Skip to content

Comments

Bump Trivy to v0.69.1#2168

Merged
priteau merged 1 commit intostackhpc/2025.1from
bump-trivy
Feb 20, 2026
Merged

Bump Trivy to v0.69.1#2168
priteau merged 1 commit intostackhpc/2025.1from
bump-trivy

Conversation

@priteau
Copy link
Member

@priteau priteau commented Feb 20, 2026

No description provided.

@priteau priteau self-assigned this Feb 20, 2026
@priteau priteau requested a review from a team as a code owner February 20, 2026 15:56
Copy link
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

The pull request updates the trivy installation instruction in tools/scan-images.sh to reference version v0.69.1, up from v0.68.2. This change is consistent with the goal of keeping dependencies up to date and providing users with the correct installation command for the latest version. The modification is straightforward and does not introduce any functional or security issues.

@priteau
Copy link
Member Author

priteau commented Feb 20, 2026

See scan test which caught the Grafana critical issue:

"PkgName","PkgPath","PkgID","VulnerabilityID","FixedVersion","PrimaryURL","Severity"
"stdlib","","stdlib@v1.25.6","CVE-2025-68121","1.24.13, 1.25.7, 1.26.0-rc.3","https://avd.aquasec.com/nvd/cve-2025-68121","CRITICAL"

@priteau priteau requested a review from Alex-Welsh February 20, 2026 16:08
@priteau priteau merged commit 9d4f672 into stackhpc/2025.1 Feb 20, 2026
25 of 29 checks passed
@priteau priteau deleted the bump-trivy branch February 20, 2026 17:23
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants