main
feat(vex): discover OpenVEX in generic in-toto OCI referrers (#10986)
chore(deps): upgrade go-redis from v8 to v9 (#10736)
feat: add support for plugin index (#6674)
feat(java): support user-defined Maven mirrors in trivy.yaml (#11006)
chore: bump go to 1.26.3 (#10683)
refactor: move the aws config (#9617)
feat(db): enable concurrent access to vulnerability database (#9750)
fix(python): normalize dependency names in PEP 621 pyproject.toml (#11050)
refactor(ubuntu): move EOL version resolution out of loop (#11047)
feat(report): add fingerprint generation for vulnerabilities (#9794)
fix(vex): handle 304 status code (#10307)
refactor: add hook interface for extended functionality (#8585)
chore(deps): bump github.com/nikolalohinski/gonja/v2 to v2.9.0 (#11038)
fix: unused-parameter rule from revive (#8794)
docs: fix typos (#10857)
feat(java): detect JAR licenses from packaged LICENSE files (#10856)
chore: bump golangci-lint to v2.12 (#10726)
fix(misconf): prevent path traversal in Terraform filesystem functions (#10664)
chore(deps): replace xeipuuv/gojsonschema and invopop/jsonschema with google/jsonschema-go (#10528)
fix: remove os.Stdout from wazero module config (#10403)
docs: clarify debug logs when version check or telemetry is disabled (#10984)
fix: more revive rules (#8814)
test: close plugin manager in tests cleanup (#10904)
chore: replace deprecated tenv linter with usetesting (#8504)
refactor: allow per-request transport options override (#10083)
fix(misconf): apply check aliases when filtering results via .trivyignore (#10112)
refactor(vuln): add OS.Supplier field and unify supplier terminology (#11007)
fix: correct format verbs in diagnostic messages (#10805)
feat(fs): optimize scanning performance by direct file access for known paths (#8525)
fix: use canonical SPDX license IDs from embeded licenses.json (#10053)
fix(nodejs): silently skip subdirectory package.json files with invalid names (#10609)
feat(report): switch ReportID from UUIDv4 to UUIDv7 (#9749)
feat(server): include server version info in JSON output for client/server mode (#10075)
fix(vuln): fall back to UNKNOWN severity when vulnerability details are missing (#10795)
feat: add bounded read helpers (#10974)