release: v0.62.0 [main] #38
Open
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
🤖 I have created a release beep boop
0.62.0 (2025-04-08)
⚠ BREAKING CHANGES
Features
--distro
flag to manually specify OS distribution for vulnerability scanning (#8070) (da17dc7)--vuln-severity-source
flag (#8269) (d464807)log.FilePath()
function for logger (#7080) (1f5f348)workspaceRelationship
(#7889) (d622ca2)trivy auth
(#7664) (27117f8)--vuln-type
flag to--pkg-types
flag (#7104) (7cbdb0a)trivy auth
totrivy registry
(#7727) (633a7ab)environment.yml
files (#6953) (654217a)CycloneDX
reports (#7507) (c225883)go.mod
main module in the parser (#7977) (5448ba2)toolchain
asstdlib
version forgo.mod
files (#7163) (2d80769)test
scope support forpom.xml
files (#7414) (2d97700)pom.xml
dependency versions can't be detected (#7520) (b836232)--skip-*
for all included modules (#7579) (c0e8da3)flavors
support (#7858) (b9b383e)SPDX
andCycloneDX
reports (#7257) (4a2f492)--path-prefix
flag for client/server mode (#7321) (24a4563)--detection-priority
flag for accuracy tuning (#7288) (fd8348d)--pkg-relationships
(#7237) (5c37361)Bug Fixes
UID
for removed packages (#7887) (07915da)clean --all
deletes only relevant dirs (#7704) (672e886)DownloadedAt
fortrivy-java-db
(#7592) (13ef3e7)dpkg
packages with different filePaths from different layers (#8298) (846498d)dpkgs
(#8623) (346f5b3)scope
fortrivy registry login
command (#8393) (8715e5d)*.deps.json
files (#7039) (5bc662b)nuget package dir not found
log only when checkingnuget
packages (#7194) (d76feba)--clear-cache
(#7281) (2a0e529)--generate-default-config
command (#8046) (5e68bdc)BLOW_UNKNOWN
error to download DBs (#8060) (51f2123)kind
andapiVersion
ofvolumeClaimTemplate
element (#7362) (da4ebfa)pom
init
dir are not found (#7245) (4e54a7e)version
andscope
from upper/rootdepManagement
anddependencies
into parents (#7541) (778df82)project.*
props (#8050) (9d9f80d)dependencyManagement
from root/child pom's for dependencies from parents (#7497) (5442949)go-mvn-version
to removePackage
duplicates (#7088) (a7a304d)PkgRelationships
(#8442) (f987e41)--report all
(#8613) (dbb6f28)mirror.gcr.io
(#7953) (9988147)importers
to detect dev deps from pnpm-lock.yaml file (#7387) (fd9ed3a)latest
version for filesyarn.lock
+package.json
(#7110) (54bb8bd)poetry
v2 support (#8323) (10cd98c)usr/share/buildinfo/
dir to detect content sets (#8222) (f352f6b)root/buildinfo/content_manifests/
contains files that are notcontentSets
files (#7912) (38775a5)git clone
output to Stderr (#7561) (fdf203c)Message
field inasff.tpl
template (#7401) (dd9733e)ExperimentalModifiedFindings
(#7463) (7ff9aff)[email protected]
schema for misconfigs insarif
report (#7898) (19aea4b)shortDescription
andfullDescription
fields for sarif reports (#8344) (3eb0b03)framework
aslibrary
when unmarshallingCycloneDX
files (#7527) (aeb7039)Annotation
instead ofAttributionTexts
forSPDX
formats (#7811) (f2bb9c6)NOASSERTION
for licenses fields in SPDX formats (#7403) (c96dcdd)unknown
dependencies (if exists) (#8104) (7558df7)hugging-face-access-token
(#7216) (8c87194).eyJ
keyword for JWT secret (#7410) (bf64003)pkgFilePaths
map for all formats (#8380) (72ea4b0)otherLicenses
without normalize (#8502) (e5072f1)hasExtractedLicensingInfos
field for licenses that are not listed in the SPDX (#8077) (aec8885)--file-patterns
flag for all post analyzers (#7365) (8b88238)Performance Improvements
bytes.Index
inemptyLineSplit
to cut allocation (#7065) (acbec05)Reverts
test
scope forpom.xml
files (#7488) (b0222fe)This PR was generated with Release Please. See documentation.