🌱 Update Builder Image group #1572
                
     Open
            
            
          
  Add this suggestion to a batch that can be applied as a single commit.
  This suggestion is invalid because no changes were made to the code.
  Suggestions cannot be applied while the pull request is closed.
  Suggestions cannot be applied while viewing a subset of changes.
  Only one suggestion per line can be applied in a batch.
  Add this suggestion to a batch that can be applied as a single commit.
  Applying suggestions on deleted lines is not supported.
  You must change the existing code in this line in order to create a valid suggestion.
  Outdated suggestions cannot be applied.
  This suggestion has been applied or marked resolved.
  Suggestions cannot be applied from pending reviews.
  Suggestions cannot be applied on multi-line comments.
  Suggestions cannot be applied while the pull request is queued to merge.
  Suggestion cannot be applied right now. Please check back later.
  
    
  
    
This PR contains the following updates:
v1.36.2->v1.37.10.60.0->0.67.2v2.12.0-alpine->v2.14.0-alpine3.21.3->3.22.21.24.5-bullseye->1.24.6-bullseyev1.64.8->v2.5.0v3.18.6->v3.19.0Release Notes
adrienverge/yamllint (adrienverge/yamllint)
v1.37.1Compare Source
v1.37.0Compare Source
aquasecurity/trivy (docker.io/aquasec/trivy)
v0.67.2Compare Source
Changelog
60c57adrelease: v0.67.2 [release/v0.67] (#9639)f3ee80cfix: Usefetch-level: 1to check out trivy-repo in the release workflow [backport: release/v0.67] (#9638)v0.67.1Compare Source
Changelog
cbed239release: v0.67.1 [release/v0.67] (#9614)1a84093fix: restore compatibility for google.protobuf.Value [backport: release/v0.67] (#9631)3bc1490fix: using SrcVersion instead of Version for echo detector [backport: release/v0.67] (#9629)542eee7fix: addbuildInfoforBlobInfoinrpcpackage [backport: release/v0.67] (#9615)f65dd05fix(vex): don't use reused BOM [backport: release/v0.67] (#9612)v0.67.0Compare Source
Features
Bug Fixes
BuildableClientinsead ofxhttp.Client(#9436) (fa6f1bf)Package.IDfor pnpm packages (#9330) (4517e8c)nugetpackage names in lower case (#9456) (1ff9ac7)v0.66.0Compare Source
Features
Bug Fixes
package.jsonfile (#9349) (03d039f)filecomponent type ofCycloneDX(#9372) (aa7cf43)v0.65.0Compare Source
Features
--serverflag (#9270) (ed4640e)Bug Fixes
filepathwhen removing duplicate packages (#9142) (4d10a81)GFDL-NIV-1.1andGFDL-NIV-1.2into Trivy mapping (#9116) (a692f29)LaxSplitLicenses(#9232) (b4193d0)*.listto*.md5sumsfiles fordpkg(#9131) (f224de3)root.iopackages (#9117) (c2ddd44)for_eachon a map returns a resource for every key (#9156) (153318f)v0.64.1Compare Source
Changelog
86ee3c1release: v0.64.1 [release/v0.64] (#9122)4e12722fix(misconf): skip rewriting expr if attr is nil [backport: release/v0.64] (#9127)9a7d384fix(cli): Add more non-sensitive flags to telemetry [backport: release/v0.64] (#9124)53adfbafix(rootio): check full version to detectroot.iopackages [backport: release/v0.64] (#9120)8cf1bf9fix(alma): parse epochs from rpmqa file [backport: release/v0.64] (#9119)v0.64.0Compare Source
Features
Bug Fixes
packagesarray ofbun.lockfile (#8998) (875ec3a)tableformat (#8549) (87fda76)v0.63.0Compare Source
Features
Minimum Trivy Version(#8880) (3b2a397)Bug Fixes
--skip-dirand--skip-filesflags forsbomcommand (#8886) (69a5fa1)--complianceflag (#8881) (35e8889)Relationshipfield support (#8939) (22f040f)rpc(#8872) (38f17c9)lo.IsNilto checkVEXfrom OCI artifact (#8858) (e97af98)Performance Improvements
v0.62.1Compare Source
Changelog
c75ed21release: v0.62.1 [release/v0.62] (#8825)aafebebchore(deps): bump the common group across 1 directory with 10 updates [backport: release/v0.62] (#8831)99485cffix(misconf): check if for-each is known when expanding dyn block [backport: release/v0.62] (#8826)b4fc9e8fix(redhat): trim invalid suffix from content_sets in manifest parsing [backport: release/v0.62] (#8824)v0.62.0Compare Source
Features
yarnpackages (#8535) (bf4cd4f)cargolock files (#8676) (93efe07)Bug Fixes
last-applied-configuration(#8791) (7a58ccb)evaluateStepto correctly setEvalContextfor multiple instances of blocks (#8555) (e25de25)v0.61.1Compare Source
Changelog
7d3b4ffrelease: v0.61.1 [release/v0.61] (#8704)80d120ffix(k8s): skip passed misconfigs for the summary report [backport: release/v0.61] (#8748)9d6290bfix(k8s): correct compare artifact versions [backport: release/v0.61] (#8699)3799ebbtest: useaquasecurityrepository for test images [backport: release/v0.61] (#8698)v0.61.0Compare Source
Features
Bug Fixes
dpkgs(#8623) (346f5b3)--report all(#8613) (dbb6f28)otherLicenseswithout normalize (#8502) (e5072f1)--file-patternsflag for all post analyzers (#7365) (8b88238)Performance Improvements
hadolint/hadolint (docker.io/hadolint/hadolint)
v2.14.0Compare Source
What's Changed
DL3062to checkgo installby @Danil42Russia in https://github.com/hadolint/hadolint/pull/1111New Contributors
Full Changelog: hadolint/hadolint@v2.13.1...v2.14.0
v2.13.1Compare Source
What's Changed
DL3022by @swarnimarun in https://github.com/hadolint/hadolint/pull/900failure-thresholdby @ericcornelissen in https://github.com/hadolint/hadolint/pull/901Configuration
📅 Schedule: Branch creation - "on the first day of the month" in timezone Europe/Berlin, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.