## aquasecurity/trivy — v0.74.0…v0.75.0

_80 commits._

### Features
- **feat(crypto): add the crypto scanner to the image command (#11144)** (dc9a384)
- **feat(echo): add vulnerability detection for Echo-patched Python packages (#10555)** (98787b8)
- **feat(crypto): transfer cryptographic assets in client/server mode (#11141)** (4128b7f)
- **feat(crypto): output cryptographic assets in CycloneDX (#11125)** (3897d5c)
- **feat(crypto): add analyzer and pass assets to the scan report (#11104)** (fb7ad28)
- **feat(crypto): describe ML-DSA keys and signature algorithms (#11137)** (20c3c35)
- **feat(crypto): describe parsed material as cryptographic assets (#11092)** (7d0a892)
- **feat(cli): allow disabling configuration files with empty paths (#11210)** (5f00edd)
- **feat: add cryptographic asset model and parser (#10970)** (64e1715)

### Fixes
- **fix(os): keep the fullest OS version when merging analyzer results (#11039)** (0afeae0)
- **fix(crypto): read RSA private keys without validating their math (#11319)** (3683d7d)
- **fix(python): support uv workspace lockfiles (#10553)** (a072319)
- **fix(purl): classify julia, bottlerocket and centos stream packages (#11326)** (3a1b311)
- **fix(python): skip pip requirement lines with malformed extras brackets (#11300)** (7e71d21)
- **fix: correct grammar and typos in user-facing error messages and CLI flags (#11281)** (5ba5be0)
- **fix(vex): avoid panic on CSAF relationships without a sub-component (#11067)** (ae561f8)
- **perf(secret): replace per-rule keyword search with one Aho-Corasick pass (#11179)** (f372e56)
- **perf(crypto): report repeated x509 material once per file (#11263)** (f6423f6)
- **perf: take JSON line numbers from decoder offsets (#11233)** (7e21433)
- **fix(sbom): skip null entries in SPDX file and package arrays (#11101)** (0aaaa71)
- **fix(license): report unparsable license names with UNKNOWN severity (#11254)** (7b598ab)
- **fix: avoid panics on malformed dependency files and version-less Amazon Linux release (#10996)** (ef28d95)
- **perf: reuse one JSON unmarshaler per document (#11232)** (e97dfcc)
- **perf: avoid regrowing the buffer when reading a cached file (#11134)** (25521f4)
- **fix(repo): strip credentials from remote repository URL in artifact name (#11213)** (c961eeb)
- **fix: set locations for JSON values sharing a line (#11231)** (e5b5a3a)
- **fix(report)!: remove getHostByName from templates (#11206)** (9b2b830)
- **fix(go): honor go directive when merging go.sum (#11169)** (71190a6)
- **fix: correct grammar and typos in user-facing error messages (#11211)** (a8c8409)
- **fix(misconf): report correct line numbers in multi-document manifests (#11207)** (4eac9a0)
- **fix(server): propagate package modularity label, build info and installed files (#11188)** (bf9f5b7)
- **fix(terraform): do not override --skip-files with --skip-dirs (#11191)** (1c8c54f)
- **fix(license): use canonical SPDX casing for license.id (#11165)** (89d3acf)
- **fix(nodejs): support boolean resolved field in package-lock.json (#11156)** (a2474b8)
- **perf(secret): avoid cloning the logger for every rule (#11133)** (ab3cf86)
- **fix(go): restore stdlib version parsing for vendor-patched Go toolchains (#11119)** (a851889)

### Backend
- **release: v0.75.0 [main] (#11110)** (591e979)

### Tests
- **test: use httptest.NewTestServer for shared test servers (#11138)** (418a7cc)
- **test(misconf): rework the Terraform scanner tests (#11218)** (6bc78c2)
- **test(rapidfort): add integration test for the RapidFort curated image (#11150)** (127db4f)

### Docs
- **docs(sbom): clarify Rekor source compatibility with Cosign (#11323)** (58680c8)
- **docs: clarify community integration listing disclaimer (#11283)** (4fb85a3)
- **docs: add PerspectiveGraph to reporting integrations (#11255)** (ad76a36)
- **docs: link security reporting guidance to relevant documentation (#11235)** (7a6433a)
- **docs(misconf): clarify custom check security considerations (#11278)** (d7708cf)
- **docs: clarify configuration file security considerations (#11209)** (ff327e7)
- **docs(go): explain why go.sum is not scanned for Go 1.17+ modules (#11163)** (38e4258)
- **docs(plugin): clarify plugin permissions and security considerations (#11202)** (bea52ad)
- **docs(terraform): clarify remote module downloads and network access (#11200)** (bb4a5f5)
- **docs(server): clarify client/server security considerations (#11198)** (6d90892)
- **docs(java): recommend mvn install for multi-module Maven projects (#11196)** (f30c208)
- **docs: fix --exclude-namespaces example and a typo in the Terraform tutorial (#11036)** (8fb76b3)
- **docs: define compatibility policy (#11128)** (0aca1c1)
- **docs(vm): mark monolithicSparse as a supported VMDK disk type (#11103)** (6d6f6a9)

### Chore
- **chore: bump SPDX license IDs and exceptions to `v3.29.0` (#11284)** (cb114ec)
- **chore(deps): bump alpine to 3.24.2 (#11309)** (d66087a)
- **chore(alpine): add EOL date for Alpine 3.24 and fix 3.21/3.22 dates (#11308)** (1849d2f)
- **chore(deps): bump github.com/containerd/containerd/v2 from 2.4.0 to 2.4.1 (#11310)** (735e8b1)
- **chore(deps): bump the common group across 1 directory with 4 updates (#11306)** (72df997)
- **chore(deps): bump the github-actions group across 1 directory with 5 updates (#11173)** (544c3cd)
- **chore(deps): bump the testcontainers group across 1 directory with 2 updates (#11130)** (1714537)
- **chore(deps): bump the aws group across 1 directory with 6 updates (#11129)** (5909e4d)
- **chore(deps): bump github.com/docker/cli from 29.8.0+incompatible to 29.8.1+incompatible in the docker group (#11305)** (4bc5cad)
- **chore(deps): bump the docker group across 1 directory with 4 updates (#11266)** (43a9d15)
- **refactor(java): parse MANIFEST.MF attributes by key (#11022)** (9deaeb7)
- **chore(deps): bump the common group across 1 directory with 27 updates (#11267)** (b830ddf)
- **chore(deps): bump github.com/containerd/containerd/v2 from 2.3.3 to 2.3.5 (#11224)** (e4c5d81)
- **refactor(misconf): take the result.new and isManaged built-ins from trivy-checks (#11194)** (3216e57)
- **chore(deps): bump google.golang.org/grpc from 1.83.1 to 1.83.2 (#11212)** (8c90537)
- **chore(deps): bump trivy-checks (#11205)** (af9d510)
- **ci: remove redundant vulnerability scan (#11184)** (99fde13)
- **chore(deps): drop outdated note about spdx/tools-golang version (#11164)** (448887d)
- **chore(deps): bump google.golang.org/grpc from 1.82.1 to 1.83.1 (#11176)** (e000312)
- **refactor: use strings.CutLast and url.URL.Clone from Go 1.27 (#11136)** (dcfb992)
- **refactor: use named constants for JSON token kinds (#11157)** (5ae0bb1)
- **ci: add rapidfort scope to PR title validation (#11151)** (7bd2206)
- **chore: bump Go to 1.27 (#11127)** (dc3c56e)
- **chore(deps): bump github.com/moby/go-archive from 0.2.1 to 0.3.3 (#11123)** (c99f251)
- **ci: add crypto scope to PR title validation (#11111)** (dcbadb7)
- **ci(helm): bump Trivy version to 0.74.0 for Trivy Helm Chart 0.26.0 (#11097)** (d98911e)

_Recap by [Repo Wrapped](https://repowrapped.com/gh/aquasecurity/trivy?utm_source=github-action)._