Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This bumps the version of trivy from 0.49.1 to 0.54.1, to resolve critical CVE detections found on quay.io:
This change also replaces the install method with the one documented here:
https://aquasecurity.github.io/trivy/v0.56/getting-started/installation/#rhelcentos-official
Why version 0.54.1?
Version 0.54.0 is the first version after 0.49.1 to include both of the critical CVE fixes. 0.54.1 includes a few additional patches. Based on changelog it looks like there can be breaking in changes in minor releases (y-stream), so I have tried to be conservative and minimise the number of versions we jump ahead.
This change will likely need some manul testing before it lands in a stable release.