Skip to content
Draft
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
29 commits
Select commit Hold shift + click to select a range
10a487a
chore(chart-deps): update trivy-operator to version 0.34.0
svcAPLBot Jul 9, 2026
0527267
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 9, 2026
6127f0f
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 10, 2026
6a8b977
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 13, 2026
3542254
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 15, 2026
459f018
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 16, 2026
3a30fec
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 20, 2026
b0eda9c
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 21, 2026
99323b4
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 21, 2026
2577aa6
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 22, 2026
a5c12dd
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 27, 2026
4311a91
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 28, 2026
78d0bc5
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 28, 2026
890ae21
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 28, 2026
22ae00c
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 28, 2026
26e53fd
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 28, 2026
aa85924
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 29, 2026
37137c0
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 29, 2026
c229051
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 29, 2026
ac94b91
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 29, 2026
feb9333
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 30, 2026
06ed42c
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Jul 31, 2026
035479f
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Aug 3, 2026
c2175b6
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Aug 3, 2026
55da3e9
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Aug 4, 2026
2a6168a
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Aug 4, 2026
33cbdcd
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Aug 4, 2026
893e39b
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Aug 4, 2026
36c4640
Merge branch 'main' into ci-update-trivy-operator-to-0.34.0
svcAPLBot Aug 5, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
2 changes: 1 addition & 1 deletion apps.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -208,7 +208,7 @@ appsInfo:
integration: App Platform uses Sealed Secrets to provide a secure way to store Kubernetes secrets in Git repositories. Sealed Secrets can be used to store secrets in the values repository.
trivy:
title: Trivy Operator
appVersion: 0.30.1
appVersion: 0.32.0
repo: https://github.com/aquasecurity/trivy-operator
maintainers: Aqua Security
relatedLinks:
Expand Down
2 changes: 1 addition & 1 deletion chart/chart-index/Chart.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -112,5 +112,5 @@ dependencies:
version: 1.12.0
repository: https://cdfoundation.github.io/tekton-helm-chart/
- name: trivy-operator
version: 0.32.1
version: 0.34.0
repository: https://aquasecurity.github.io/helm-charts/
4 changes: 2 additions & 2 deletions charts/trivy-operator/Chart.yaml
Original file line number Diff line number Diff line change
@@ -1,5 +1,5 @@
apiVersion: v2
appVersion: 0.30.1
appVersion: 0.32.0
description: Keeps security report resources updated
keywords:
- aquasecurity
Expand All @@ -9,4 +9,4 @@ name: trivy-operator
sources:
- https://github.com/aquasecurity/trivy-operator
type: application
version: 0.32.1
version: 0.34.0
6 changes: 3 additions & 3 deletions charts/trivy-operator/README.md
Original file line number Diff line number Diff line change
@@ -1,6 +1,6 @@
# trivy-operator

![Version: 0.32.1](https://img.shields.io/badge/Version-0.32.1-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 0.30.1](https://img.shields.io/badge/AppVersion-0.30.1-informational?style=flat-square)
![Version: 0.34.0](https://img.shields.io/badge/Version-0.34.0-informational?style=flat-square) ![Type: application](https://img.shields.io/badge/Type-application-informational?style=flat-square) ![AppVersion: 0.32.0](https://img.shields.io/badge/AppVersion-0.32.0-informational?style=flat-square)

Keeps security report resources updated

Expand Down Expand Up @@ -153,7 +153,7 @@ Keeps security report resources updated
| trivy.image.pullPolicy | string | `"IfNotPresent"` | pullPolicy is the imge pull policy used for trivy image , valid values are (Always, Never, IfNotPresent) |
| trivy.image.registry | string | `"mirror.gcr.io"` | registry of the Trivy image |
| trivy.image.repository | string | `"aquasec/trivy"` | repository of the Trivy image |
| trivy.image.tag | string | `"0.69.3"` | tag version of the Trivy image |
| trivy.image.tag | string | `"0.72.0"` | tag version of the Trivy image |
| trivy.imageScanCacheDir | string | `"/tmp/trivy/.cache"` | imageScanCacheDir the flag to set custom path for trivy image scan `cache-dir` parameter. Only applicable in image scan mode. |
| trivy.includeDevDeps | bool | `false` | includeDevDeps include development dependencies in the report (supported: npm, yarn) (default: false) note: this flag is only applicable when trivy.command is set to filesystem |
| trivy.insecureRegistries | object | `{}` | The registry to which insecure connections are allowed. There can be multiple registries with different keys. |
Expand Down Expand Up @@ -190,7 +190,7 @@ Keeps security report resources updated
| trivy.storageClassEnabled | bool | `true` | whether to use a storage class for trivy server or emptydir (one mey want to use ephemeral storage) |
| trivy.storageClassName | string | `""` | storageClassName is the name of the storage class to be used for trivy server PVC. If empty, tries to find default storage class |
| trivy.storageSize | string | `"5Gi"` | storageSize is the size of the trivy server PVC |
| trivy.supportedConfigAuditKinds | string | `"Workload,Service,Role,ClusterRole,NetworkPolicy,Ingress,LimitRange,ResourceQuota"` | The Flag is the list of supported kinds separated by comma delimiter to be scanned by the config audit scanner |
| trivy.supportedConfigAuditKinds | string | `"Workload,Service,Role,ClusterRole,NetworkPolicy,Ingress,LimitRange,ResourceQuota,PersistentVolume,PersistentVolumeClaim"` | The Flag is the list of supported kinds separated by comma delimiter to be scanned by the config audit scanner |
| trivy.timeout | string | `"5m0s"` | timeout is the duration to wait for scan completion. |
| trivy.useBuiltinRegoPolicies | string | `"false"` | The Flag to enable the usage of builtin rego policies by default, these policies are downloaded by default from mirror.gcr.io/aquasec/trivy-checks |
| trivy.useEmbeddedRegoPolicies | string | `"true"` | To enable the usage of embedded rego policies, set the flag useEmbeddedRegoPolicies. This should serve as a fallback for air-gapped environments. When useEmbeddedRegoPolicies is set to true, useBuiltinRegoPolicies should be set to false. |
Expand Down
2 changes: 2 additions & 0 deletions charts/trivy-operator/generated/role.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -10,6 +10,8 @@ rules:
- configmaps
- limitranges
- nodes
- persistentvolumeclaims
- persistentvolumes
- pods
- replicationcontrollers
- resourcequotas
Expand Down
2 changes: 1 addition & 1 deletion charts/trivy-operator/templates/specs/eks-cis-1.4.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
labels:
app.kubernetes.io/name: trivy-operator
app.kubernetes.io/instance: trivy-operator
app.kubernetes.io/version: 0.30.1
app.kubernetes.io/version: 0.32.0
app.kubernetes.io/managed-by: kubectl
Comment on lines 6 to 10
spec:
cron: {{ .Values.compliance.cron | quote }}
Expand Down
2 changes: 1 addition & 1 deletion charts/trivy-operator/templates/specs/k8s-cis-1.23.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,7 +6,7 @@ metadata:
labels:
app.kubernetes.io/name: trivy-operator
app.kubernetes.io/instance: trivy-operator
app.kubernetes.io/version: 0.30.1
app.kubernetes.io/version: 0.32.0
app.kubernetes.io/managed-by: kubectl
Comment on lines 6 to 10
spec:
cron: {{ .Values.compliance.cron | quote }}
Expand Down
2 changes: 1 addition & 1 deletion charts/trivy-operator/templates/specs/k8s-nsa-1.0.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ metadata:
labels:
app.kubernetes.io/name: trivy-operator
app.kubernetes.io/instance: trivy-operator
app.kubernetes.io/version: 0.30.1
app.kubernetes.io/version: 0.32.0
app.kubernetes.io/managed-by: kubectl
Comment on lines 7 to 11
spec:
cron: {{ .Values.compliance.cron | quote}}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ metadata:
labels:
app.kubernetes.io/name: trivy-operator
app.kubernetes.io/instance: trivy-operator
app.kubernetes.io/version: 0.30.1
app.kubernetes.io/version: 0.32.0
app.kubernetes.io/managed-by: kubectl
Comment on lines 7 to 11
spec:
cron: {{ .Values.compliance.cron | quote}}
Expand Down
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ metadata:
labels:
app.kubernetes.io/name: trivy-operator
app.kubernetes.io/instance: trivy-operator
app.kubernetes.io/version: 0.30.1
app.kubernetes.io/version: 0.32.0
app.kubernetes.io/managed-by: kubectl
Comment on lines 7 to 11
spec:
cron: {{ .Values.compliance.cron | quote}}
Expand Down
2 changes: 1 addition & 1 deletion charts/trivy-operator/templates/specs/rke2-cis-1.24.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -7,7 +7,7 @@ metadata:
labels:
app.kubernetes.io/name: trivy-operator
app.kubernetes.io/instance: trivy-operator
app.kubernetes.io/version: 0.30.1
app.kubernetes.io/version: 0.32.0
app.kubernetes.io/managed-by: kubectl
Comment on lines 7 to 11
spec:
cron: {{ .Values.compliance.cron | quote}}
Expand Down
4 changes: 2 additions & 2 deletions charts/trivy-operator/values.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -360,7 +360,7 @@ trivy:
# -- repository of the Trivy image
repository: aquasec/trivy
# -- tag version of the Trivy image
tag: 0.69.3
tag: 0.72.0
# -- imagePullSecret is the secret name to be used when pulling trivy image from private registries example : reg-secret
# It is the user responsibility to create the secret for the private registry in `trivy-operator` namespace
imagePullSecret: ~
Expand Down Expand Up @@ -581,7 +581,7 @@ trivy:

# -- The Flag is the list of supported kinds separated by comma delimiter to be scanned by the config audit scanner
#
supportedConfigAuditKinds: "Workload,Service,Role,ClusterRole,NetworkPolicy,Ingress,LimitRange,ResourceQuota"
supportedConfigAuditKinds: "Workload,Service,Role,ClusterRole,NetworkPolicy,Ingress,LimitRange,ResourceQuota,PersistentVolume,PersistentVolumeClaim"

# -- command. One of `image`, `filesystem` or `rootfs` scanning, depending on the target type required for the scan.
# For 'filesystem' and `rootfs` scanning, ensure that the `trivyOperator.scanJobPodTemplateContainerSecurityContext` is configured
Expand Down
Loading