* main:
chore(deps): update tools to latest versions (#4302)
chore(deps): bump github.com/github/go-spdx/v2 from 2.3.3 to 2.3.4 (#4301)
chore(deps): bump github/codeql-action from 4.30.8 to 4.30.9 (#4299)
support universal (fat) mach-o binary files (#4278)
chore(deps): bump sigstore/cosign-installer from 3.10.0 to 4.0.0 (#4296)
chore(deps): bump anchore/sbom-action from 0.20.7 to 0.20.8 (#4297)
convert posix path back to windows (#4285)
Remove duplicate image source providers (#4289)
chore(deps): bump anchore/sbom-action from 0.20.6 to 0.20.7 (#4293)
feat: add option to fetch remote licenses for pnpm-lock.yaml files (#4286)
Add PDM parser (#4234)
chore(deps): update tools to latest versions (#4291)
fix: panic during java archive maven resolution (#4290)
Extract zip archive with multiple entries (#4283)
chore: update to use old configuration on new cosign (#4287)
chore(deps): update anchore dependencies (#4282)
chore(deps): bump github.com/mholt/archives from 0.1.3 to 0.1.5 (#4280)
add docs to configs (#4281)