# Trivy changelog > A comprehensive security scanner for containers, code repositories and clouds. - Vendor: Aqua Security - Category: Developer Tools - Official site: https://trivy.dev - Tracked by: What's New (https://whatsnew.fyi/product/trivy) - Harvested from: GitHub (aquasecurity/trivy) - Entries below: 10 (newest first) What's New is an index, not a publisher: every entry below links to the vendor's own release notes, which are the authoritative source. Entries are labelled where they are hand-curated sample data, pre-releases, or drawn from a secondary source such as a developer blog. Reuse: the summaries, labels and curation here are © What's New. Quote freely with attribution and a link back; wholesale republication of the corpus is not permitted — terms: https://whatsnew.fyi/terms. The vendors' own release notes remain their publishers'. ## Releases ### v0.73.0 - Date: 2026-08-03 - Version: v0.73.0 - Original notes: https://github.com/aquasecurity/trivy/releases/tag/v0.73.0 - Permalink: https://whatsnew.fyi/product/trivy/releases/v0.73.0 - **added** — Add support for detecting vulnerabilities in Dart/Flutter packages - **added** — Add Kubernetes config scanner support - **added** — Add SBOM generation for container images - **changed** — Improve performance of vulnerability scanning for large images - **fixed** — Fix false positives in Java dependency detection - **fixed** — Fix handling of Python packages with complex version specifiers ##### ⚡ Highlights ⚡ 👉 https://github.com/aquasecurity/trivy/discussions/11033 ##### Changelog https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md#0730-2026-08-03 ### v0.72.0 - Date: 2026-06-30 - Version: v0.72.0 - Original notes: https://github.com/aquasecurity/trivy/releases/tag/v0.72.0 - Permalink: https://whatsnew.fyi/product/trivy/releases/v0.72.0 ##### ⚡ Highlights ⚡ 👉 https://github.com/aquasecurity/trivy/discussions/10907 ##### Changelog https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md#0720-2026-06-30 ### v0.71.2 - Date: 2026-06-19 - Version: v0.71.2 - Original notes: https://github.com/aquasecurity/trivy/releases/tag/v0.71.2 - Permalink: https://whatsnew.fyi/product/trivy/releases/v0.71.2 - **fixed** — Bump alpine to 3.24.1 - **changed** — Update common dependencies ##### Changelog * 055a5c8a53bfd61f7a8e276a5b2f0c3fc1673420 release: v0.71.2 [release/v0.71] (#10871) * 875328a4138f26e8559cfee80adaef82b6693076 fix(deps): bump alpine to 3.24.1 [backport: release/v0.71] (#10870) * 998f7b3c3f3c9de2132bc4358970eeafbd797fba chore(deps): bump the common group with 4 updates [backport: release/v0.71] (#10867) ### v0.71.1 - Date: 2026-06-15 - Version: v0.71.1 - Original notes: https://github.com/aquasecurity/trivy/releases/tag/v0.71.1 - Permalink: https://whatsnew.fyi/product/trivy/releases/v0.71.1 - **fixed** — Validate artifact filename in OCI - **fixed** — Forward ospkg detector options through ospkg.NewScanner - **fixed** — Load VEX documents from within the repository directory - **fixed** — Surface the original analysis error instead of context cancellation ##### Changelog * 164b383121351c2d49c5d354c2245719d972752b release: v0.71.1 [release/v0.71] (#10818) * a72d9a4d997c25fbb6534e231b4e206c9b202b31 fix(oci): validate artifact filename * 3dd98471dfbbc4a95edd5cd866468d3a8c87fd17 fix: forward ospkg detector options through ospkg.NewScanner [backport: release/v0.71] (#10825) * a62cbe40a240d3a3f568401b8a5f86e14114e371 fix(vex): load VEX documents from within the repository directory [backport: release/v0.71] (#10821) * 43d1d2628725e913db110b89419f0bebd36f58a8 fix: surface the original analysis error instead of context cancellation [backport: release/v0.71] (#10812) * ac7696c7b50d633183ce2ff44898d4b5c6eae565 ci: expect GitHub App bot as backport PR author [backport: release/v0.71] (#10815) ### v0.71.0 - Date: 2026-06-01 - Version: v0.71.0 - Original notes: https://github.com/aquasecurity/trivy/releases/tag/v0.71.0 - Permalink: https://whatsnew.fyi/product/trivy/releases/v0.71.0 - **added** — Support for scanning and detecting vulnerabilities in Kubernetes workloads - **added** — New integration with additional container registries for artifact scanning - **changed** — Improved performance for large-scale vulnerability database queries - **fixed** — Resolved issues with SBOM generation for certain container image formats - **changed** — Enhanced filtering options for vulnerability reports ##### ⚡ Highlights ⚡ 👉 https://github.com/aquasecurity/trivy/discussions/10767 ##### Changelog https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md#0710-2026-06-01 ### v0.70.0 - Date: 2026-04-17 - Version: v0.70.0 - Original notes: https://github.com/aquasecurity/trivy/releases/tag/v0.70.0 - Permalink: https://whatsnew.fyi/product/trivy/releases/v0.70.0 ##### ⚡ Highlights ⚡ 👉 https://github.com/aquasecurity/trivy/discussions/10546 ##### Changelog https://github.com/aquasecurity/trivy/blob/main/CHANGELOG.md#0700-2026-04-16 ### v0.69.3 - Date: 2026-03-03 - Version: v0.69.3 - Original notes: https://github.com/aquasecurity/trivy/releases/tag/v0.69.3 - Permalink: https://whatsnew.fyi/product/trivy/releases/v0.69.3 - **fixed** — Bump github.com/go-git/go-git/v5 from 5.16.4 to 5.16.5 ##### Changelog * 6fb20c8edd70745d6b34bff0387b53b03c8a760a release: v0.69.3 [release/v0.69] (#10293) * dabefec57d099184bc8bd268dea23cd5d502f9cc fix(deps): bump github.com/go-git/go-git/v5 from 5.16.4 to 5.16.5 [backport: release/v0.69] (#10291) ### v0.69.2 - Date: 2026-03-01 - Version: v0.69.2 - Original notes: https://github.com/aquasecurity/trivy/releases/tag/v0.69.2 - Permalink: https://whatsnew.fyi/product/trivy/releases/v0.69.2 - **fixed** — Bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 - **fixed** — Bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 ##### Changelog * cfa322ed23f2e33ef1632ae3a5a8c7172f06a5c3 release: v0.69.2 [release/v0.69] (#10266) * 86debce0f4897e9501368fe0611c5ae472a141eb fix(deps): bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 [backport: release/v0.69] (#10267) * cf3d4cd6a8bdf5b5b1d701f591bd8aaabd2c7c27 fix(deps): bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 [backport: release/v0.69] (#10264) * 6dfd3b078b95d30e812e04f13fd1cac7e08f9b4e ci: remove apidiff workflow ### v0.26.0 - Date: 2022-04-15 - Version: v0.26.0 - Original notes: https://github.com/aquasecurity/trivy/releases/tag/v0.26.0 - Permalink: https://whatsnew.fyi/product/trivy/releases/v0.26.0 - **added** — Warn when mixing Alpine versions - **changed** — Update ASFF template - **changed** — Replace containerd/containerd version to fix CVE-2022-23648 - **fixed** — Fix panic when scanning .egg archive in Python - **fixed** — Set correct go modules type - **added** — Support apk repositories for Alpine - **added** — Support go.mod in Go 1.17+ ##### Changelog * a0047a79 feat(alpine): warn mixing versions (#2000) * d786655a Update ASFF template (#1914) * a02cf651 chore(deps): replace `containerd/containerd` version to fix CVE-2022-23648 (#1994) * 613e38cc chore(deps): bump alpine from 3.15.3 to 3.15.4 (#1993) * 3b6d65be test(go): add integration tests for gomod (#1989) * 22f5b938 fix(python): fixed panic when scan .egg archive (#1992) * 485637c2 fix(go): set correct go modules type (#1990) * 6fdb554a feat(alpine): support apk repositories (#1987) * d9bddb90 docs: add CBL-Mariner (#1982) * 1cf1873f docs(go): fix version (#1986) * d77dbe8a feat(go): support go.mod in Go 1.17+ (#1985) * 32bd1e48 ci: fix URLs in the PR template (#1972) * 94a5a180 ci: add semantic pull requests check (#1968) * 72d94b21 docs(issue): added docs for wrong detection issues (#1961) ### v0.25.4 - Date: 2022-04-11 - Version: v0.25.4 - Original notes: https://github.com/aquasecurity/trivy/releases/tag/v0.25.4 - Permalink: https://whatsnew.fyi/product/trivy/releases/v0.25.4 - **fixed** — Add --db-repository flag to SBOM functionality - **added** — Add PkgPath in table result - **changed** — Use file name instead of package path in table output - **fixed** — Merge multiple pom imports in a better manner ##### Changelog * b4a7d6a8 docs: move CONTRIBUTING.md to docs (#1971) * 0127c1d3 refactor(table): use file name instead package path (#1966) * a92da722 fix(sbom): add --db-repository (#1964) * b0f3864e feat(table): add PkgPath in table result (#1960) * 0b1d32c1 fix(pom): merge multiple pom imports in a good manner (#1959)