This update for trivy fixes the following issues:
Update to version 0.58.2 (
boo#1234512, CVE-2024-45337, boo#1235265, CVE-2024-45338):
* fix(misconf): allow null values only for tf variables [backport:
release/v0.58] (#8238)
* fix(suse): SUSE - update OSType constants and references for
compatility [backport: release/v0.58] (#8237)
* fix: CVE-2025-21613 and CVE-2025-21614 : go-git: argument injection
via the URL field [backport: release/v0.58] (#8215)
* fix(sbom): attach nested packages to Application [backport:
release/v0.58] (#8168)
* fix(python): skip dev group's deps for poetry [backport:
release/v0.58] (#8158)
* fix(sbom): use root package for `unknown` dependencies (if exists)
[backport: release/v0.58] (#8156)
* chore(deps): bump `golang.org/x/net` from `v0.32.0` to `v0.33.0`
[backport: release/v0.58] (#8142)
* chore(deps): bump `github.com/CycloneDX/cyclonedx-go` from...
Read the Full AdvisoryPatch Instructions:
To install this openSUSE Security Update use the SUSE recommended installation methods
like YaST online_update or "zypper patch".
Alternatively you can run the command listed for your product:
- openSUSE Backports SLE-15-SP6:
zypper in -t patch openSUSE-2025-56=1
- openSUSE Backports SLE-15-SP6 (aarch64 i586 ppc64le s390x x86_64):
trivy-0.58.2-bp156.2.6.1
https://www.suse.com/security/cve/CVE-2024-34155.html
https://www.suse.com/security/cve/CVE-2024-34156.html
https://www.suse.com/security/cve/CVE-2024-34158.html
https://www.suse.com/security/cve/CVE-2024-3817.html
https://www.suse.com/security/cve/CVE-2024-45337.html
https://www.suse.com/security/cve/CVE-2024-45338.html
https://www.suse.com/security/cve/CVE-2025-21613.html
https://www.suse.com/security/cve/CVE-2025-21614.html
https://bugzilla.suse.com/show_bug.cgi?id=1227010
https://bugzilla.suse.com/show_bug.cgi?id=1234512
https://bugzilla.suse.com/show_bug.cgi?id=1235265