Skip to content

chore(docker): bump the docker group across 1 directory with 5 updates#42

Closed
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker/versions/docker-dbe0372d97
Closed

chore(docker): bump the docker group across 1 directory with 5 updates#42
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker/versions/docker-dbe0372d97

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Jul 20, 2026

Copy link
Copy Markdown

Bumps the docker group with 5 updates in the /versions directory:

Package From To
trufflesecurity/trufflehog 3.95.2 3.95.9
anchore/syft v1.44.0 v1.48.0
aquasecurity/trivy 0.70.0 0.72.0
anchore/grype v0.112.0 v0.116.0
semgrep/semgrep 1.161.0 1.169.0

Updates trufflesecurity/trufflehog from 3.95.2 to 3.95.9

Release notes

Sourced from trufflesecurity/trufflehog's releases.

v3.95.9

What's Changed

New Contributors

Full Changelog: trufflesecurity/trufflehog@v3.95.8...v3.95.9

v3.95.8

What's Changed

Full Changelog: trufflesecurity/trufflehog@v3.95.7...v3.95.8

v3.95.7

What's Changed

... (truncated)

Commits
  • 27b0417 Don't log as error when git diff is too long (#5113)
  • d328285 [INS-410] Added batch token detector (#4824)
  • 33d9dad [INT-715] Retry transient failures when verifying OpenAI keys (#5117)
  • d7dcc6d feat: Support archived repo exclusion from GH org scans (#4875)
  • f845f18 feat(action): add image input to allow registry mirror overrides (#4965)
  • 6c97970 [INS-468] Add improved lob detector to defaults.go (#4971)
  • 1675e17 fix: reject --include-repos/--exclude-repos with --repo in github scan (#5112)
  • 5c27626 [INS-467] Add IPinfo detector to default detectors list (#4970)
  • 53e6391 [INS-341] Added Shippo detector (#4820)
  • d3b5487 [INS-351] Added Duffel Token Detector (#4795)
  • Additional commits viewable in compare view

Updates anchore/syft from v1.44.0 to v1.48.0

Release notes

Sourced from anchore/syft's releases.

v1.48.0

Added Features

Bug Fixes

Dependencies

9 dependency changes (8 updated, 1 added).

  • github.com/bmatcuk/doublestar v1.3.1v8.8.8
  • github.com/klauspost/compress v1.18.6v1.19.0
  • golang.org/x/tools v0.46.0v0.47.0
  • modernc.org/cc/v4 v4.28.2v4.28.4
  • modernc.org/ccgo/v4 v4.34.0v4.34.4
  • modernc.org/gc/v3 v3.1.2v3.1.3
  • modernc.org/libc v1.72.3v1.73.4
  • modernc.org/sqlite v1.51.0v1.53.0

... (truncated)

Commits

Updates aquasecurity/trivy from 0.70.0 to 0.72.0

Release notes

Sourced from aquasecurity/trivy's releases.

v0.72.0

⚡ Highlights ⚡

👉 aquasecurity/trivy#10907

Changelog

https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md#0720-2026-06-30

v0.71.2

Changelog

  • 055a5c8a53bfd61f7a8e276a5b2f0c3fc1673420 release: v0.71.2 [release/v0.71] (#10871)
  • 875328a4138f26e8559cfee80adaef82b6693076 fix(deps): bump alpine to 3.24.1 [backport: release/v0.71] (#10870)
  • 998f7b3c3f3c9de2132bc4358970eeafbd797fba chore(deps): bump the common group with 4 updates [backport: release/v0.71] (#10867)

v0.71.1

Changelog

  • 164b383121351c2d49c5d354c2245719d972752b release: v0.71.1 [release/v0.71] (#10818)
  • a72d9a4d997c25fbb6534e231b4e206c9b202b31 fix(oci): validate artifact filename
  • 3dd98471dfbbc4a95edd5cd866468d3a8c87fd17 fix: forward ospkg detector options through ospkg.NewScanner [backport: release/v0.71] (#10825)
  • a62cbe40a240d3a3f568401b8a5f86e14114e371 fix(vex): load VEX documents from within the repository directory [backport: release/v0.71] (#10821)
  • 43d1d2628725e913db110b89419f0bebd36f58a8 fix: surface the original analysis error instead of context cancellation [backport: release/v0.71] (#10812)
  • ac7696c7b50d633183ce2ff44898d4b5c6eae565 ci: expect GitHub App bot as backport PR author [backport: release/v0.71] (#10815)

v0.71.0

⚡ Highlights ⚡

👉 aquasecurity/trivy#10767

Changelog

https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md#0710-2026-06-01

Changelog

Sourced from aquasecurity/trivy's changelog.

0.72.0 (2026-06-30)

⚠ BREAKING CHANGES

  • migrate docker config to dockers_v2 (#10783)

Features

  • bottlerocket: add vulnerability matching for Bottlerocket OS (#10893) (246ee3c)
  • dotnet: detect bundled runtime in self-contained deployments (#10786) (bd78842)
  • java: detect JAR licenses from packaged LICENSE files (#10856) (b8a1ccd)
  • java: detect JAR licenses from the embedded pom.xml (#10851) (0a166c3)
  • misconf: Adds CloudFront standard logging v2 support to AVD-AWS-0010 (#10848) (a848925)
  • secret: add OpenAI secret detection rules (#10798) (65e5128)
  • secret: support new stateless format for GitHub App installation tokens (#10826) (e68f3d2)

Bug Fixes

  • correct format verbs in diagnostic messages (#10805) (859a933)
  • forward ospkg detector options through ospkg.NewScanner (#10811) (28d44d3)
  • image: deterministic OS package deduplication for images with embedded SBOMs (#10777) (888911b)
  • image: lookup origin layer for custom resources in merged layers (#10788) (dccb128)
  • misconf: support github_repository_vulnerability_alerts resource (#10680) (abb5174)
  • nodejs: parse project dependencies from multi-document pnpm-lock.yaml (#10861) (a10291b)
  • server: propagate package repository class in client/server mode (#10874) (a2777ae)
  • spdx: guard against nil root component in SPDX marshaler (#10771) (c0654e1)
  • surface the original analysis error instead of context cancellation (#10793) (3054b3b)
  • terraform: avoid data race on global getter.Getters in remote module resolver (#10843) (0aff3fd)
  • use random suffix for process temp directory instead of PID (#10431) (c8d1d0d)
  • vex: load VEX documents from within the repository directory (#10820) (1f56a34)
  • vuln: fall back to UNKNOWN severity when vulnerability details are missing (#10795) (dfd53cf)

Continuous Integration

0.71.0 (2026-06-01)

Features

  • add WithDriver and WithProvider options to ospkg detector (#10740) (f8a6ddb)
  • java: support <mirrors> from settings.xml (#10692) (c080ce3)
  • sbom: support for CycloneDX 1.7 (#10715) (04f739e)
  • seal: add vendor support for language file detection. (#10297) (b08bf6a)
  • secret: add a way to customize skipped folders, files and exts (#10550) (e4325b1)
  • secret: add Azure secret detection rules (#10562) (69dcd18)

... (truncated)

Commits
  • 8a32853 release: v0.72.0 [main] (#10782)
  • 4295ac0 test: close plugin manager in tests cleanup (#10904)
  • d4213d7 Merge commit from fork
  • 246ee3c feat(bottlerocket): add vulnerability matching for Bottlerocket OS (#10893)
  • abb5174 fix(misconf): support github_repository_vulnerability_alerts resource (#10680)
  • b8a1ccd feat(java): detect JAR licenses from packaged LICENSE files (#10856)
  • a10291b fix(nodejs): parse project dependencies from multi-document pnpm-lock.yaml (#...
  • a2777ae fix(server): propagate package repository class in client/server mode (#10874)
  • 6e37acf chore(deps): bump github.com/containerd/containerd/v2 from 2.3.1 to 2.3.2 (#1...
  • dfd53cf fix(vuln): fall back to UNKNOWN severity when vulnerability details are missi...
  • Additional commits viewable in compare view

Updates anchore/grype from v0.112.0 to v0.116.0

Release notes

Sourced from anchore/grype's releases.

v0.116.0

Added Features

Bug Fixes

  • regenerate v6.1.8 blob and sql schemas [PR #3574 @​spiffcs]
  • rhel version streams [PR #3572 @​kzantow]
  • Grype doesn't match u-boot in SBOM if type is set to firmware [Issue #2537]
  • Ignore Go compiler affecting CVE when Docker image only contains a binary compiled with Go [Issue #1782]
  • Zarf scans emit warnings for consistently unreadable files (i.e., included non-SBOMs) [Issue #3516] [PR #3545 @​brandtkeller]
  • Fail parsing github actions [Issue #3220]
  • Go vulnerability returned when installed version is greater than fixed version [Issue #3520]

Dependencies

14 dependency changes (11 updated, 3 added).

  • github.com/anchore/go-rpmdb v0.1.0v0.2.0
  • github.com/anchore/syft v1.46.0v1.48.0
  • github.com/klauspost/compress v1.18.6v1.19.0
  • golang.org/x/text v0.38.0v0.39.0
  • golang.org/x/tools v0.46.0v0.47.0
  • gorm.io/gorm v1.31.1v1.31.2
  • modernc.org/cc/v4 v4.28.2v4.28.4
  • modernc.org/ccgo/v4 v4.34.0v4.34.4
  • modernc.org/gc/v3 v3.1.2v3.1.3
  • modernc.org/libc v1.72.3v1.73.4
  • modernc.org/sqlite v1.51.0v1.53.0
  • github.com/mattn/go-sqlite3 v1.14.23
  • gorm.io/driver/sqlite v1.6.0
  • howett.net/plist v1.0.1

(Full Changelog)

... (truncated)

Commits
  • 3b014b0 chore(deps): update anchore dependencies (#3536)
  • 159bf2d feat: add Go symbol matching for stdlib, golang.org/x, and third party Go vul...
  • 9490127 fix(db): regenerate v6.1.8 blob and sql schemas (#3574)
  • fcf08ae fix: rhel version streams (#3572)
  • bcfc0e7 Add Ubuntu ESM vulnerability matching (#3546)
  • b31a422 chore(deps): bump github.com/klauspost/compress from 1.18.6 to 1.19.0 (#3566)
  • 488696e chore(deps): bump github/codeql-action/upload-sarif (#3563)
  • 2319b61 chore(deps): bump docker/login-action from 4.2.0 to 4.4.0 (#3564)
  • a0581cd chore(deps): bump golang.org/x/text from 0.38.0 to 0.39.0 (#3565)
  • 1c601b2 chore(deps): bump anchore/workflows/.github/workflows/check-gate.yaml (#3552)
  • Additional commits viewable in compare view

Updates semgrep/semgrep from 1.161.0 to 1.169.0

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the docker group with 5 updates in the /versions directory:

| Package | From | To |
| --- | --- | --- |
| [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog) | `3.95.2` | `3.95.9` |
| [anchore/syft](https://github.com/anchore/syft) | `v1.44.0` | `v1.48.0` |
| [aquasecurity/trivy](https://github.com/aquasecurity/trivy) | `0.70.0` | `0.72.0` |
| [anchore/grype](https://github.com/anchore/grype) | `v0.112.0` | `v0.116.0` |
| semgrep/semgrep | `1.161.0` | `1.169.0` |



Updates `trufflesecurity/trufflehog` from 3.95.2 to 3.95.9
- [Release notes](https://github.com/trufflesecurity/trufflehog/releases)
- [Commits](trufflesecurity/trufflehog@v3.95.2...v3.95.9)

Updates `anchore/syft` from v1.44.0 to v1.48.0
- [Release notes](https://github.com/anchore/syft/releases)
- [Changelog](https://github.com/anchore/syft/blob/main/RELEASE.md)
- [Commits](anchore/syft@v1.44.0...v1.48.0)

Updates `aquasecurity/trivy` from 0.70.0 to 0.72.0
- [Release notes](https://github.com/aquasecurity/trivy/releases)
- [Changelog](https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md)
- [Commits](aquasecurity/trivy@v0.70.0...v0.72.0)

Updates `anchore/grype` from v0.112.0 to v0.116.0
- [Release notes](https://github.com/anchore/grype/releases)
- [Changelog](https://github.com/anchore/grype/blob/main/RELEASE.md)
- [Commits](anchore/grype@v0.112.0...v0.116.0)

Updates `semgrep/semgrep` from 1.161.0 to 1.169.0

---
updated-dependencies:
- dependency-name: trufflesecurity/trufflehog
  dependency-version: 3.95.9
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: docker
- dependency-name: anchore/syft
  dependency-version: v1.48.0
  dependency-type: direct:production
  dependency-group: docker
- dependency-name: aquasecurity/trivy
  dependency-version: 0.72.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: docker
- dependency-name: anchore/grype
  dependency-version: v0.116.0
  dependency-type: direct:production
  dependency-group: docker
- dependency-name: semgrep/semgrep
  dependency-version: 1.169.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: docker
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file docker Pull requests that update Docker base images labels Jul 20, 2026
@github-actions

Copy link
Copy Markdown

Security Scan Results

Repository: actions | Commit: 799f3aa

Check Status Details
✅ Secret Scan Pass No secrets detected
⏩ Dependencies Skipped -

Scanned at 2026-07-20 09:20 UTC

@github-actions

Copy link
Copy Markdown

Semgrep Scan Results

Repository: actions | Commit: 799f3aa

Check Status Details
✅ Semgrep Pass 0 total findings (no error/warning)

Scanned at 2026-07-20 09:20 UTC

@dependabot @github

dependabot Bot commented on behalf of github Jul 27, 2026

Copy link
Copy Markdown
Author

Looks like these dependencies are updatable in another way, so this is no longer needed.

@dependabot dependabot Bot closed this Jul 27, 2026
@dependabot
dependabot Bot deleted the dependabot/docker/versions/docker-dbe0372d97 branch July 27, 2026 09:20
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker Pull requests that update Docker base images

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants