What aquasecurity/trivy shipped
Written by FoxPlug from public releases; not affiliated with Aqua Security. An automatic summary of the public release, pull request and commit data of github.com/aquasecurity/trivy. Aqua Security did not write it and does not use or endorse FoxPlug. Every line links to the public change it describes.
Get a weekly update like this for your product, free
Week of September 21, 2026
What shipped
- Secret scanning now uses a single Aho-Corasick pass instead of per-rule keyword searches across 105 built-in rules. Pull request #11179
- Crypto scanning reports repeated x509 material once per file instead of once per copy, reducing memory usage by ~14x for files with certificate repetition. Pull request #11263
- Crypto scanning now describes ML-DSA keys and signature algorithms from Go 1.27's crypto/mldsa. Pull request #11137
- Fixed a panic when scanning CSAF VEX documents with relationships lacking a sub-component. Pull request #11067
- Fixed a panic when scanning SPDX JSON SBOMs containing null entries in file and package arrays. Pull request #11101
- JSON line numbers are now derived from decoder offsets instead of buffer positions for correctness with json/v2. Pull request #11233
- MANIFEST.MF parsing now splits lines into key-value pairs once and switches on the key instead of matching prefixes per attribute. Pull request #11022
- License scanning now reports unparsable license names with UNKNOWN severity instead of empty severity. Pull request #11254
- Documentation clarified that custom Rego checks must come from trusted sources and can access environment variables and make HTTP requests. Pull request #11278
- Documentation added PerspectiveGraph to community reporting integrations. Pull request #11255
Why it matters
Performance improvements in secret scanning and crypto handling reduce resource consumption on large scans, while fixes to VEX and SBOM parsing prevent crashes on malformed documents. Better support for modern cryptography and clearer security guidance for custom checks strengthen the project's reliability and safety.
Changelog entry
- perf(secret): replace per-rule keyword search with one Aho-Corasick pass Pull request #11179
- perf(crypto): report repeated x509 material once per file Pull request #11263
- feat(crypto): describe ML-DSA keys and signature algorithms Pull request #11137
- fix(vex): avoid panic on CSAF relationships without a sub-component Pull request #11067
- fix(sbom): skip null entries in SPDX file and package arrays Pull request #11101
- perf: take JSON line numbers from decoder offsets Pull request #11233
- refactor(java): parse MANIFEST.MF attributes by key Pull request #11022
- fix(license): report unparsable license names with UNKNOWN severity Pull request #11254
- docs(misconf): clarify custom check security considerations Pull request #11278
- docs: link security reporting guidance to relevant documentation Pull request #11235
- docs: add PerspectiveGraph to reporting integrations Pull request #11255
- docs: clarify community integration listing disclaimer Pull request #11283
[1][2][6] This week: optimized secret scanning with Aho-Corasick, 14x memory reduction for repeated crypto material, ML-DSA support. [0][5] Fixed panics in VEX and SBOM parsing.
Trivy's latest release brings significant performance improvements and stability fixes. Secret scanning [1] now consolidates keyword searching into a single pass, while crypto scanning [2] reduces memory usage up to 14x for files with repeated certificates. We've added support for ML-DSA keys [6] from Go 1.27 and fixed crashes [0][5] when processing malformed VEX and SBOM documents. Additional improvements include better JSON line number handling [3], streamlined MANIFEST.MF parsing [4], and clearer security documentation [10] for custom checks.