microsoft / security-devops-azdevops

Microsoft Security DevOps extension for Azure DevOps.
MIT License
60 stars 16 forks source link

Trivy version is very out of date #50

Closed dmakovec-astralas closed 1 year ago

dmakovec-astralas commented 1 year ago

The tool currently uses Trivy v0.19.2, which is 2 years old. Can it please be updated to something more recent, current version being 0.41.0 ?

boAndron commented 1 year ago

An update to 0.38.1 is coming soon (next 2 weeks we hope), with more updates planned. Thanks!

JamesChristianson commented 11 months ago

The version is still out of date (v0.19.2). This is causing issues because apps using package-lock.json lockfileVersion: 3 , are not supported and vulnerabilities aren't found.