dependabot[bot]
36016a0c5f
chore(deps): bump github/codeql-action from 3.27.7 to 3.27.9 ( #3524 )
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.27.7 to 3.27.9.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](babb554ede...df409f7d92 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-13 10:38:58 -05:00
dependabot[bot]
8dcb495312
chore(deps): bump golang.org/x/crypto from 0.30.0 to 0.31.0 ( #3523 )
...
Bumps [golang.org/x/crypto](https://github.com/golang/crypto ) from 0.30.0 to 0.31.0.
- [Commits](https://github.com/golang/crypto/compare/v0.30.0...v0.31.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/crypto
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-12 15:43:40 -05:00
dependabot[bot]
02f9350fa5
chore(deps): bump actions/setup-go from 5.1.0 to 5.2.0 ( #3519 )
...
Bumps [actions/setup-go](https://github.com/actions/setup-go ) from 5.1.0 to 5.2.0.
- [Release notes](https://github.com/actions/setup-go/releases )
- [Commits](41dfa10bad...3041bf56c9 )
---
updated-dependencies:
- dependency-name: actions/setup-go
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-11 13:14:55 -05:00
dependabot[bot]
20fb9cc00c
chore(deps): bump actions/checkout from 4.2.1 to 4.2.2 ( #3518 )
...
Bumps [actions/checkout](https://github.com/actions/checkout ) from 4.2.1 to 4.2.2.
- [Release notes](https://github.com/actions/checkout/releases )
- [Changelog](https://github.com/actions/checkout/blob/main/CHANGELOG.md )
- [Commits](https://github.com/actions/checkout/compare/v4.2.1...11bd71901bbe5b1630ceea73d27597364c9af683 )
---
updated-dependencies:
- dependency-name: actions/checkout
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-11 13:14:25 -05:00
William Murphy
6deb41c458
chore: make fixes field in PR template match auto-close regex ( #3520 )
...
Previously, if filling out this template, someone pasted a PR link after
"Fixes #", the issue wouldn't automatically close, probably because the
extra "#" confused the auto-close regex.
Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>
2024-12-11 12:37:55 -05:00
William Murphy
445142886e
fix: stop omitting redundantly parenthesized licenses in CDX formatter ( #3517 )
...
Previously, a bug in the formatter would cause SPDX expressions that
were surrounded in redundant parentheses to be dropped instead of
normalized.
Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>
2024-12-11 10:06:08 -05:00
Christopher Angelo Phillips
561ed50c2d
chore: migrate syft to use the anchore fork of archiver without replace ( #3516 )
...
---------
Signed-off-by: Christopher Phillips <32073428+spiffcs@users.noreply.github.com>
2024-12-10 13:33:24 -05:00
Alex Goodman
d77e78ea9d
Make pre-release integration PRs ( #3370 )
...
* use reusable dep update action
Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
* use workflow that takes multiple repo
Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
* fix mispelling
Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
* remove taskfile update
Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
* bump action to main branch
Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
* rename action
Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
* remove gh make var
Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
---------
Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
2024-12-10 17:14:11 +00:00
dependabot[bot]
0f9d2e5311
chore(deps): bump github.com/docker/docker ( #3512 )
...
Bumps [github.com/docker/docker](https://github.com/docker/docker ) from 27.3.1+incompatible to 27.4.0+incompatible.
- [Release notes](https://github.com/docker/docker/releases )
- [Commits](https://github.com/docker/docker/compare/v27.3.1...v27.4.0 )
---
updated-dependencies:
- dependency-name: github.com/docker/docker
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-10 10:49:17 -05:00
dependabot[bot]
0dc74a3c37
chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.3 to 6.6.4 ( #3513 )
...
Bumps [github.com/jedib0t/go-pretty/v6](https://github.com/jedib0t/go-pretty ) from 6.6.3 to 6.6.4.
- [Release notes](https://github.com/jedib0t/go-pretty/releases )
- [Commits](https://github.com/jedib0t/go-pretty/compare/v6.6.3...v6.6.4 )
---
updated-dependencies:
- dependency-name: github.com/jedib0t/go-pretty/v6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-10 10:49:05 -05:00
dependabot[bot]
37957b895e
chore(deps): bump github/codeql-action from 3.27.6 to 3.27.7 ( #3514 )
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.27.6 to 3.27.7.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](aa57810251...babb554ede )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-10 10:48:52 -05:00
Alex Goodman
d38efb0b7f
chore(deps): update anchore dependencies ( #3510 )
...
* integrate anchore deps
Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
* upgrade to released versions
Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
---------
Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
v1.18.0
2024-12-09 15:51:16 -05:00
Christopher Angelo Phillips
f9e320c5b7
fix: convert file paths for spdx formats from absolute to relative ( #3509 )
...
* feat: convert file paths for spdx formats from absolute to relative
---------
Signed-off-by: Christopher Phillips <32073428+spiffcs@users.noreply.github.com>
2024-12-09 13:02:54 -05:00
anchore-actions-token-generator[bot]
cd0900e758
chore(deps): update CPE dictionary index ( #3507 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: wagoodman <590471+wagoodman@users.noreply.github.com>
2024-12-09 09:54:52 -05:00
anchore-actions-token-generator[bot]
064a9712ac
chore(deps): update tools to latest versions ( #3506 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: spiffcs <32073428+spiffcs@users.noreply.github.com>
2024-12-09 09:54:48 -05:00
dependabot[bot]
c43c9df1ba
chore(deps): bump github.com/magiconair/properties from 1.8.7 to 1.8.9 ( #3508 )
...
Bumps [github.com/magiconair/properties](https://github.com/magiconair/properties ) from 1.8.7 to 1.8.9.
- [Release notes](https://github.com/magiconair/properties/releases )
- [Commits](https://github.com/magiconair/properties/compare/v1.8.7...v1.8.9 )
---
updated-dependencies:
- dependency-name: github.com/magiconair/properties
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-09 09:54:12 -05:00
dependabot[bot]
4015f40982
chore(deps): bump actions/cache from 4.1.2 to 4.2.0 ( #3503 )
...
Bumps [actions/cache](https://github.com/actions/cache ) from 4.1.2 to 4.2.0.
- [Release notes](https://github.com/actions/cache/releases )
- [Changelog](https://github.com/actions/cache/blob/main/RELEASES.md )
- [Commits](6849a64899...1bd1e32a3b )
---
updated-dependencies:
- dependency-name: actions/cache
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-06 15:29:44 -05:00
Alex Goodman
340b5e17f0
Add relationships for rust audit binary packages ( #3500 )
...
* add rust audit binary pkg relationships
Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
* fix linting
Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
---------
Signed-off-by: Alex Goodman <wagoodman@users.noreply.github.com>
2024-12-06 09:23:18 -05:00
William Murphy
4adb56d2fe
fix order of rust dependencies and support git sources in Cargo.lock dependencies ( #3502 )
...
* fix: un-reverse Cargo.lock dependencies
Previously, dependencyOf was pointing the wrong way. Use dependency
specification helpers to build the dependency graph.
Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>
* feat: parse Cargo.lock git dependency relationships
Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>
---------
Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>
2024-12-06 13:38:36 +00:00
anchore-actions-token-generator[bot]
d3c9ce532d
chore(deps): update tools to latest versions ( #3501 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: spiffcs <32073428+spiffcs@users.noreply.github.com>
2024-12-06 08:36:54 -05:00
dependabot[bot]
5e22251c86
chore(deps): bump golang.org/x/net from 0.31.0 to 0.32.0 ( #3499 )
...
Bumps [golang.org/x/net](https://github.com/golang/net ) from 0.31.0 to 0.32.0.
- [Commits](https://github.com/golang/net/compare/v0.31.0...v0.32.0 )
---
updated-dependencies:
- dependency-name: golang.org/x/net
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-05 11:36:33 -05:00
William Murphy
25e5d555ef
chore: add and document target for updating unit snapshots ( #3498 )
...
* chore: add and document target for updating unit snapshots
Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>
* chore: rename to reflect narrower scope
Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>
---------
Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>
2024-12-04 20:21:07 +00:00
Christopher Angelo Phillips
48190233f4
fix: emit NOASSERTION for copyright text to fix SPDX 2.2 validation failure ( #3495 )
...
* fixes issue #3346
Signed-off-by: Fearkin <fearjin1@gmail.com>
* chore: update schema and unit tests to reflect new copyright property
Signed-off-by: Christopher Phillips <32073428+spiffcs@users.noreply.github.com>
* chore: revert schema changes
Signed-off-by: Christopher Phillips <32073428+spiffcs@users.noreply.github.com>
* fix: noassert copyright on spdx root package
Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>
* test: explicitly test spdx 2.2 with tools-java validator
Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>
* test: update snapshot files
Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>
---------
Signed-off-by: Fearkin <fearjin1@gmail.com>
Signed-off-by: Christopher Phillips <32073428+spiffcs@users.noreply.github.com>
Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>
Co-authored-by: Fearkin <fearjin1@gmail.com>
Co-authored-by: Will Murphy <willmurphyscode@users.noreply.github.com>
2024-12-04 14:58:36 -05:00
anchore-actions-token-generator[bot]
3508e648af
chore(deps): update tools to latest versions ( #3496 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: spiffcs <32073428+spiffcs@users.noreply.github.com>
2024-12-04 10:01:21 -05:00
anchore-actions-token-generator[bot]
1af70d766d
chore(deps): update tools to latest versions ( #3487 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: spiffcs <32073428+spiffcs@users.noreply.github.com>
2024-12-03 11:04:44 -05:00
dependabot[bot]
0c3fa82952
chore(deps): bump github/codeql-action from 3.27.5 to 3.27.6 ( #3494 )
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.27.5 to 3.27.6.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](f09c1c0a94...aa57810251 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-03 11:04:28 -05:00
dependabot[bot]
c3619422bb
chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.2 to 6.6.3 ( #3489 )
2024-12-02 16:30:09 +00:00
GGMU
59e943385d
feat: set max layer size ( #3464 )
...
Signed-off-by: tomersein <tomersein@gmail.com>
2024-12-02 11:29:42 -05:00
anchore-actions-token-generator[bot]
0e880e83e6
chore(deps): update CPE dictionary index ( #3491 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: wagoodman <590471+wagoodman@users.noreply.github.com>
2024-12-02 11:14:28 -05:00
dependabot[bot]
74d58024f6
chore(deps): bump modernc.org/sqlite from 1.34.1 to 1.34.2 ( #3492 )
...
Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite ) from 1.34.1 to 1.34.2.
- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.34.1...v1.34.2 )
---
updated-dependencies:
- dependency-name: modernc.org/sqlite
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-02 10:47:33 -05:00
dependabot[bot]
a0a62931c8
chore(deps): bump github.com/saferwall/pe from 1.5.5 to 1.5.6 ( #3493 )
...
Bumps [github.com/saferwall/pe](https://github.com/saferwall/pe ) from 1.5.5 to 1.5.6.
- [Release notes](https://github.com/saferwall/pe/releases )
- [Changelog](https://github.com/saferwall/pe/blob/main/CHANGELOG.md )
- [Commits](https://github.com/saferwall/pe/compare/v1.5.5...v1.5.6 )
---
updated-dependencies:
- dependency-name: github.com/saferwall/pe
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-12-02 10:47:21 -05:00
anchore-actions-token-generator[bot]
a320cf76a4
chore(deps): update tools to latest versions ( #3478 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: spiffcs <32073428+spiffcs@users.noreply.github.com>
2024-11-27 10:17:54 -05:00
anchore-actions-token-generator[bot]
ec5f3169db
chore(deps): update CPE dictionary index ( #3479 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: wagoodman <590471+wagoodman@users.noreply.github.com>
2024-11-27 10:17:34 -05:00
dependabot[bot]
bbc292ecc0
chore(deps): bump github.com/stretchr/testify from 1.9.0 to 1.10.0 ( #3480 )
...
Bumps [github.com/stretchr/testify](https://github.com/stretchr/testify ) from 1.9.0 to 1.10.0.
- [Release notes](https://github.com/stretchr/testify/releases )
- [Commits](https://github.com/stretchr/testify/compare/v1.9.0...v1.10.0 )
---
updated-dependencies:
- dependency-name: github.com/stretchr/testify
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-11-27 10:17:19 -05:00
dependabot[bot]
b8d3dd3039
chore(deps): bump github.com/charmbracelet/bubbletea from 1.2.3 to 1.2.4 ( #3482 )
...
Bumps [github.com/charmbracelet/bubbletea](https://github.com/charmbracelet/bubbletea ) from 1.2.3 to 1.2.4.
- [Release notes](https://github.com/charmbracelet/bubbletea/releases )
- [Changelog](https://github.com/charmbracelet/bubbletea/blob/main/.goreleaser.yml )
- [Commits](https://github.com/charmbracelet/bubbletea/compare/v1.2.3...v1.2.4 )
---
updated-dependencies:
- dependency-name: github.com/charmbracelet/bubbletea
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-11-27 10:17:10 -05:00
anchore-actions-token-generator[bot]
9f1e91e72e
chore(deps): update stereoscope to be5deed44b7c03fcbfa6f1f42fb67202d31636a9 ( #3483 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: kzantow <3009477+kzantow@users.noreply.github.com>
2024-11-27 10:17:00 -05:00
witchcraze
2118295f19
fix: dart classifier for 2.x and ARM ( #3475 )
...
Signed-off-by: witchcraze <witchcraze@gmail.com>
2024-11-22 13:05:09 -05:00
Adam McClenaghan
21df38798e
Use file indexer directly when scanning with file source ( #3333 )
...
* Use file indexer when scanning with file source
Prevents filesystem walks when scanning a single file, to
optimise memory & scan times in case the scanned file
lives in a directory containing many files.
Signed-off-by: adammcclenaghan <adam@mcclenaghan.co.uk>
* Create filetree resolver
Shared behaviour for resolving indexed filetrees.
Signed-off-by: adammcclenaghan <adam@mcclenaghan.co.uk>
---------
Signed-off-by: adammcclenaghan <adam@mcclenaghan.co.uk>
2024-11-22 11:53:53 -05:00
dependabot[bot]
8abd97a5bf
chore(deps): bump anchore/sbom-action from 0.17.7 to 0.17.8 ( #3476 )
...
Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action ) from 0.17.7 to 0.17.8.
- [Release notes](https://github.com/anchore/sbom-action/releases )
- [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md )
- [Commits](fc46e51fd3...55dc4ee224 )
---
updated-dependencies:
- dependency-name: anchore/sbom-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-11-22 11:18:05 -05:00
dependabot[bot]
05c09fd73d
chore(deps): bump github/codeql-action from 3.27.4 to 3.27.5 ( #3473 )
...
Bumps [github/codeql-action](https://github.com/github/codeql-action ) from 3.27.4 to 3.27.5.
- [Release notes](https://github.com/github/codeql-action/releases )
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md )
- [Commits](ea9e4e3799...f09c1c0a94 )
---
updated-dependencies:
- dependency-name: github/codeql-action
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-11-21 15:14:27 -05:00
anchore-actions-token-generator[bot]
a8d4202d77
chore(deps): update stereoscope to aa3a3ef4efe8d8759c9aa87261b405cc003bfc9a ( #3472 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: willmurphyscode <12529630+willmurphyscode@users.noreply.github.com>
v1.17.0
2024-11-21 14:28:51 +00:00
dependabot[bot]
19a30b9fd2
chore(deps): bump github.com/charmbracelet/bubbletea from 1.2.2 to 1.2.3 ( #3467 )
...
Bumps [github.com/charmbracelet/bubbletea](https://github.com/charmbracelet/bubbletea ) from 1.2.2 to 1.2.3.
- [Release notes](https://github.com/charmbracelet/bubbletea/releases )
- [Changelog](https://github.com/charmbracelet/bubbletea/blob/main/.goreleaser.yml )
- [Commits](https://github.com/charmbracelet/bubbletea/compare/v1.2.2...v1.2.3 )
---
updated-dependencies:
- dependency-name: github.com/charmbracelet/bubbletea
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-11-20 08:32:30 -05:00
William Murphy
e65fe243bf
fix: bump clio to pull in logging fix ( #3466 )
...
Previously, if SYFT_LOG_FILE was not set, and no TTY was present,
log.Warn messages were discarded instead of being sent to stderr.
Signed-off-by: Will Murphy <willmurphyscode@users.noreply.github.com>
2024-11-19 14:56:53 -05:00
Christopher Angelo Phillips
f4cad63da1
3122 valid license url characters ( #3449 )
...
* chore: strip unwanted characters from license URL
---------
Signed-off-by: Christopher Phillips <32073428+spiffcs@users.noreply.github.com>
2024-11-19 15:34:58 +00:00
Christopher Angelo Phillips
e7b65c2c58
3030 license declared spdx correction ( #3461 )
...
* feat: update hasExtractedLicense field to include license-ref candidates
---------
Signed-off-by: Christopher Phillips <32073428+spiffcs@users.noreply.github.com>
2024-11-19 15:00:59 +00:00
anchore-actions-token-generator[bot]
8aef0c908a
chore(deps): update tools to latest versions ( #3463 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: spiffcs <32073428+spiffcs@users.noreply.github.com>
2024-11-19 09:36:46 -05:00
dependabot[bot]
35fa0cc454
chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.1 to 6.6.2 ( #3465 )
...
Bumps [github.com/jedib0t/go-pretty/v6](https://github.com/jedib0t/go-pretty ) from 6.6.1 to 6.6.2.
- [Release notes](https://github.com/jedib0t/go-pretty/releases )
- [Commits](https://github.com/jedib0t/go-pretty/compare/v6.6.1...v6.6.2 )
---
updated-dependencies:
- dependency-name: github.com/jedib0t/go-pretty/v6
dependency-type: direct:production
update-type: version-update:semver-patch
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-11-19 09:36:32 -05:00
dependabot[bot]
1c61e9cbff
chore(deps): bump modernc.org/sqlite from 1.33.1 to 1.34.1 ( #3460 )
...
Bumps [modernc.org/sqlite](https://gitlab.com/cznic/sqlite ) from 1.33.1 to 1.34.1.
- [Commits](https://gitlab.com/cznic/sqlite/compare/v1.33.1...v1.34.1 )
---
updated-dependencies:
- dependency-name: modernc.org/sqlite
dependency-type: direct:production
update-type: version-update:semver-minor
...
Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-11-18 09:33:08 -05:00
anchore-actions-token-generator[bot]
d91150edea
chore(deps): update CPE dictionary index ( #3453 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: wagoodman <590471+wagoodman@users.noreply.github.com>
2024-11-18 08:33:41 -05:00
anchore-actions-token-generator[bot]
215ae2bbb9
chore(deps): update tools to latest versions ( #3454 )
...
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Co-authored-by: spiffcs <32073428+spiffcs@users.noreply.github.com>
2024-11-18 08:33:23 -05:00