## aquasecurity/trivy — v0.71.2…v0.72.0

_45 commits._

### Features
- **feat(bottlerocket): add vulnerability matching for Bottlerocket OS (#10893)** (246ee3c)
- **feat(java): detect JAR licenses from packaged LICENSE files (#10856)** (b8a1ccd)
- **feat(java): detect JAR licenses from the embedded pom.xml (#10851)** (0a166c3)
- **feat(misconf): Adds CloudFront standard logging v2 support to AVD-AWS-0010 (#10848)** (a848925)
- **feat(secret): support new stateless format for GitHub App installation tokens (#10826)** (e68f3d2)
- **feat(dotnet): detect bundled runtime in self-contained deployments (#10786)** (bd78842)
- **feat(secret): add OpenAI secret detection rules (#10798)** (65e5128)

### Fixes
- **fix(misconf): support github_repository_vulnerability_alerts resource (#10680)** (abb5174)
- **fix(nodejs): parse project dependencies from multi-document pnpm-lock.yaml (#10861)** (a10291b)
- **fix(server): propagate package repository class in client/server mode (#10874)** (a2777ae)
- **fix(vuln): fall back to UNKNOWN severity when vulnerability details are missing (#10795)** (dfd53cf)
- **fix(terraform): avoid data race on global getter.Getters in remote module resolver (#10843)** (0aff3fd)
- **fix: correct format verbs in diagnostic messages (#10805)** (859a933)
- **fix: forward ospkg detector options through ospkg.NewScanner (#10811)** (28d44d3)
- **fix(vex): load VEX documents from within the repository directory (#10820)** (1f56a34)
- **fix: surface the original analysis error instead of context cancellation (#10793)** (3054b3b)
- **fix: use random suffix for process temp directory instead of PID (#10431)** (c8d1d0d)
- **fix(image): lookup origin layer for custom resources in merged layers (#10788)** (dccb128)
- **fix(image): deterministic OS package deduplication for images with embedded SBOMs (#10777)** (888911b)
- **fix(spdx): guard against nil root component in SPDX marshaler (#10771)** (c0654e1)

### Backend
- **release: v0.72.0 [main] (#10782)** (8a32853)
- **Merge commit from fork** (d4213d7)
- **Merge commit from fork** (39e0b13)

### Tests
- **test: close plugin manager in tests cleanup (#10904)** (4295ac0)
- **test: fix flaky containerd integration test (#10760)** (9032dcb)
- **test(java): force offline-scan for client/server integration tests (#10721)** (b3d7be5)

### Docs
- **docs: fix article typo in plugin developer guide (#10860)** (13de603)
- **docs: fix typos (#10857)** (c1ad0e0)
- **docs: fix repository scan heading typo (#10828)** (469d4fb)
- **docs: update signature verification for deb and rpm packages (#10784)** (3851371)
- **docs: fix broken nixpkgs reference link in installation guide (#10776)** (48af854)

### Chore
- **chore(deps): bump github.com/containerd/containerd/v2 from 2.3.1 to 2.3.2 (#10888)** (6e37acf)
- **chore(deps): Upgrade github.com/cenkalti/backoff to v6 (#10863)** (7a69b8f)
- **ci(helm): bump Trivy version to 0.71.2 for Trivy Helm Chart 0.23.2 (#10873)** (1df6ca3)
- **chore(deps): bump alpine to 3.24.1 (#10868)** (49299df)
- **ci(helm): bump Trivy version to 0.71.1 for Trivy Helm Chart 0.23.1 (#10845)** (47b7ba4)
- **refactor: use ParseErrorsAllowlist instead of ParseErrorsWhitelist (#10830)** (3960fac)
- **chore(deps): bump github.com/bufbuild/buf to v1.70.0 (#10801)** (5619ae1)
- **ci!: migrate docker config to dockers_v2 (#10783)** (848d135)
- **ci: expect GitHub App bot as backport PR author (#10813)** (c613b5d)
- **chore(deps): bump the github-actions group across 1 directory with 11 updates (#10803)** (15bdd2c)
- **chore(deps): bump the common group with 4 updates (#10797)** (576b093)
- **chore(deps): bump the aws group with 4 updates (#10796)** (92b4a05)
- **ci: bump GoReleaser to v2.16.0 (#10774)** (f00ee41)
- **ci(helm): bump Trivy version to 0.71.0 for Trivy Helm Chart 0.23.0 (#10768)** (7ca5a6b)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/aquasecurity/trivy?utm_source=github-action)._