Skip to content

build(deps): bump aquasecurity/trivy-action from 0.31.0 to 0.34.0#5461

Open
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/github_actions/aquasecurity/trivy-action-0.34.0
Open

build(deps): bump aquasecurity/trivy-action from 0.31.0 to 0.34.0#5461
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/github_actions/aquasecurity/trivy-action-0.34.0

Conversation

@dependabot
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Feb 16, 2026

Bumps aquasecurity/trivy-action from 0.31.0 to 0.34.0.

Release notes

Sourced from aquasecurity/trivy-action's releases.

v0.34.0

What's Changed

Full Changelog: aquasecurity/trivy-action@0.33.1...0.34.0

v0.33.1

What's Changed

Full Changelog: aquasecurity/trivy-action@0.33.0...0.33.1

v0.33.0

What's Changed

New Contributors

Full Changelog: aquasecurity/trivy-action@0.32.0...0.33.0

v0.32.0

What's Changed

Full Changelog: aquasecurity/trivy-action@0.31.0...0.32.0

Commits
  • c1824fd chore(deps): Update trivy to v0.69.1 (#506)
  • bc61dc5 Merge commit from fork
  • 5eb7ef2 ci: use checks bundle v2 in sync workflow (#505)
  • 22438a4 Merge pull request #496 from aquasecurity/bump-trivy-1765431074
  • 0024b3f chore(deps): Update trivy to v0.68.1
  • 83690f7 ci: install trivy in bump-trivy workflow and update tests (#495)
  • df65449 chore: update README (#493)
  • 0317097 ci: use setup-bats in bump-trivy workflow (#494)
  • b6643a2 Update setup-trivy action to version v0.2.4 (#486)
  • f9424c1 Merge pull request #481 from aquasecurity/bump-trivy-1755898251
  • Additional commits viewable in compare view

Dependabot compatibility score

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)

Bumps [aquasecurity/trivy-action](https://github.com/aquasecurity/trivy-action) from 0.31.0 to 0.34.0.
- [Release notes](https://github.com/aquasecurity/trivy-action/releases)
- [Commits](aquasecurity/trivy-action@0.31.0...0.34.0)

---
updated-dependencies:
- dependency-name: aquasecurity/trivy-action
  dependency-version: 0.34.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@dependabot dependabot bot added pr/dependabot/github-actions This pull is for github-actions from dependabot release/none no release note labels Feb 16, 2026
@dependabot dependabot bot added pr/dependabot/github-actions This pull is for github-actions from dependabot release/none no release note labels Feb 16, 2026
@github-actions
Copy link
Contributor

📋 Release Label Required

To automatically generate release notes, this PR must have at least one of the following labels:

  • release/bug: 🐛 Bug fix - fixes an existing bug
  • release/feature-new: ✨ New feature - adds new functionality
  • release/feature-changed: 🔄 Feature change - modifies existing functionality
  • release/none: 📝 No release note - documentation, tests, or internal changes
  • pr/robot_update: 🤖 Robot update - automated dependency or version updates
    Use the following commands in a comment:
  • /label release/bug
  • /label release/feature-new
  • /label release/feature-changed
  • /label release/none
  • /label pr/robot_update

This message is automatically sent by GitHub Actions

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

pr/dependabot/github-actions This pull is for github-actions from dependabot release/none no release note

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants