Skip to content

Bump Trivy to 0.69.2 Yoga#2191

Merged
priteau merged 1 commit intostackhpc/yogafrom
trivy-bump-yoga
Mar 2, 2026
Merged

Bump Trivy to 0.69.2 Yoga#2191
priteau merged 1 commit intostackhpc/yogafrom
trivy-bump-yoga

Conversation

@seunghun1ee
Copy link
Member

Trivy had security incident on 1st March 2026 [1], resulting losing all GitHub Releases between 0.27.0-0.69.1.
They then restored the latest as 0.69.2

[1] aquasecurity/trivy#10265

(cherry picked from commit 9144c9f)

Trivy had security incident on 1st March 2026 [1], resulting losing all
GitHub Releases between 0.27.0-0.69.1.
They then restored the latest as 0.69.2

[1] aquasecurity/trivy#10265

(cherry picked from commit 9144c9f)
@seunghun1ee seunghun1ee self-assigned this Mar 2, 2026
@seunghun1ee seunghun1ee requested a review from a team as a code owner March 2, 2026 11:41
@seunghun1ee seunghun1ee added the yoga Targets the Yoga OpenStack release label Mar 2, 2026
Copy link
Contributor

@gemini-code-assist gemini-code-assist bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Code Review

This pull request updates the recommended Trivy version in the scan-images.sh script to v0.69.2. This change is necessary due to a security incident that led to the removal of older Trivy releases, making the previous version specified (v0.49.1) unavailable. The update ensures that the installation command provided to users is valid and points to an available release. The change is correct and I have no further suggestions.

@priteau priteau merged commit 7dc99fb into stackhpc/yoga Mar 2, 2026
15 checks passed
@priteau priteau deleted the trivy-bump-yoga branch March 2, 2026 12:05
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

yoga Targets the Yoga OpenStack release

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants