulnerability detection, and handles both patched and unpatched vulnerabilities. The implementation includes support for RHEL versions 6 through 10, with appropriate content sets and end-of-life date tracking for each OS version.

pkg/detector/ospkg/redhat · high confidence

Refactored Rego scanner architecture for IaC scanning

The Rego scanner implementation in pkg/iac/rego has been refactored into a modular, testable structure. The new codebase introduces dedicated files for building schema sets, loading and registering embedded policies and libraries, filtering modules by version and framework, and parsing scan results. This change supports configurable Rego error limits, minimum Trivy version requirements, and the ability to disable checks by ID or mark them as deprecated.

pkg/iac/rego · high confidence

SUSE Linux vulnerability scanning support

Added a new SUSE Linux vulnerability scanner that detects vulnerabilities for SUSE Linux Enterprise (SLES), SUSE Linux Enterprise Micro, openSUSE, and openSUSE Tumbleweed. The implementation includes version support checks using end-of-life (EOL) dates for each distribution and integrates with the SUSE CVRF data source to identify affected packages.

pkg/detector/ospkg/suse · high confidence

Secret scanning engine refactored to support streaming and configurable rules

The secret scanning engine has been refactored to use a streaming scanner with byte offset tracking, improving memory usage and performance. This change introduces a new \scanner.go\ implementation that supports configurable built-in and custom rules, allow-rules for path/regex-based filtering, and exclude-blocks for ignoring specific content patterns. The refactoring also adds support for multi-line secrets, UTF-8 validation, and various provider-specific detection rules (e.g., Azure, OpenAI, Hugging Face).

pkg/fanal/secret · high confidence

Support for JSONC (JSON with Comments) and location tracking

The \pkg/x/json\ package now supports parsing JSONC files, which allow single-line (//) and multi-line (/\* \*/) comments as well as trailing commas. The \UnmarshalJSONC\ function automatically strips comments and trailing commas to produce valid JSON before parsing. Additionally, the \Unmarshal\ and \UnmarshalRead\ functions now track source code locations (start and end line numbers) for decoded objects, enabling precise error reporting and location-based analysis.

pkg/x/json · high confidence

Support for Python pylock.toml dependency files

Added a new parser for the PEP 751 pylock.toml format, enabling the tool to analyze Python projects that use this lockfile format alongside existing dependency managers. The implementation includes the parsing logic and corresponding unit tests.

pkg/dependency/parser/python/pylock · high confidence

Support for analyzing non-packaged binaries

The system now includes a handler for 'unpacked' or non-packaged binaries, allowing the tool to analyze these files during the scan process. This is achieved by registering the new 'unpacked' handler alongside the existing 'sysfile' handler, enabling the detection and analysis of binaries that are not part of a package manager.

pkg/fanal/handler/all · high confidence

Support for parsing Sigstore bundle attestations

Users can now parse Sigstore bundle attestations, which use a DSSE envelope format. The new \Statement\ type in \pkg/attestation\ handles the decoding of these envelopes and unwraps the underlying in-toto statement, enabling the tool to process this specific attestation format.

pkg/attestation · high confidence

Support for pnpm lockfile v9 and multi-document lockfiles

The pnpm dependency parser has been updated to support pnpm lockfile version 9, which introduces a new 'snapshots' format and handles multi-document YAML files (separating the project lockfile from the environment config). This change enables Trivy to correctly parse modern pnpm lockfiles, including those with cyclic imports, multiple workspaces with overlapping packages, and various edge cases like archives and peer dependencies.

pkg/dependency/parser/nodejs/pnpm · high confidence

Support for remote SBOM discovery via OCI referrers and Sigstore bundles

The image artifact inspection now attempts to retrieve an existing Software Bill of Materials (SBOM) from external sources before performing a full image scan. It supports fetching SBOMs from OCI artifact referrers and Sigstore bundles (Rekor attestations). If a remote SBOM is found, the tool uses that data directly, potentially skipping the time-consuming local analysis. This feature allows users to leverage pre-generated SBOMs for faster scanning and verification of container images.

pkg/fanal/artifact/image · high confidence

Support for scanning Git repositories

Users can now scan Git repositories directly by providing a remote or local Git repository URL or path. The system automatically clones the repository to a temporary directory, supporting authentication via GITHUB\_TOKEN or GITLAB\_TOKEN environment variables, and allows specifying a branch, tag, or commit hash to scan. The implementation in pkg/fanal/artifact/repo/git.go handles both local and remote repositories, with corresponding tests in git\_test.go.

pkg/fanal/artifact/repo · high confidence

Support for scanning SBOM attestations and Sigstore bundles

The SBOM scanner now detects and processes SBOM attestation files (CycloneDX and SPDX) as well as Sigstore bundles containing SBOM data. This enables the tool to analyze SBOMs embedded within attestation records and Sigstore bundle formats, expanding the range of SBOM sources that can be scanned for vulnerabilities.

pkg/sbom · high confidence

Support for scanning container images via containerd, Docker, and Podman daemons

Users can now scan container images directly from the local containerd, Docker, or Podman daemons. This change introduces new implementations for each daemon: containerd support allows scanning images by digest and respects the \CONTAINERD\_NAMESPACE\ environment variable; Docker support resolves the daemon host using the \--docker-host\ flag or \DOCKER\_HOST\/\DOCKER\_CONTEXT\ environment variables; and Podman support connects to the Podman socket to inspect images. Each implementation provides the necessary metadata (config, history, layers) for scanning, with appropriate cleanup of temporary files.

pkg/fanal/image/daemon · high confidence

Support scanning SBOM files as artifacts

Users can now scan Software Bill of Materials (SBOM) files directly as artifacts. The system detects the SBOM format (e.g., CycloneDX, SPDX) and parses the file to extract package information, application details, and metadata, storing the result in the cache for further analysis.

pkg/fanal/artifact/sbom · high confidence

Support vulnerability scanning for unpackaged binaries via SBOM attestations

A new post-handler has been added to process unpackaged executable files by retrieving Software Bill of Materials (SBOM) attestations from the Rekor transparency log. This allows the scanner to identify applications and their dependencies for unpackaged binaries that are not part of a package manager, enabling vulnerability scanning on these files.

pkg/fanal/handler/unpackaged · high confidence

Synced Terraform parser functions with upstream Terraform

The \pkg/iac/scanners/terraform/parser/funcs\ package has been synchronized with the upstream Terraform \internal/lang/funcs\ module. This change introduces a comprehensive set of new and updated functions for Terraform template parsing, including \cidr\, \collection\, \conversion\, \crypto\, \datetime\, \encoding\, \filesystem\, \ip\, \marks\, \number\, \redact\, \refinements\, \sensitive\, and \string\ operations. These functions provide capabilities such as CIDR network calculations, cryptographic hashing, base64 encoding, and sensitive value handling, ensuring the IAC scanner's Terraform parser remains compatible with the latest Terraform language features.

pkg/iac/scanners/terraform/parser/funcs · high confidence

Versioned documentation URL generation

Added a new \pkg/version/doc\ package that generates version-specific documentation URLs. The \BaseURL\ and \URL\ functions construct links to \trivy.dev/docs/\ paths, mapping version strings (e.g., \0.52.0\) to versioned paths (e.g., \v0.52\) while defaulting to a \dev\ path for pre-release or invalid versions. This change introduces the logic for generating these URLs, supported by comprehensive unit tests.

pkg/version/doc · high confidence

Vulnerability severity selection and primary URL generation

The vulnerability package now implements a structured approach to selecting vulnerability severity from multiple data sources (e.g., NVD, Red Hat, GHSA) and generates primary URLs for different vulnerability ID formats (CVE, RUSTEC, GHSA). The \Client\ in \pkg/vulnerability/vulnerability.go\ provides a \FillInfo\ method that resolves severity by checking configured sources, falling back to NVD or other vendors, and warns if non-vendor severities are used. It also populates the \PrimaryURL\ field based on the vulnerability ID prefix and source-specific reference lists. Test fixtures in \testdata/fixtures/vulnerability.yaml\ and \sad.yaml\ provide sample vulnerability data for testing this logic.

pkg/vulnerability · high confidence

Yarn analyzer now parses package.json alongside yarn.lock to identify direct dependencies and dev dependencies

The Yarn analyzer now reads the package.json file located next to the yarn.lock file. This allows the analyzer to distinguish between direct and transitive dependencies, and to mark packages as dev dependencies. Additionally, license information is now extracted and attached to the analyzed packages.

pkg/fanal/analyzer/language/nodejs/yarn · high confidence

Architecture

Refactor report writers into a unified, testable interface

The report output logic has been refactored to use a common \Writer\ interface, with each format (JSON, SARIF, Template, etc.) implemented as a distinct writer struct (e.g., \JSONWriter\, \SarifWriter\, \TemplateWriter\). This change introduces a centralized \Write\ function in \writer.go\ that routes to the appropriate writer based on the requested format, and exposes internal helper functions (like \clearURI\ and \toProperties\) for testing via \export\_test.go\.

pkg/report · high confidence

Refactored Trivy RPC server implementation

The Trivy RPC server implementation in pkg/rpc/server has been refactored to improve code organization and maintainability. The server logic, including the HTTP handler setup, request processing, and background DB update worker, has been consolidated into new files (listen.go, server.go) with corresponding unit tests. This change restructures the server's internal architecture while preserving the existing client/server mode functionality.

pkg/rpc/server · high confidence

Behavioural changes

Add JSON serialization support for image references

The image reference type in the fanal package now supports JSON marshaling and unmarshaling, allowing image references to be directly included in report metadata as JSON fields. This enables the image reference to be serialized into the report's metadata section.

pkg/fanal/image/name · high confidence

Add license metadata to NuGet package test data

The test data for the .NET NuGet analyzer now includes license information for the Newtonsoft.Json and NuGet.Frameworks packages. Specifically, the .nuspec files for Newtonsoft.Json (versions 6.0.4 and 12.0.3) and NuGet.Frameworks (5.7.0) have been updated to include license details, enabling the analyzer to extract license metadata from these packages during analysis.

pkg/fanal/analyzer/language/dotnet/nuget/testdata/repository/.nuget/packages/newtonsoft.json, pkg/fanal/analyzer/language/dotnet/nuget/testdata/repository/.nuget/packages/nuget.frameworks · medium confidence

Add version endpoint and refine version info for server mode

The versioning logic in \pkg/version\ has been refactored to support a new \/version\ endpoint that exposes application, vulnerability database, Java database, and check bundle metadata. For server-mode deployments, the version info explicitly excludes JavaDB and CheckBundle data, as these are managed on the client side. This change introduces the \NewVersionInfo\ function and associated tests to handle these distinctions.

pkg/version · high confidence

Adopt trivy-java-db for Java vulnerability database management

The Java database client has been refactored to use the external trivy-java-db library, replacing the previous internal implementation. This change introduces a new client interface with methods to check for artifact existence and search by SHA1 or ArtifactID, while also supporting configurable repositories and registry options for downloading the Java DB.

pkg/javadb · medium confidence

Azure ACR authentication now supports China Cloud and Workload Identity

The Azure container registry client was refactored to use the stable azcontainerregistry SDK, enabling authentication via Workload Identity (using AZURE\_TENant\_ID) and adding support for Azure China Cloud endpoints (.azurecr.cn) with the correct scope and cloud configuration.

pkg/fanal/image/registry/azure · high confidence

Centralized artifact configuration and metadata structures

The artifact package now defines a unified Option struct that consolidates scanning configuration (analyzers, file patterns, parallelism, security and license scanner options) and a Reference struct that bundles image and repository metadata (including branch, commit, and tag information). This centralizes how artifact scanning is configured and how results are represented, making it easier to pass settings and access metadata across the scanning pipeline.

pkg/fanal/artifact · medium confidence

Centralized registry credential resolution

The registry package now uses a centralized token resolution mechanism that iterates through registered cloud provider clients (Google, AWS ECR, Azure) to find valid credentials. This change consolidates how authentication is retrieved for different registries, allowing the system to automatically select the correct credential source based on the domain and provided options, rather than relying on separate, isolated lookup logic for each provider.

pkg/fanal/image/registry · high confidence

Complete rewrite of the Java POM parser

The Java POM parser has been completely rewritten to improve correctness and maintainability. The new implementation adds support for fetching packages from remote repositories, resolving user-defined Maven mirrors from both settings.xml and the Trivy config file, and correctly inheriting properties, versions, and scopes from parent POMs and dependencyManagement sections. It also supports proxy configuration from Maven settings.xml, handles environment variable placeholders in settings, and includes comprehensive tests for mirror matching and settings resolution.

pkg/dependency/parser/java/pom · high confidence

Complete rewrite of the Terraform parser with improved module resolution and security hardening

The Terraform parser in the IAC scanner has been completely rewritten, introducing a new modular architecture with separate files for evaluation, function definitions, and module loading. This rewrite adds support for OpenTofu file extensions (.tofu), enforces sandboxed file system access to prevent path traversal vulnerabilities in Terraform's file functions, and improves handling of cached modules and dynamic blocks. The changes also include comprehensive unit tests for the new parser components.

pkg/iac/scanners/terraform/parser · high confidence

Dockerfile parser refactored to handle unknown flags and heredocs

The Dockerfile parser has been refactored to gracefully handle unsupported or unknown flags by filtering them out rather than failing, and to correctly process heredoc syntax in instructions. This improves robustness when scanning Dockerfiles that use non-standard or future flags, and ensures heredoc content is parsed accurately for security analysis.

pkg/iac/scanners/dockerfile/parser · high confidence

ECR authentication now supports custom TLS settings and regional endpoints

The ECR registry client has been refactored to use the AWS SDK for Go v2, enabling support for custom TLS configurations (insecure skip verify, custom CA certificates) and handling of various AWS ECR endpoint formats, including FIPS, China, and GovCloud regions. This change improves connectivity to ECR registries with non-standard TLS requirements and ensures correct region detection across all supported AWS partition domains.

pkg/fanal/image/registry/ecr · high confidence

Enforce new linting rules for code style and error handling

The project introduces a new Go linting configuration (rules.go) that enforces several code style and safety improvements. Developers are now guided to initialize empty slices and maps using the more efficient zero-value declarations. The linter also flags the use of standard library errors.Join in favor of hashicorp/go-multierror for better error output. Additionally, the linter encourages using a process-safe temporary file API (x/os) instead of the standard os package to ensure safe cleanup, excluding test files.

misc/lint · high confidence

Extract AWS configuration logic into a dedicated module

The AWS configuration logic has been moved into a new, dedicated package at pkg/config/aws. This change isolates AWS-specific setup—such as region and endpoint resolution—into its own module, making the configuration structure more modular and easier to maintain.

pkg/config · low confidence

Filter out OS package manager files to prevent false positive vulnerability reports

A new post-processing step has been introduced to filter out files installed by the OS package manager (such as yum or dpkg) from the analysis results. This change ensures that packages installed via the OS package manager are not included in the final report, which prevents false positive vulnerability findings that could arise from incorrect version information for these system-level packages.

pkg/fanal/handler/sysfile · high confidence

Go module analyzer refactored to support dependency graph and direct-only tree

The Go module analyzer has been refactored as a post-analyzer, enabling the construction of a dependency graph and the display of only direct dependencies in the tree. The analyzer now scans for licenses in both the GOPATH and vendor directories, and correctly handles the \toolchain\ directive as the \stdlib\ version for \go.mod\ files. Additionally, the \v\ prefix is preserved from versions in the Go Mod Analyzer, and the \--file-patterns\ flag is now used for all post-analyzers.

pkg/fanal/analyzer/language/golang/mod · high confidence

Helm chart parsing refactored to use the Helm SDK

The Helm parser has been refactored to use the Helm SDK for loading and rendering charts, replacing the previous custom archive parsing. This change introduces new configuration options for setting values, file values, string values, API versions, and Kubernetes versions. The parser now supports multiple archived dependencies and handles symlinks inside Helm archives. Test coverage has been added for various chart scenarios, including charts with integer names, packaged dependencies, and templated names.

pkg/iac/scanners/helm/parser · high confidence

Improved caching for local filesystem scans

When scanning a local directory that is a clean Git repository, Trivy now extracts Git metadata (commit hash, branch, tags, and remote URL) and uses the commit hash as the cache key. This allows Trivy to reuse cached analysis results for clean repositories, improving scan performance. The change also includes test data and test cases to verify this caching behavior.

pkg/fanal/artifact/local · high confidence

Improved npm lockfile parsing for modern and legacy formats

The npm dependency parser now correctly handles modern package-lock.json formats (v2 and v3), including support for peer dependencies, workspaces (both array and object formats), and legacy license structures. It also fixes a panic when parsing package names from paths and handles broken symlinks gracefully. Additionally, the parser now merges indirect, dev, and external reference fields for the same dependencies, ensuring more accurate dependency tree construction.

pkg/dependency/parser/nodejs/npm · high confidence

Introduce generic scanner for Dockerfile

The Dockerfile scanner has been refactored to use the new generic scanner framework, enabling support for inline ignore comments and simplifying the scanning logic. This change aligns the Dockerfile scanner with the generic scanner architecture, allowing for more consistent handling of scan options and results.

pkg/iac/scanners/dockerfile · high confidence

Introduce new Alpine Linux vulnerability scanner implementation

The Alpine Linux OS package detector has been refactored into a new \alpine\ package, replacing the previous implementation. This change introduces a dedicated \Scanner\ struct that handles vulnerability detection for Alpine-based systems, including support for mixed repository versions, unfixed vulnerabilities, and source package name resolution. The new implementation includes comprehensive unit tests and test fixtures to validate vulnerability detection logic across various package versions and repository configurations.

pkg/detector/ospkg/alpine · high confidence

Introduce new DB client implementation in pkg/db

The \pkg/db\ package now features a new \Client\ struct and \NewClient\ factory method, replacing the previous implementation. This change introduces a functional options pattern for configuring the database client, including support for specifying OCI artifacts and multiple database repositories. The \NeedsUpdate\ method has been refactored to handle first-run scenarios, schema version validation, and skip flags more robustly, ensuring that users are not allowed to skip the initial database download. Additionally, the codebase now includes test data and comprehensive unit tests for the new client behavior.

pkg/db · high confidence

Introduce new SBOM decoding and encoding logic

The SBOM parsing and serialization logic has been refactored into new \decode.go\ and \encode.go\ files within the \pkg/sbom/io\ package. The new decoder handles the conversion of internal BOM structures into the \types.SBOM\ format, including support for image labels, OS packages, and language-specific packages. The encoder converts reports back into the internal BOM structure, supporting options for BOM-Ref generation and parent tracking. This change replaces the previous ad-hoc parsing and serialization code with a more structured approach.

pkg/sbom/io · medium confidence

Introduce new license classification and scanning logic

The \pkg/licensing\ package has been refactored to use a new \classifier\ for detecting licenses from file content, a \scanner\ for categorizing licenses into severity levels, and a \normalize\ module for standardizing license names. This change adds support for classifying licenses based on content, normalizing license identifiers to their canonical SPDX forms, and scanning license expressions to determine their category (e.g., forbidden, restricted, permissive).

pkg/licensing · high confidence

Local scan service refactored into a new Service struct

The local scanning logic has been restructured into a new \Service\ struct in \pkg/scan/local/service.go\. This change introduces a dedicated service layer that coordinates OS package scanning, language package scanning, vulnerability detection, and license checking. The refactoring includes adding pre- and post-scan hooks, implementing a \Scan\ method that applies image layers and merges results, and updating the test suite with new fixtures to validate the refactored service behavior.

pkg/scan/local · high confidence

Migrate CLI framework from urfave/cli to spf13/cobra

The Trivy CLI has been refactored to use the spf13/cobra framework instead of the previous urfave/cli library. This change restructures the command-line interface, introducing a new app entry point (app.go) and a centralized run loop (run.go) that handles graceful shutdowns and error reporting. Users will see a reorganized command structure with grouped subcommands (scanning, management, utility, and plugin commands) and updated help text, but the core scanning and reporting capabilities remain consistent.

pkg/commands · high confidence

New license expression parser and normalization logic

The \pkg/licensing/expression\ package has been refactored to use a \goyacc\-generated parser for license expressions. This introduces a new parsing and normalization pipeline that handles license identifiers, compound expressions (AND, OR, WITH), and exceptions. The change includes a new \category.go\ file defining canonical license names, \expression.go\ for normalization logic (including SPDX-specific formatting), and supporting files (\lexer.go\, \parser.go.y\, \types.go\, and associated tests). This replaces the previous manual parsing approach, improving the handling of complex license expressions and exception handling in SBOM reports.

pkg/licensing/expression · medium confidence

Node.js package.json analyzer refactored into a dedicated package module

The Node.js package.json analyzer has been refactored into a new, dedicated \pkg\ module (\pkg/fanal/analyzer/language/nodejs/pkg\). This change introduces a \nodePkgLibraryAnalyzer\ that parses \package.json\ files and extracts package metadata, while also implementing logic to distinguish top-level package roots from subpath-helper files (such as \rxjs/ajax/package.json\) to prevent false positives. The implementation includes a new \IsPackageRoot\ function that correctly identifies valid package directories across various node\_modules structures, including nested dependencies and pnpm virtual stores, and is accompanied by comprehensive unit tests.

pkg/fanal/analyzer/language/nodejs/pkg · high confidence

OS package scanning now supports custom detector options

The OS package scanner has been refactored to accept and forward configuration options to the underlying vulnerability detector. This change allows external components to inject custom drivers or modify detection behavior through the scanner's constructor, enabling more flexible and testable scanning workflows.

pkg/scan/ospkg · medium confidence

RPC client retries unavailable errors and converts package data to RPC format

The RPC client now automatically retries HTTP requests that fail with an 'unavailable' error, improving reliability during transient network issues. Additionally, the RPC package now includes comprehensive conversion logic for package data, including license categories, package identifiers, locations, layers, and custom resources, ensuring that all relevant package details are correctly mapped to the RPC protocol.

pkg/rpc · medium confidence

Refactor core data types into dedicated files

The core data types for the Trivy scan results have been reorganized into separate, dedicated files (e.g., \finding.go\, \report.go\, \vulnerability.go\). This refactoring introduces a unified \Finding\ interface and a \ModifiedFinding\ structure to handle security findings such as vulnerabilities, misconfigurations, and secrets, while also adding support for VEX status tracking and enhanced report metadata.

pkg/types · high confidence

Refactor image layer application and merging logic

The image layer application and merging logic in the fanal applier has been refactored. The \ApplyLayers\ function and its associated test suite have been restructured to improve determinism and correctness when merging container image layers. This includes updates to how packages, applications, and other metadata are combined from multiple layers, ensuring that the final merged state accurately reflects the cumulative changes across all layers.

pkg/fanal/applier · high confidence

Refactor main entry point to support plugins and graceful shutdown

The main entry point for the Trivy CLI has been refactored to support running as a plugin and to handle graceful shutdowns via signal handling. The code now checks for the TRIVY\_RUN\_AS\_PLUGIN environment variable to determine whether to execute plugin logic or standard commands, and ensures cleanup and signal handling are properly managed.

cmd · high confidence

Refactor secret scanning to support binary files and configurable skip patterns

The secret analyzer now processes binary files (such as .pyc) by extracting printable bytes before scanning, and respects a new \skip-patterns\ configuration option that allows users to exclude specific files and directories from scanning. Additionally, the analyzer now correctly skips the secret-scanner configuration file itself to prevent false positives or redundant scans.

pkg/fanal/analyzer/secret · high confidence

Refactored CycloneDX SBOM serialization and deserialization

The CycloneDX SBOM handling has been refactored to use an intermediate representation (core.BOM) for both marshaling and unmarshaling. The new \Marshaler\ in \marshal.go\ converts Trivy reports and components into the CycloneDX format, while \unmarshal.go\ parses incoming CycloneDX files into the internal BOM structure. This change improves the handling of third-party SBOMs, preserves the original BOM structure when scanning SBOM files with vulnerability updates, and ensures consistent serialization of components, dependencies, and vulnerabilities.

pkg/sbom/cyclonedx · high confidence

Refactored Kubernetes manifest parsing with unified JSON/YAML support

The Kubernetes scanner's parser has been refactored to use a new \Manifest\ and \ManifestNode\ structure that supports both JSON and YAML inputs. The \parser.Parse\ function now detects the format and routes to \ManifestFromJSON\ or \ManifestFromYAML\ accordingly. The \ManifestNode\ type handles YAML tags (like \!!timestamp\, \!!binary\, \!!float\) and converts them into a \ToRego()\ representation that includes metadata such as file path, line numbers, and offsets. This change ensures that null values in YAML/JSON are handled correctly, and the parser now supports multi-document YAML files with proper offset tracking for each manifest.

pkg/iac/scanners/kubernetes/parser · high confidence

Refactored OS package vulnerability detection with a driver-based architecture

The OS package vulnerability detection logic has been refactored to use a pluggable driver architecture. A new \driver\ package defines the \Driver\ interface and a \Supplier\ mechanism for dynamic detection, while the central \detect.go\ file now resolves and delegates to the appropriate OS-specific scanner. This change introduces a default filtering mechanism that drops packages from third-party repositories (like EPEL or Docker) to prevent false positives, a behavior that can be overridden by individual drivers. The \gpg-pubkey\ package is explicitly skipped during scanning. Tests have been added to verify the new detection and filtering behavior.

pkg/detector/ospkg · high confidence

Refactored downloader to support ETag-based conditional requests and per-request transport options

The downloader has been refactored to support ETag-based conditional requests, allowing the system to skip downloads when the remote resource has not changed (returning ErrSkipDownload on a 304 response). This change introduces a backup-and-restore mechanism for destination files to ensure that a skipped download does not overwrite existing content. Additionally, the downloader now accepts per-request transport options, including an \Insecure\ flag to allow self-signed certificates, and respects authentication headers for GitHub content downloads.

pkg/downloader · high confidence

Refactored filesystem and tar file walkers with caching and improved skip logic

The filesystem and tar-based file walkers have been refactored to improve performance and correctness. A new \cachedFile\ mechanism caches file contents in memory for small files or in temporary files for large ones, reducing redundant I/O operations. The filesystem walker now uses \filepath.WalkDir\ for more robust directory traversal, and skip path logic has been corrected to properly handle relative and absolute paths. Additionally, symlinks and hardlinks are now correctly skipped during tar scans, and the walker implementation is better integrated with the rest of the Trivy analysis pipeline.

pkg/fanal/walker · high confidence

Replace custom Azure ARM template parser with new modular parser supporting object-based resources

The Azure ARM scanner now uses a new parser implementation (parser.go, template.go) that replaces the previous custom JSON parsing logic. This change introduces support for Azure Resource Manager (ARM) templates where the 'resources' field is defined as an object rather than an array, normalizing both forms into a flat slice for consistent processing. The new parser leverages Go's standard library (encoding/json/v2) and includes a metadata collector to track line numbers and file references for each parsed element, improving the accuracy of security findings. Tests confirm correct parsing of parameters, resources, and nested properties.

pkg/iac/scanners/azure/arm/parser · high confidence

Replace logging implementation with Go's standard slog library

The logging subsystem has been refactored to use Go's standard \log/slog\ library, replacing the previous custom implementation. This change introduces a new \ColorHandler\ for formatted output, supports context-based prefixes and attributes, and ensures error messages are consistently written to stderr. Users will see structured log output with color-coded severity levels and improved context propagation for debugging.

pkg/log · high confidence

Standardize package identification and uniqueness logic

The system now uses a centralized \ID\ function to generate consistent, language-specific identifiers for packages (e.g., \name@version\ for most, \name/version\ for .NET/Conan, \name:version\ for Java/Sbt, and \name@vversion\ for Go). Additionally, a \UID\ function computes a unique hash for each package based on its file path and metadata, ensuring accurate dependency graph construction and deduplication.

pkg/dependency · high confidence

Terraform misconfiguration scanning is consolidated into a new executor

The Terraform scanner now uses a dedicated executor that adapts HCL modules into a state representation for Rego-based scanning. This change introduces support for rendering specific causes for failed checks, enabling users to see the exact Terraform block or attribute that triggered a failure. Additionally, the executor supports scanning raw Terraform data alongside the adapted state, and applies ignore rules and result filters to the final output.

pkg/iac/scanners/terraform/executor · medium confidence

Terraform parsing and evaluation engine refactored

The internal Terraform parsing and evaluation engine has been refactored, introducing new core types for Attributes, Blocks, and Modules to improve how configuration is represented and traversed. This change adds support for new Terraform constructs including the 'action' and 'removed' blocks, and introduces preset value generation for resources like 'random\_id' and 'aws\_region'. Additionally, the system now supports partial evaluation for policy templates and can export raw Terraform data to Rego, while also fixing several issues with dynamic block expansion and reference resolution.

pkg/iac/terraform · high confidence

Terraform scanner refactored with new options and test coverage

The Terraform scanner has been refactored to support configurable scanning options, including the ability to scan raw configuration, skip cached modules, and control directory scanning behavior. A new options package provides a fluent API for configuring the scanner, such as setting workspace names, TF variable paths, and file/directory filters. Additionally, comprehensive test coverage has been added for attribute checking, block presence, count handling, deterministic results, file system scanning, ignore rules, JSON configuration parsing, and module resolution.

pkg/iac/scanners/terraform · high confidence

Test infrastructure updates: HTTP basic auth support and improved repo management

The internal Git test server now supports HTTP basic authentication, allowing tests to verify secured Git operations. Additionally, the test fixture management was updated to pull an existing repository rather than always cloning it, and the server setup was refactored to use dynamically created repositories instead of relying on embedded static files.

internal/gittest · high confidence

Fixes

Add port range parsing utility for network rules

A new \ParsePortRange\ function and \PortRange\ type have been added to the common adapters package to correctly parse network port specifications, including single ports, ranges (e.g., '1000-2000'), and wildcards. This addresses a bug where empty or malformed port ranges in Google Compute Firewall rules were not being parsed correctly, ensuring that network policies are now accurately interpreted from infrastructure-as-code configurations.

pkg/iac/adapters/common · medium confidence

Fix: Add missing S3 bucket module for cached modules test data

The Terraform parser's cached modules test data now includes a \main.tf\ file defining an \aws\_s3\_bucket\ resource. This addition ensures the parser has the necessary module content to correctly process cached module references during scanning.

pkg/iac/scanners/terraform/parser/testdata/cached-modules/.terraform/modules/s3-bucket · medium confidence

Updated npm fixture to include package UIDs and experimental findings

The integration test fixtures for npm conversion now include unique package UIDs and an ExperimentalModifiedFindings section. This update ensures that package identities are uniquely tracked and that experimental vulnerability findings are correctly unmarshalled, preventing errors during report generation.

integration/testdata/fixtures/convert · medium confidence

Test coverage

Add ARM adapter test helper for Azure deployments; Add end-to-end testing framework for image and proxy scans; Add in-memory cache test helpers and error simulation; Add test fixtures for result filtering and ignore rules; Add test hook for internal testing; Add test plugin fixtures for plugin support; Add test server for SBOM attestation scenarios; Add test utility for creating Terraform modules from source; Added CloudFormation scanning tests and example templates; Added CycloneDX SBOM test data for scanning attestation and OS-only scenarios; Added Docker integration test helper for image replication; Added Kubernetes test fixtures for namespace-scoped resource validation; Added SBOM test fixtures for CycloneDX and SPDX formats; Added Terraform plan snapshot test data for nested and local modules; Added integration tests for containerd, library scanning, and registry interactions; Added test data for Terraform Plan snapshot scanning; Added test fixtures for Go module parsing edge cases; New CloudFormation test utility for validating adapter logic; New test helpers for database and fake OCI artifacts; New test utilities for Docker, filesystems, and assertions; Restructured integration test suite with comprehensive golden file management; Updated Python package metadata test fixtures; Updated integration test golden files for multiple output formats; Updated package analysis golden files with new metadata fields; Updated test golden files for vulnerability and package analysis.

Dependencies

Update Go dependencies and toolchain versions

Updated the Go toolchain to version 1.24.7 and upgraded numerous Go dependencies, including github.com/aws/aws-sdk-go, github.com/docker/docker, github.com/open-policy-agent/opa, and github.com/google/go-containerregistry. These updates ensure compatibility with the latest Go releases and incorporate upstream fixes and features.

(dependencies) · high confidence

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

How this codebase got here

Baseline

  • First survey — no prior run to compare against. CAI 74.

Lenses

  • Code Health 81
  • Architecture 100
  • Maturity 74
  • Readiness 68
  • Security 81

Changes since last survey

  • 300 commits — 226 feature/other, 74 fixes

By area

  • (root) — 76 commits
  • pkg/fanal — 37 commits
  • pkg/iac — 37 commits
  • .github/workflows — 32 commits
  • pkg/dependency — 23 commits
  • docs/guide — 19 commits
  • pkg/detector — 12 commits
  • helm/trivy — 11 commits
  • integration/testdata — 9 commits
  • pkg/vex — 6 commits
  • pkg/rpc — 4 commits
  • pkg/sbom — 4 commits
  • docs/getting-started — 3 commits
  • pkg/x — 3 commits
  • .github/CODEOWNERS — 2 commits
  • magefiles/config_schema.go — 2 commits
  • pkg/flag — 2 commits
  • pkg/licensing — 2 commits
  • pkg/module — 2 commits
  • pkg/plugin — 2 commits

Notable commits

  • fix: chore(deps): Bump go-ini and fix the import path. (#10489)
  • fix: chore(deps): bump to alpine:3.23.3 and go-1.25.6 to fix CVEs (#10107)
  • fix: chore(deps): upgrade vm scan dependency for bug fix (#10575)
  • fix: fix(cloudformation): propagate AWS::EC2::Instance MetadataOptions (#10731)
  • fix: fix(conda): avoid panic on an all-operator dependency line (#10955)
  • fix: fix(cyclonedx): include CVSS v4 vulnerability ratings (#10313)
  • fix: fix(docker): fix non-det scan results for images with embedded SBOM (#9866)
  • fix: fix(dotnet): identify deps.json root project from dependency graph (#10954)
  • fix: fix(flag): validate template file extension (#10296)
  • fix: fix(go): use ldflags version for all pseudo-versions (#10037)
  • fix: fix(image): correctly reconstruct RUN instructions built without BuildKit (#10714)
  • fix: fix(image): deterministic OS package deduplication for images with embedded SBOMs (#10777)
  • fix: fix(image): lookup origin layer for custom resources in merged layers (#10788)
  • fix: fix(image): race condition in image artifact inspection (#9966)
  • fix: fix(java): Disable overwriting exclusions (#10088)
  • fix: fix(java): add hash of GAV+root pom file path for pkgID for packages from pom.xml files (#9880)
  • fix: fix(java): correctly inherit properties from parent fields for pom.xml files (#9111)
  • fix: fix(java): correctly propagate repositories from upper POMs to dependencies (#10077)
  • fix: fix(java): set per-file digest for nested JARs (#10855)
  • fix: fix(java): surface 429 from a remote Maven repository as a fatal error when scanning pom.xml files (#10693)
  • …and 280 more

Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.

Survey your own repository

aquasecurity/trivy was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.

About this page

  • The score is its most recent published measurement, taken on 6 August 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
  • Measured at commit 748a639b1d436a0566d325a4233ca13baf4cbd60 — the exact code this score is about.
  • Scored under rubric-2026.08.19 — the same rubric and the same method as every other entry in this index.
  • Measured by watchdog.canine.dev using codehealth-analyzer latest.