Commit Graph

  • 677f4c0110
    remove workflows that update the code remove-update-workflows Alex Goodman 2026-03-27 12:24:02 -04:00
  • dc1e4b633b
    chore(deps): bump the actions-minor-patch group across 2 directories with 5 updates dependabot/github_actions/actions-minor-patch-4a5a782b71 dependabot[bot] 2026-03-27 13:19:18 +00:00
  • 341f5f0d85
    chore(deps): bump the go-minor-patch group with 3 updates dependabot/go_modules/go-minor-patch-24703a7f21 dependabot[bot] 2026-03-27 13:14:00 +00:00
  • ba1409021c chore(deps): update tools to latest versions auto/latest-tools spiffcs 2026-03-27 08:23:12 +00:00
  • d71b747cd1
    chore(deps): bump slackapi/slack-github-action from 2.1.1 to 3.0.1 (#4684) main dependabot[bot] 2026-03-26 11:12:33 -04:00
  • 58a8a95e26
    chore(deps): bump marocchino/sticky-pull-request-comment (#4685) dependabot[bot] 2026-03-25 19:27:59 -04:00
  • 78a21b9c88
    chore(deps): bump the go-minor-patch group with 2 updates (#4697) dependabot[bot] 2026-03-25 19:27:50 -04:00
  • 7d3882a425
    chore(deps): bump actions/create-github-app-token from 2.2.1 to 3.0.0 (#4699) dependabot[bot] 2026-03-25 19:27:31 -04:00
  • 673c85754c
    chore(deps): update CPE dictionary index (#4689) anchore-actions-token-generator[bot] 2026-03-25 08:38:49 -04:00
  • c5114fd745
    chore(deps): ignore some dependabot deps (#4696) Will Murphy 2026-03-24 08:12:50 -04:00
  • f68a7cc899
    ci: further pr target code checkout assurances (#4695) Weston Steimel 2026-03-24 11:16:16 +00:00
  • 7800b16529
    fix: update arangodb classifier and capture-snippet.sh (#4662) witchcraze 2026-03-24 05:29:39 +09:00
  • 834ddcb1c0
    fix: golang version file regex (#4694) Keith Zantow 2026-03-23 15:56:29 -04:00
  • f5d318d934
    ci: add explicit ref to main and warning for pull_request_target workflow (#4693) Weston Steimel 2026-03-23 16:45:18 +00:00
  • 8531e1917b
    chore(deps): update tools to latest versions (#4690) anchore-actions-token-generator[bot] 2026-03-23 12:01:27 -04:00
  • 1f2a299cb5
    test: add failing CPE formatting for colons cpe-formatting-fixes Weston Steimel 2026-03-23 15:47:12 +00:00
  • 860126c650
    chore(deps): update anchore dependencies (#4681) v1.42.3 anchore-actions-token-generator[bot] 2026-03-19 16:44:55 +00:00
  • 36639f136b
    chore(deps): bump github.com/buger/jsonsparser to v1.1.2 (#4680) Will Murphy 2026-03-19 11:08:18 -04:00
  • f32238c268
    chore(deps): bump the go-minor-patch group with 2 updates (#4678) dependabot[bot] 2026-03-19 10:25:19 -04:00
  • 0c8eef65f0
    chore(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.3 (#4675) dependabot[bot] 2026-03-18 16:55:30 -04:00
  • 4d42f8af32
    chore(deps): bump the go-minor-patch group with 2 updates (#4674) dependabot[bot] 2026-03-18 16:13:35 -04:00
  • e38851143e
    chore: centralize temp files and prefer streaming IO (#4668) Will Murphy 2026-03-18 10:53:51 -04:00
  • a3dacf5ecd
    chore(deps): update tools to latest versions (#4663) anchore-actions-token-generator[bot] 2026-03-16 11:26:06 -04:00
  • cccc9bf7f9
    chore(deps): bump the go-minor-patch group with 3 updates (#4669) dependabot[bot] 2026-03-16 11:25:41 -04:00
  • 59f7725d0d
    chore(deps): bump github/codeql-action (#4670) dependabot[bot] 2026-03-16 11:25:27 -04:00
  • 7a6b1575ae
    chore(deps): bump docker/login-action from 3.7.0 to 4.0.0 (#4671) dependabot[bot] 2026-03-16 11:25:16 -04:00
  • 92a6b36e89
    chore(deps): update CPE dictionary index (#4673) anchore-actions-token-generator[bot] 2026-03-16 11:25:05 -04:00
  • 5ea14d6e8b [wip] prototype sbom-split Alex Goodman 2026-03-11 10:00:29 -04:00
  • 7158535fe6
    chore(tests): fix test fixture build on modern ARM Mac (#4666) Will Murphy 2026-03-11 09:37:40 -04:00
  • 75455f050a
    chore(deps): update anchore dependencies (#4631) v1.42.2 anchore-actions-token-generator[bot] 2026-03-09 18:10:53 +00:00
  • 22e78c7be1
    chore(deps): update tools to latest versions (#4630) anchore-actions-token-generator[bot] 2026-03-09 12:17:09 -04:00
  • d2461a9e0a
    chore(deps): update SPDX license list (#4637) anchore-actions-token-generator[bot] 2026-03-09 11:02:47 -04:00
  • 01f0e332c2
    chore(deps): bump actions/download-artifact from 7.0.0 to 8.0.0 (#4658) dependabot[bot] 2026-03-09 10:37:33 -04:00
  • c88051d74e
    chore(deps): bump github.com/cloudflare/circl from 1.6.1 to 1.6.3 (#4638) dependabot[bot] 2026-03-09 10:34:11 -04:00
  • 7d3d1c6237
    chore(deps): bump the actions-minor-patch group across 2 directories with 2 updates (#4657) dependabot[bot] 2026-03-09 10:33:14 -04:00
  • dcba765d86
    chore(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0 (#4659) dependabot[bot] 2026-03-09 10:32:22 -04:00
  • 2c201469c3
    chore(deps): bump go.opentelemetry.io/otel/sdk from 1.39.0 to 1.40.0 (#4646) dependabot[bot] 2026-03-09 10:29:46 -04:00
  • c583da1c15
    chore(deps): update CPE dictionary index (#4647) anchore-actions-token-generator[bot] 2026-03-09 10:26:42 -04:00
  • 22014b6022
    chore(deps): bump the go-minor-patch group across 1 directory with 5 updates (#4661) dependabot[bot] 2026-03-09 10:20:06 -04:00
  • b5e85c3ea5
    chore: migrate fixtures to testdata (#4651) Alex Goodman 2026-03-06 14:42:04 -05:00
  • 35278f3d3d
    fix(java): improve lz4 detection (#4642) Dimitri John Ledkov 2026-02-27 19:38:05 +00:00
  • db76d85d51
    fix: use correct hashes for empty files (#4620) Paweł Pałucha 2026-02-24 15:52:29 +01:00
  • e9e7e20cc8
    fix: grafana classifier (#4635) witchcraze 2026-02-23 23:38:02 +09:00
  • eb072deb9c
    chore(deps): update CPE dictionary index (#4636) anchore-actions-token-generator[bot] 2026-02-23 08:19:30 -05:00
  • f4fc2d669a
    chore(deps): bump github/codeql-action (#4634) dependabot[bot] 2026-02-20 08:41:46 -05:00
  • f5110f109a
    chore(deps): bump github.com/charmbracelet/bubbles from 0.21.1 to 1.0.0 (#4633) dependabot[bot] 2026-02-20 08:41:21 -05:00
  • 612eadb22e
    chore(deps): bump the go-minor-patch group with 5 updates (#4632) dependabot[bot] 2026-02-20 08:40:09 -05:00
  • 0a3f7bb06e
    chore: call cleanup on tmpfile and replace some io.ReadAlls with streams (#4629) v1.42.1 Will Murphy 2026-02-17 17:32:35 -05:00
  • 2fe5f9c7b8
    fix: bumps go mod version to 1.25; ci takes latest patch (#4628) Christopher Angelo Phillips 2026-02-17 12:04:51 -05:00
  • f70631a719
    chore(deps): update tools to latest versions (#4614) anchore-actions-token-generator[bot] 2026-02-17 11:19:37 -05:00
  • 0bb3741c87
    chore(deps): bump the actions-minor-patch group across 1 directory with 2 updates (#4622) dependabot[bot] 2026-02-17 11:16:26 -05:00
  • 458ebbbff8
    chore(deps): bump the go-minor-patch group with 2 updates (#4621) dependabot[bot] 2026-02-17 10:14:13 -05:00
  • fb3f560e43
    chore(deps): update CPE dictionary index (#4623) anchore-actions-token-generator[bot] 2026-02-17 09:50:12 -05:00
  • 89b901b20b
    Use redhat as namespace for hummingbird rpms (#4615) Scott Hebert 2026-02-11 14:19:20 -05:00
  • 9872ff36ba
    chore(deps): update anchore dependencies (#4613) v1.42.0 anchore-actions-token-generator[bot] 2026-02-10 17:19:56 +00:00
  • 31c503124f
    chore(deps): bump github.com/go-git/go-git/v5 from 5.16.4 to 5.16.5 (#4612) dependabot[bot] 2026-02-10 08:25:31 -05:00
  • 2c5e193f7a
    feat: Add support for scanning GGUF models from OCI registries (#4335) Christopher Angelo Phillips 2026-02-09 16:05:52 -05:00
  • 3a23cfff1d
    chore(deps): update CPE dictionary index (#4610) anchore-actions-token-generator[bot] 2026-02-08 22:02:34 -05:00
  • 61dff5de88
    chore: migrate .goreleaser build to docker_v2 goreleaser_dockers_v2 Christopher Phillips 2026-02-06 15:59:16 -05:00
  • 443de210ca
    chore(deps): bump github.com/bmatcuk/doublestar/v4 (#4606) dependabot[bot] 2026-02-06 13:20:24 -05:00
  • 1af8b1acaa
    chore(deps): bump the actions-minor-patch group across 2 directories with 2 updates (#4607) dependabot[bot] 2026-02-06 13:20:12 -05:00
  • c185657d71
    feat: add yarn lock dev dep detection; fixed #4548 Rez Moss 2026-02-05 17:27:17 -05:00
  • 48ee12be0c
    ci(generate-capabilities): serialize writing and reading yaml (#4602) Will Murphy 2026-02-05 11:35:45 -05:00
  • 0b05f0ed69
    chore(deps): update CPE dictionary index (#4601) anchore-actions-token-generator[bot] 2026-02-05 15:29:00 +00:00
  • 138cb1be0e
    fix(cpe-generation): set start and end date (#4600) Will Murphy 2026-02-05 09:54:24 -05:00
  • 6755377554
    fix: CPE detection for APK libavif to use aomedia vendor (#4597) Peter Bücker 2026-02-05 10:11:44 +01:00
  • 540c08a41b
    chore(deps): update tools to latest versions (#4594) anchore-actions-token-generator[bot] 2026-02-04 09:26:09 -05:00
  • add2629446
    fix: further improve go binary classifier, including windows (#4593) v1.41.2 Keith Zantow 2026-02-03 10:29:00 -05:00
  • ce6e763ddb
    test: bust cache prefix to force rebuild report-java-archive-metadata Christopher Phillips 2026-02-02 15:03:20 -05:00
  • a19555f742
    test: makefile; fingerprint shell change Christopher Phillips 2026-02-02 13:26:34 -05:00
  • 0f95a1985c
    chore: bump fingerprint for cache rebuild Christopher Phillips 2026-02-02 13:18:19 -05:00
  • d22139ef1a
    chore(deps): update tools to latest versions (#4589) anchore-actions-token-generator[bot] 2026-02-02 12:59:57 -05:00
  • 67986a9279
    test: update tests with new expections Christopher Phillips 2026-02-02 12:49:03 -05:00
  • cb62054eed
    chore: 16.1.3 drift Christopher Phillips 2026-01-30 17:43:49 -05:00
  • 04313718b0
    fix: lint-fix Christopher Phillips 2026-01-30 17:27:14 -05:00
  • 7f01403a6b
    pr: pr feedback Christopher Phillips 2026-01-30 17:23:20 -05:00
  • 169ded1804
    Merge branch 'main' into report-java-archive-metadata Christopher Phillips 2026-01-30 17:11:05 -05:00
  • 2dffebd34a
    pr: resolve schema drift Christopher Phillips 2026-01-30 17:02:09 -05:00
  • c94d1ccf1c
    fix: lookup alternate scheme on url->licenseID (#4588) Christopher Angelo Phillips 2026-01-30 14:25:27 -05:00
  • 69d0898918
    chore(deps): bump the go-minor-patch group with 2 updates (#4583) dependabot[bot] 2026-01-30 11:24:34 -05:00
  • 94c8088542
    feat: add Qt6 binary detection (#4550) Rez Moss 2026-01-30 10:35:33 -05:00
  • e136ebc44f
    chore(deps): bump the actions-minor-patch group across 1 directory with 2 updates (#4584) dependabot[bot] 2026-01-30 10:33:32 -05:00
  • 0bca34f986
    fix: snap cataloger incorrectly identifies snap container as deb package (#4500) Alan Pope 2026-01-30 15:19:26 +00:00
  • 49a57a0307
    chore: update snippets to be managed by config qt6-binary-detection Christopher Phillips 2026-01-30 10:18:59 -05:00
  • ab725de6a1
    fix: base extension without spdx upstream update fix-license-url Christopher Phillips 2026-01-29 14:26:30 -05:00
  • 8d836fb8b0
    chore(deps): update tools to latest versions (#4577) v1.41.1 anchore-actions-token-generator[bot] 2026-01-27 15:18:18 -05:00
  • 9a250a4b4b
    fix: update mixed case dependencies in python to be normalized (#4573) Christopher Angelo Phillips 2026-01-27 15:16:32 -05:00
  • e8b4527bfb
    chore(deps): update anchore dependencies (#4575) v1.41.0 anchore-actions-token-generator[bot] 2026-01-27 10:14:26 +00:00
  • d0bb042d74
    chore(deps): update tools to latest versions (#4570) anchore-actions-token-generator[bot] 2026-01-26 12:25:31 -05:00
  • c744873ac9
    feat: detect Debian version from /etc/debian_version (#4569) patch-1.33.0-r1 Keith Zantow 2026-01-23 17:52:21 -05:00
  • 0773492f84
    fix: correctly report supporting evidence for binary packages (#4558) Keith Zantow 2026-01-23 13:01:12 -05:00
  • c65d023668
    feat: detect Debian version from /etc/debian_version (#4569) Keith Zantow 2026-01-23 17:52:21 -05:00
  • 836f358cd4
    fix: correctly report supporting evidence for binary packages (#4558) Keith Zantow 2026-01-23 13:01:12 -05:00
  • 27b1219e98
    chore(deps): bump the actions-minor-patch group across 2 directories with 3 updates (#4568) dependabot[bot] 2026-01-23 10:37:23 -05:00
  • c0e0058c86
    chore(deps): bump the go-minor-patch group with 6 updates (#4567) dependabot[bot] 2026-01-23 10:37:10 -05:00
  • a9fabb6c0f
    chore(deps): update tools to latest versions (#4565) anchore-actions-token-generator[bot] 2026-01-22 13:04:45 -05:00
  • 2d52c78595
    qt bin classifier, fixed #4467 Rez Moss 2026-01-19 10:55:43 -05:00
  • 7954324417
    chore(deps): bump github.com/spdx/tools-golang (#4557) dependabot[bot] 2026-01-16 13:04:13 -05:00
  • 3e563d90d5
    ci: enable zizmor to fail PRs (#4556) Will Murphy 2026-01-16 10:49:00 -05:00
  • 5987f46353
    Chore new slack action (#4553) Will Murphy 2026-01-16 06:26:40 -05:00