SUSE-CU-2026:9142-1: Security update of private-registry/harbor-trivy-adapter

sle-container-updates at lists.suse.com sle-container-updates at lists.suse.com
Tue Aug 25 07:08:13 UTC 2026


SUSE Container Update Advisory: private-registry/harbor-trivy-adapter
-----------------------------------------------------------------
Container Advisory ID : SUSE-CU-2026:9142-1
Container Tags        : private-registry/harbor-trivy-adapter:1.1.3 , private-registry/harbor-trivy-adapter:1.1.3-2.104 , private-registry/harbor-trivy-adapter:latest
Container Release     : 2.104
Severity              : moderate
Type                  : security
References            : 1276128 CVE-2026-72815 CVE-2026-72816 CVE-2026-72817 
-----------------------------------------------------------------

The container private-registry/harbor-trivy-adapter was updated. The following patches have been included in this update:

-----------------------------------------------------------------
Advisory ID: SUSE-SU-2026:3763-1
Released:    Mon Aug 24 20:26:59 2026
Summary:     Security update for trivy
Type:        security
Severity:    moderate
References:  1276128,CVE-2026-72815,CVE-2026-72816,CVE-2026-72817
This update for trivy fixes the following issue:

- CVE-2026-72815,CVE-2026-72816,CVE-2026-72817: github.com/go-chi/chi/v5: multiple IP spoofing vulnerabilities allow
  authentication bypass, authorization override, and log forgery (bsc#1276128).

Changes for trivy:

- Update to version 0.74.0:
 * release: v0.74.0 [main] (#11037)
 * chore(deps): update golang.org/x modules (#11094)
 * chore(deps): bump the docker group with 2 updates (#11090)
 * docs: update release branch ruleset instructions (#11093)
 * chore(deps): bump the common group across 1 directory with 7 updates (#11086)
 * fix(misconf): unmark cty values outside the evaluation context (#11078)
 * chore(deps): bump the aws group across 1 directory with 6 updates (#11053)
 * fix(misconf): parse Azure flexible server parameters under their own names (#11072)
 * chore(deps): bump the docker group with 2 updates (#11054)
 * feat: add RapidFort curated image scanner (#10452)
 * feat(java): resolve JAR license URLs to SPDX IDs (Bundle-License, pom <url>) (#10948)
 * refactor(misconf): remove unused Azure expression-related code (#10637)
 * fix(server): preserve check aliases and query in uploaded blobs (#11080)
 * fix(java): read artifact properties only from the MANIFEST.MF main section (#11066)
 * fix(terraform): support OpenTofu language block (#10923)
 * chore(deps): bump github.com/go-git/go-git/v5 from 5.19.1 to 5.19.2 (#11063)
 * ci: trigger Auto Ready for Review after Test docs (#11045)
 * docs: remove trivy-checks from AWS ECR locations (#11044)
 * refactor(ubuntu): move EOL version resolution out of loop (#11047)
 * fix(python): normalize dependency names in PEP 621 pyproject.toml (#11050)
 * chore(deps): bump oras.land/oras-go/v2 from 2.6.1 to 2.6.2 (#11042)
 * chore(deps): bump github.com/nikolalohinski/gonja/v2 to v2.9.0 (#11038)
 * fix(terraform): avoid panic when for_each local has unknown object values (#11019)
 * chore(deps): bump the github-actions group across 2 directories with 15 updates (#11028)
 * ci(spdx): migrate to Slack notifications (#11032)
 * ci(helm): bump Trivy version to 0.73.0 for Trivy Helm Chart 0.25.0 (#11034)
- Update to version 0.73.0 
 * release: v0.73.0 [main] (#11012)
 * docs: clarify debug logs when version check or telemetry is disabled (#10984)
 * feat(java): support user-defined Maven mirrors in trivy.yaml (#11006)
 * chore(deps): bump the common group across 1 directory with 17 updates (#11025)
 * chore(deps): bump the docker group across 1 directory with 2 updates (#10991)
 * chore(deps): bump the aws group across 1 directory with 6 updates (#10947)
 * refactor(alpine): remove type assertion when reading the APKINDEX archive (#11013)
 * chore(deps): bump google.golang.org/grpc from 1.81.1 to 1.82.1 (#10995)
 * feat(vex): discover OpenVEX in generic in-toto OCI referrers (#10986)
 * refactor(vuln): add OS.Supplier field and unify supplier terminology (#11007)
 * chore(deps): bump github.com/google/cel-go from 0.28.1 to 0.30.0 (#11009)
 * fix(vex): reject non-local VEX repository names (#10987)
 * fix(vex): handle 304 status code (#10307)
 * fix(vuln): don't skip packages covered by a driver's own advisory feed (#10980)
 * fix(conda): avoid panic on an all-operator dependency line (#10955)
 * chore: add schema id (#10969)
 * feat(vex): native discovery of VEX documents stored as OCI artifacts (#10932)
 * feat: add bounded read helpers (#10974)
 * fix(dotnet): identify deps.json root project from dependency graph (#10954)
 * feat(java): read Jenkins plugin manifest licenses (#10939)
 * docs: ask contributors to coordinate before starting on an issue (#10940)
 * fix(nodejs): support pnpm workspaces with overlapping packages (#10894)
 * ci: create release branch with the App token to bypass the merge queue rule (#10931)
 * chore(deps): bump the common group across 1 directory with 15 updates (#10892)
 * feat(seal): detect no-prefix packages by version suffix (#10911)
 * chore(deps): bump the testcontainers group with 2 updates (#10918)
 * chore(deps): bump the docker group across 1 directory with 4 updates (#10919)
 * fix(java): set per-file digest for nested JARs (#10855)
 * fix(misconf): guard nil Healthcheck when building Dockerfile from history (#10899)
 * ci(helm): bump Trivy version to 0.72.0 for Trivy Helm Chart 0.24.0 (#10908)
 * ci(helm): allow trivy team to approve Chart.yaml bumps (#10912)


The following package changes have been done:

- trivy-0.74.0-150000.1.30.1 updated
- container:suse-sle15-15.7-4de2a562289c9545ddd1e888292b3fa87a6156d62d9bb6f2574c92a9e0e8fe98-0 updated


More information about the sle-container-updates mailing list