Skip to content

Commit 82e2adc

Browse files
authored
fix(misconf): Disable deprecated checks by default (#7632)
1 parent 1faf529 commit 82e2adc

File tree

8 files changed

+7
-8
lines changed

8 files changed

+7
-8
lines changed

docs/docs/references/configuration/cli/trivy_config.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -31,7 +31,7 @@ trivy config [flags] DIR
3131
-h, --help help for config
3232
--ignore-policy string specify the Rego file path to evaluate each vulnerability
3333
--ignorefile string specify .trivyignore file (default ".trivyignore")
34-
--include-deprecated-checks include deprecated checks (default true)
34+
--include-deprecated-checks include deprecated checks
3535
--include-non-failures include successes and exceptions, available with '--scanners misconfig'
3636
--k8s-version string specify k8s version to validate outdated api by it (example: 1.21.0)
3737
--misconfig-scanners strings comma-separated list of misconfig scanners to use for misconfiguration scanning (default [azure-arm,cloudformation,dockerfile,helm,kubernetes,terraform,terraformplan-json,terraformplan-snapshot])

docs/docs/references/configuration/cli/trivy_filesystem.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,7 @@ trivy filesystem [flags] PATH
5353
--ignore-unfixed display only fixed vulnerabilities
5454
--ignored-licenses strings specify a list of license to ignore
5555
--ignorefile string specify .trivyignore file (default ".trivyignore")
56-
--include-deprecated-checks include deprecated checks (default true)
56+
--include-deprecated-checks include deprecated checks
5757
--include-dev-deps include development dependencies in the report (supported: npm, yarn)
5858
--include-non-failures include successes and exceptions, available with '--scanners misconfig'
5959
--java-db-repository strings OCI repository(ies) to retrieve trivy-java-db in order of priority (default [ghcr.io/aquasecurity/trivy-java-db:1])

docs/docs/references/configuration/cli/trivy_image.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -71,7 +71,7 @@ trivy image [flags] IMAGE_NAME
7171
--ignorefile string specify .trivyignore file (default ".trivyignore")
7272
--image-config-scanners strings comma-separated list of what security issues to detect on container image configurations (misconfig,secret)
7373
--image-src strings image source(s) to use, in priority order (docker,containerd,podman,remote) (default [docker,containerd,podman,remote])
74-
--include-deprecated-checks include deprecated checks (default true)
74+
--include-deprecated-checks include deprecated checks
7575
--include-non-failures include successes and exceptions, available with '--scanners misconfig'
7676
--input string input file path instead of image name
7777
--java-db-repository strings OCI repository(ies) to retrieve trivy-java-db in order of priority (default [ghcr.io/aquasecurity/trivy-java-db:1])

docs/docs/references/configuration/cli/trivy_kubernetes.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -66,7 +66,7 @@ trivy kubernetes [flags] [CONTEXT]
6666
--ignore-unfixed display only fixed vulnerabilities
6767
--ignorefile string specify .trivyignore file (default ".trivyignore")
6868
--image-src strings image source(s) to use, in priority order (docker,containerd,podman,remote) (default [docker,containerd,podman,remote])
69-
--include-deprecated-checks include deprecated checks (default true)
69+
--include-deprecated-checks include deprecated checks
7070
--include-kinds strings indicate the kinds included in scanning (example: node)
7171
--include-namespaces strings indicate the namespaces included in scanning (example: kube-system)
7272
--include-non-failures include successes and exceptions, available with '--scanners misconfig'

docs/docs/references/configuration/cli/trivy_repository.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -53,7 +53,7 @@ trivy repository [flags] (REPO_PATH | REPO_URL)
5353
--ignore-unfixed display only fixed vulnerabilities
5454
--ignored-licenses strings specify a list of license to ignore
5555
--ignorefile string specify .trivyignore file (default ".trivyignore")
56-
--include-deprecated-checks include deprecated checks (default true)
56+
--include-deprecated-checks include deprecated checks
5757
--include-dev-deps include development dependencies in the report (supported: npm, yarn)
5858
--include-non-failures include successes and exceptions, available with '--scanners misconfig'
5959
--java-db-repository strings OCI repository(ies) to retrieve trivy-java-db in order of priority (default [ghcr.io/aquasecurity/trivy-java-db:1])

docs/docs/references/configuration/cli/trivy_rootfs.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -56,7 +56,7 @@ trivy rootfs [flags] ROOTDIR
5656
--ignore-unfixed display only fixed vulnerabilities
5757
--ignored-licenses strings specify a list of license to ignore
5858
--ignorefile string specify .trivyignore file (default ".trivyignore")
59-
--include-deprecated-checks include deprecated checks (default true)
59+
--include-deprecated-checks include deprecated checks
6060
--include-non-failures include successes and exceptions, available with '--scanners misconfig'
6161
--java-db-repository strings OCI repository(ies) to retrieve trivy-java-db in order of priority (default [ghcr.io/aquasecurity/trivy-java-db:1])
6262
--license-confidence-level float specify license classifier's confidence level (default 0.9)

docs/docs/references/configuration/config-file.md

+1-1
Original file line numberDiff line numberDiff line change
@@ -479,7 +479,7 @@ rego:
479479
data: []
480480

481481
# Same as '--include-deprecated-checks'
482-
include-deprecated-checks: true
482+
include-deprecated-checks: false
483483

484484
# Same as '--check-namespaces'
485485
namespaces: []

pkg/flag/rego_flags.go

-1
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,6 @@ var (
1111
Name: "include-deprecated-checks",
1212
ConfigName: "rego.include-deprecated-checks",
1313
Usage: "include deprecated checks",
14-
Default: true,
1514
}
1615
SkipCheckUpdateFlag = Flag[bool]{
1716
Name: "skip-check-update",

0 commit comments

Comments
 (0)