Skip to content

chore(docker): bump the docker group across 1 directory with 4 updates - #48

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker/versions/docker-708c9db61b
Open

chore(docker): bump the docker group across 1 directory with 4 updates#48
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/docker/versions/docker-708c9db61b

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 7, 2026

Copy link
Copy Markdown

Warning

Cooldown could not be applied because no publication date was available from the registry.

Bumps the docker group with 4 updates in the /versions directory: trufflesecurity/trufflehog, anchore/syft, anchore/grype and semgrep/semgrep.

Updates trufflesecurity/trufflehog from 3.95.2 to 3.97.4

Release notes

Sourced from trufflesecurity/trufflehog's releases.

v3.97.4

What's Changed

Full Changelog: trufflesecurity/trufflehog@v3.97.3...v3.97.4

v3.97.3

What's Changed

Full Changelog: trufflesecurity/trufflehog@v3.97.2...v3.97.3

v3.97.2

What's Changed

New Contributors

Full Changelog: trufflesecurity/trufflehog@v3.97.1...v3.97.2

v3.97.1

What's Changed

... (truncated)

Commits
  • 363923b added tests for twilio detector fixes (#5271)
  • f537081 Improve the json-enumerator source (#5265)
  • 8a9a4c6 Made retry exaustion indeterminate for Twilio secrets and twilioapikeys (#5267)
  • 8947a7f Revert "De-base64 SourceUnit.UnitData in the GitHub Source (#5248)" (#5269)
  • ea33cd0 fix(s3): cut a child context per object so key/size log values don't pile up ...
  • cc1fe98 Retry git clone on secondary rate limit (bare 403/429) (#5260)
  • 74dcf3f Update link to Truffle Security documentation (#5256)
  • 2b75fd2 Implement Enumerate for the Jenkins source (#5229)
  • 0c952ac De-base64 SourceUnit.UnitData in the GitHub Source (#5248)
  • 1ea7fc1 expand result code in pagerduty detector (#5230)
  • Additional commits viewable in compare view

Updates anchore/syft from v1.44.0 to v1.51.1

Release notes

Sourced from anchore/syft's releases.

v1.51.1

Bug Fixes

Additional Changes

  • gzip binary classifier reports false-positive GNU gzip from BusyBox multicall binary via applet symlink [Issue #5171] [PR #5202 @​spiffcs]
  • pnpm v5 lockfile: underscore peer-dep suffixes are not stripped from package versions [Issue #5174] [PR #5175 @​codeAnqiang-ma]
  • pnpm cataloger reads only the first YAML document: SBOM contains pnpm's own binaries and no project dependencies [Issue #5168] [PR #5188 @​hamodywe]

Dependencies

72 dependency changes (70 updated, 1 added, 1 removed). 3 vulnerabilities remediated.

🟢 Remediated (3)

  • cel.dev/expr v0.25.1v0.25.2
  • cloud.google.com/go/auth v0.18.2v0.22.0
  • cloud.google.com/go/iam v1.5.3v1.11.0
  • cloud.google.com/go/logging v1.13.1v1.18.0
  • cloud.google.com/go/longrunning v0.8.0v1.2.0
  • cloud.google.com/go/monitoring v1.24.3v1.29.0
  • cloud.google.com/go/storage v1.61.3v1.64.0
  • cloud.google.com/go/trace v1.11.7v1.16.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.32.0v1.33.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.55.0v0.57.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock v0.55.0v0.57.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0v0.57.0
  • github.com/anchore/stereoscope v0.3.0v0.3.1

... (truncated)

Commits
  • 91a0032 chore(deps): update anchore dependencies (#5085)
  • f91bf45 fix: correct Apache Derby group ID in purl generation (#5090)
  • c5fc699 chore(deps): update CPE dictionary index (#5221)
  • d3734dd fix(binary): detect grafana security-patch release versions (#5213)
  • bf82010 fix(lua): skip rockspec with no package name (#4825)
  • 7ca1f22 fix(dotnet): correct inverted dependency-of relationship direction in package...
  • 93cf893 fix(rpm): keep the epoch when parsing RPM manifest packages (#5201)
  • 34ef7dc chore(deps): bump golang.org/x/mod from 0.39.0 to 0.40.0 (#5208)
  • 29edf90 chore(deps): bump github.com/hashicorp/go-getter from 1.8.6 to 1.8.8 (#5207)
  • 766907e chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0 (#5206)
  • Additional commits viewable in compare view

Updates anchore/grype from v0.112.0 to v0.118.0

Release notes

Sourced from anchore/grype's releases.

v0.118.0

Added Features

Bug Fixes

  • prevent panic on portage versions without digits [PR #3655 @​ashvinctrl]
  • grype vex does not match oci purl with repository_url [Issue #3657] [PR #3659 @​spiffcs]
  • Old JVM version comparisons sometimes incorrect [Issue #2701] [PR #3583 @​Eljees]
  • CVSSv4 calculation can produce incorrect vulnerability severity [Issue #3656]
  • Grype 0.90.0 DB update failed [Issue #3629]

Dependencies

72 dependency changes (70 updated, 1 added, 1 removed). 3 vulnerabilities remediated.

🟢 Remediated (3)

  • cel.dev/expr v0.25.1v0.25.2
  • cloud.google.com/go/auth v0.18.2v0.22.0
  • cloud.google.com/go/iam v1.5.3v1.11.0
  • cloud.google.com/go/logging v1.13.1v1.18.0
  • cloud.google.com/go/longrunning v0.8.0v1.2.0
  • cloud.google.com/go/monitoring v1.24.3v1.29.0
  • cloud.google.com/go/storage v1.61.3v1.64.0
  • cloud.google.com/go/trace v1.11.7v1.16.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.32.0v1.33.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.55.0v0.57.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock v0.55.0v0.57.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0v0.57.0
  • github.com/anchore/stereoscope v0.3.0v0.3.1
  • github.com/anchore/syft v1.51.0v1.51.1
  • github.com/aws/aws-sdk-go-v2 v1.41.5v1.43.4
  • github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.8v1.7.16
  • github.com/aws/aws-sdk-go-v2/config v1.32.12v1.32.35
  • github.com/aws/aws-sdk-go-v2/credentials v1.19.12v1.19.34
  • github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.20v1.18.35
  • github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.21v1.4.35
  • github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.21v2.7.35
  • github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.22v1.4.36
  • github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.7v1.13.15
  • github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.13v1.9.28

... (truncated)

Commits
  • 756eb9a chore(deps): update anchore dependencies (#3648)
  • 9963eb7 fix(bug): package_url mismatchs vex document on namespace/name (#3659)
  • 8b1354c fix: normalize "u" update shorthand in pre-JEP 223 JVM versions (#3583)
  • 0f57388 feat(apk/matcher): apk matcher does alias aware aggregation (#3634)
  • 0ee65de fix(version): prevent panic on portage versions without digits (#3655)
  • 2739bfa chore: update the stdin subprocess tests (#3661)
  • ab6707d chore(deps): bump golang.org/x/text from 0.40.0 to 0.41.0 (#3668)
  • ffbca56 chore(deps): bump github.com/google/go-containerregistry (#3651)
  • fd366aa chore(deps): bump zizmorcore/zizmor-action from 0.6.0 to 0.6.2 (#3650)
  • b5fa92b chore(deps): update anchore dependencies (#3610)
  • Additional commits viewable in compare view

Updates semgrep/semgrep from 1.161.0 to 1.175.1

You can trigger a rebase of this PR by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

Bumps the docker group with 4 updates in the /versions directory: [trufflesecurity/trufflehog](https://github.com/trufflesecurity/trufflehog), [anchore/syft](https://github.com/anchore/syft), [anchore/grype](https://github.com/anchore/grype) and semgrep/semgrep.


Updates `trufflesecurity/trufflehog` from 3.95.2 to 3.97.4
- [Release notes](https://github.com/trufflesecurity/trufflehog/releases)
- [Commits](trufflesecurity/trufflehog@v3.95.2...v3.97.4)

Updates `anchore/syft` from v1.44.0 to v1.51.1
- [Release notes](https://github.com/anchore/syft/releases)
- [Changelog](https://github.com/anchore/syft/blob/main/RELEASE.md)
- [Commits](anchore/syft@v1.44.0...v1.51.1)

Updates `anchore/grype` from v0.112.0 to v0.118.0
- [Release notes](https://github.com/anchore/grype/releases)
- [Changelog](https://github.com/anchore/grype/blob/main/RELEASE.md)
- [Commits](anchore/grype@v0.112.0...v0.118.0)

Updates `semgrep/semgrep` from 1.161.0 to 1.175.1

---
updated-dependencies:
- dependency-name: trufflesecurity/trufflehog
  dependency-version: 3.97.4
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: docker
- dependency-name: anchore/syft
  dependency-version: v1.51.1
  dependency-type: direct:production
  dependency-group: docker
- dependency-name: anchore/grype
  dependency-version: v0.118.0
  dependency-type: direct:production
  dependency-group: docker
- dependency-name: semgrep/semgrep
  dependency-version: 1.175.1
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: docker
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file docker Pull requests that update Docker base images labels Sep 7, 2026
@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

Security Scan Results

Repository: actions | Commit: cda4d0e

Check Status Details
✅ Secret Scan Pass No secrets detected
⏩ Dependencies Skipped -

Scanned at 2026-09-07 09:19 UTC

@github-actions

github-actions Bot commented Sep 7, 2026

Copy link
Copy Markdown

Semgrep Scan Results

Repository: actions | Commit: cda4d0e

Check Status Details
✅ Semgrep Pass 0 total findings (no error/warning)

Scanned at 2026-09-07 09:19 UTC

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file docker Pull requests that update Docker base images

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants