Commit Graph

  • 8a870995a1
    chore(deps): bump the go-minor-patch group across 2 directories with 11 updates dependabot/go_modules/go-minor-patch-11a597bef2 dependabot[bot] 2026-05-19 16:15:14 +00:00
  • b1287d45d8
    chore(deps): bump github.com/go-git/go-git/v5 from 5.19.0 to 5.19.1 (#4930) main dependabot[bot] 2026-05-19 16:11:18 +00:00
  • d97216ff70
    Remediate audit (#4929) Alex Goodman 2026-05-18 15:01:37 -04:00
  • c09a009bda
    chore(deps): bump the actions-minor-patch group across 1 directory with 4 updates (#4927) dependabot[bot] 2026-05-18 16:13:54 +00:00
  • d61af0abab
    Port to go-make (#4923) Alex Goodman 2026-05-18 11:59:55 -04:00
  • 89cda82263
    chore(deps): update CPE dictionary index (#4925) anchore-oss-update-bot 2026-05-18 10:21:30 -04:00
  • ee6ace36d1
    chore(deps): bump the actions-minor-patch group across 1 directory with 2 updates (#4920) dependabot[bot] 2026-05-15 13:34:58 +00:00
  • e2e5e223ab
    feat: mysqld, ndbd, ndbmtd and ndb_mgmd classifier (#4907) witchcraze 2026-05-15 00:29:42 +09:00
  • 4579d11abc
    fix: detect compressed kernel modules (.ko.gz, .ko.xz, .ko.zst) (#4740) William Bates 2026-05-13 13:44:18 -04:00
  • 07ae2ca08d
    chore(deps): update CPE dictionary index (#4909) anchore-oss-update-bot 2026-05-13 10:03:11 -04:00
  • 36969bdeff
    fix: Allow duplicates in Yarn "Berry" files (#4691) (#4838) Calum Leslie 2026-05-11 22:10:17 +01:00
  • dfb6011083
    pin and update fixture versions (#4913) Alex Goodman 2026-05-11 16:30:35 -04:00
  • 997a486e22
    use released shared workflow (#4914) Alex Goodman 2026-05-11 16:21:41 -04:00
  • 4f64fbc004
    chore(deps): bump github.com/go-git/go-git/v5 from 5.18.0 to 5.19.0 (#4911) dependabot[bot] 2026-05-11 16:25:44 +00:00
  • 87d6a288d7
    Tighten workflow permissions and update release shape (#4899) Alex Goodman 2026-05-08 17:16:31 -04:00
  • 20987d30d0
    chore(deps): bump the actions-minor-patch group across 1 directory with 2 updates (#4897) dependabot[bot] 2026-05-08 13:38:31 +00:00
  • e2007d9bf2
    feat: add aws-lc classifier (#4882) witchcraze 2026-05-07 05:43:34 +09:00
  • 4f0e32ab51
    binary classifier: detect elixir release-candidate versions (#4851) ChrisJr404 2026-05-06 11:14:09 -04:00
  • 605391114c
    add ingress-nginx classifier (#4857) witchcraze 2026-05-06 23:54:20 +09:00
  • 1caf243d29
    fix(source): treat exclude paths with trailing slash as directories (#4892) ChrisJr404 2026-05-06 10:51:41 -04:00
  • 48e91312e8
    fix(dotnet): align runtime CPEs with NVD (#4743) PGray 2026-05-06 14:07:49 +01:00
  • d81df67493
    fix(debian): only parse machine-readable copyright files with Format header (#4754) bahtyar 2026-05-06 21:02:27 +08:00
  • 47cda2b5ef
    chore(deps): bump the actions-minor-patch group across 2 directories with 5 updates (#4846) dependabot[bot] 2026-05-05 11:42:04 -04:00
  • ae711963d1
    fix: parse arbitrary equality python requirements (#4835) Rayan Salhab 2026-05-05 16:49:03 +03:00
  • f878197150
    chore: remove common workflows (#4881) Alex Goodman 2026-05-04 14:31:07 -04:00
  • 514efb03e0
    fix: prevent redis classifier from detecting valkey (#4619) witchcraze 2026-05-05 03:07:29 +09:00
  • 1e4f424f09
    chore(deps): update CPE dictionary index (#4831) anchore-oss-update-bot 2026-05-04 10:14:08 -04:00
  • b5f0877967
    fix: map "nuget" purl type to DotnetPkg in TypeByName (#4848) ChrisJr404 2026-05-04 08:51:19 -04:00
  • cd27d55f2a
    feat: safe tensors safe-tensors Christopher Phillips 2026-04-30 13:33:17 -04:00
  • 8cb78ce40c
    fix: resolve yarn lock aliases to source package (#4836) v1.44.0 Rayan Salhab 2026-04-29 16:50:09 +03:00
  • 3b046b3787
    chore: move snippet files from test-fixtures to testdata (#4830) witchcraze 2026-04-28 00:09:21 +09:00
  • 05cc8ee5f4
    Add support for linux-riscv64 (#4757) Ludovic Henry 2026-04-27 12:21:41 +02:00
  • 3562dab445
    fix(lua-rockspec): handle empty and whitespace-only rockspec files gracefully (#4827) Akihiko Komada 2026-04-25 01:44:25 +09:00
  • 014a4c9c59
    chore: tidy go.mod (#4823) Sebastiaan van Stijn 2026-04-24 00:07:11 +02:00
  • 3cb838eacf
    fixed pe dotnet wrong ver , fixed #4813 (#4814) Rez Moss 2026-04-22 20:55:56 -04:00
  • 758324b3e8
    fix: propagate non-EOF errors out of safeCopy (#4807) Sai Asish Y 2026-04-22 09:06:03 -07:00
  • 390cf6cce0
    chore(deps): update anchore dependencies (#4797) v1.43.0 anchore-oss-update-bot 2026-04-22 11:09:10 -04:00
  • 4393654d03
    Chore fix sync bump (#4809) Will Murphy 2026-04-22 08:48:30 -04:00
  • d179724f42
    fix: improve redhat-release parsing fallback for RHEL clones (#4808) Weston Steimel 2026-04-22 13:48:08 +01:00
  • 2ddaaac706
    restore go minimum version to 1.25.8 (#4805) Alex Goodman 2026-04-21 15:20:14 -04:00
  • 073b4c5d55
    chore(deps): restore Go version to 1.25.8 (#4804) Alex Goodman 2026-04-21 15:02:26 -04:00
  • ff6c34de7e
    fix: improve haskell classifiers (#4793) witchcraze 2026-04-21 01:23:35 +09:00
  • 66ba575ae2
    chore(deps): bump the actions-minor-patch group across 1 directory with 2 updates (#4790) dependabot[bot] 2026-04-20 10:13:26 -04:00
  • ed306c2a6d
    chore(deps): bump github.com/go-git/go-git/v5 from 5.17.0 to 5.18.0 (#4792) dependabot[bot] 2026-04-20 10:09:31 -04:00
  • 33bc4b8397
    chore(deps): update Go version (#4798) anchore-oss-update-bot 2026-04-20 10:03:15 -04:00
  • 89e4e609d5
    fix: update jruby download URLs from S3 to GitHub Releases (#4799) Alex Goodman 2026-04-20 09:12:09 -04:00
  • 076fb211cc
    fix(cyclonedx): conditionally exclude group from package name (#4791) David Dashti 2026-04-18 02:21:21 +02:00
  • 26175d74f8
    fix: consul classifier (#4741) witchcraze 2026-04-17 23:38:24 +09:00
  • 9b58efed0c
    chore(deps): update tools to latest versions (#4701) anchore-actions-token-generator[bot] 2026-04-16 15:39:39 -04:00
  • 30fe53e629
    fix(javascript): accept scalar people fields in package.json (#4779) Yoav Alon 2026-04-15 21:21:49 +03:00
  • 952469f0f0
    update vault classifier (#4742) witchcraze 2026-04-15 23:41:37 +09:00
  • 4321ecc66f
    fix(javascript): ensure deterministic pnpm lockfile parsing (#4765) chaoliang yan 2026-04-16 00:39:57 +10:00
  • 5b58ec96b7
    chore(deps): update Go version (#4773) anchore-oss-update-bot 2026-04-15 10:01:39 -04:00
  • 26e87c7cd3
    fix format string in search results (#4775) Will Murphy 2026-04-14 12:59:44 -04:00
  • 722e3f267b
    added deno bin classifiers (#4677) Rez Moss 2026-04-14 11:33:26 -04:00
  • c09f42e024
    feat: support zImage and bzImage in linux-kernel-cataloger (#4751) nadimz 2026-04-14 16:02:20 +02:00
  • 19b4f41270
    pin wolfi cache version (#4774) Alex Goodman 2026-04-14 09:15:24 -04:00
  • bcc1f15ceb
    feat: OpenLDAP binary classifier (#4755) nadimz 2026-04-13 22:27:48 +02:00
  • ce2c56bf06
    chore(deps): bump github.com/aws/aws-sdk-go-v2/service/s3 (#4750) dependabot[bot] 2026-04-13 15:47:17 -04:00
  • 532fbafe36
    chore(deps): bump go.opentelemetry.io/otel/sdk from 1.40.0 to 1.43.0 (#4752) dependabot[bot] 2026-04-13 15:22:53 -04:00
  • 8835af66b0
    chore(deps): bump github.com/go-jose/go-jose/v4 from 4.1.3 to 4.1.4 (#4737) dependabot[bot] 2026-04-13 14:58:53 -04:00
  • f4290cb876
    chore(deps): bump the actions-minor-patch group across 2 directories with 7 updates (#4763) dependabot[bot] 2026-04-13 11:39:21 -04:00
  • 990cc3c599
    chore(deps): bump github.com/hashicorp/go-getter from 1.8.5 to 1.8.6 (#4764) dependabot[bot] 2026-04-13 11:39:08 -04:00
  • 03d6399b0c
    fix: update erlang classifier (#4766) witchcraze 2026-04-14 00:31:19 +09:00
  • 1e08f703d0
    chore(deps): update CPE dictionary index (#4767) anchore-oss-update-bot 2026-04-13 11:28:50 -04:00
  • e420322494
    fix: more istio classifier matching (#4645) witchcraze 2026-04-12 23:54:08 +09:00
  • cc3b8eb48f
    fix(json): use value alias in Document.UnmarshalJSON to prevent infinite recursion with encoding/json/v2 (#4748) Benjamin Grandfond 2026-04-10 19:36:07 +02:00
  • d0ee9098cf
    bump version (#4756) Alex Goodman 2026-04-09 17:11:47 -04:00
  • 344d1f47a1
    support single arch images without manifests when checking platform (#4753) Alex Goodman 2026-04-09 11:54:41 -04:00
  • f618917527
    chore(deps): update CPE dictionary index (#4745) v1.42.4 anchore-oss-update-bot 2026-04-08 13:06:28 -04:00
  • 99158be0ba
    chore: move test fixtures to oss-cache repo (#4733) Will Murphy 2026-04-02 16:50:43 -04:00
  • 2089d086fe
    chore: update zizmor workflow triggers (#4732) Alex Goodman 2026-04-02 14:56:46 -04:00
  • b0dc65a4fb
    improve automation (#4730) Alex Goodman 2026-04-02 12:44:54 -04:00
  • 611a24fcae
    (chore): removing automations (#4727) Alex Goodman 2026-04-01 14:27:29 -04:00
  • da601363ed
    chore(deps): update CPE dictionary index (#4726) anchore-oss-update-bot 2026-04-01 10:24:27 -04:00
  • 0d748ec700
    chore: cpe index update job needs tools (#4725) Will Murphy 2026-04-01 09:35:17 -04:00
  • d60e43f822
    chore: move CPE cache to oss-cache repo (#4723) Will Murphy 2026-04-01 06:57:47 -04:00
  • 2884cc77fc
    chore(deps): update CPE dictionary index (#4715) anchore-actions-token-generator[bot] 2026-03-31 14:28:15 -04:00
  • c11a79ef19
    chore(deps): update tool versions (#4706) anchore-oss-update-bot 2026-03-31 14:06:07 -04:00
  • 1a8caa2665 chore: make CPE_CACHE_REGISTRY configurable chore-configurable-cache-location Will Murphy 2026-03-30 14:32:02 -04:00
  • 90198da04d
    Add a trust boundary section (#4716) Josh Bressers 2026-03-30 11:29:37 -05:00
  • 677f4c0110
    remove workflows that update the code remove-update-workflows Alex Goodman 2026-03-27 12:24:02 -04:00
  • d71b747cd1
    chore(deps): bump slackapi/slack-github-action from 2.1.1 to 3.0.1 (#4684) dependabot[bot] 2026-03-26 11:12:33 -04:00
  • 58a8a95e26
    chore(deps): bump marocchino/sticky-pull-request-comment (#4685) dependabot[bot] 2026-03-25 19:27:59 -04:00
  • 78a21b9c88
    chore(deps): bump the go-minor-patch group with 2 updates (#4697) dependabot[bot] 2026-03-25 19:27:50 -04:00
  • 7d3882a425
    chore(deps): bump actions/create-github-app-token from 2.2.1 to 3.0.0 (#4699) dependabot[bot] 2026-03-25 19:27:31 -04:00
  • 673c85754c
    chore(deps): update CPE dictionary index (#4689) anchore-actions-token-generator[bot] 2026-03-25 08:38:49 -04:00
  • c5114fd745
    chore(deps): ignore some dependabot deps (#4696) Will Murphy 2026-03-24 08:12:50 -04:00
  • f68a7cc899
    ci: further pr target code checkout assurances (#4695) Weston Steimel 2026-03-24 11:16:16 +00:00
  • 7800b16529
    fix: update arangodb classifier and capture-snippet.sh (#4662) witchcraze 2026-03-24 05:29:39 +09:00
  • 834ddcb1c0
    fix: golang version file regex (#4694) Keith Zantow 2026-03-23 15:56:29 -04:00
  • f5d318d934
    ci: add explicit ref to main and warning for pull_request_target workflow (#4693) Weston Steimel 2026-03-23 16:45:18 +00:00
  • 8531e1917b
    chore(deps): update tools to latest versions (#4690) anchore-actions-token-generator[bot] 2026-03-23 12:01:27 -04:00
  • 1f2a299cb5
    test: add failing CPE formatting for colons cpe-formatting-fixes Weston Steimel 2026-03-23 15:47:12 +00:00
  • 860126c650
    chore(deps): update anchore dependencies (#4681) v1.42.3 anchore-actions-token-generator[bot] 2026-03-19 16:44:55 +00:00
  • 36639f136b
    chore(deps): bump github.com/buger/jsonsparser to v1.1.2 (#4680) Will Murphy 2026-03-19 11:08:18 -04:00
  • f32238c268
    chore(deps): bump the go-minor-patch group with 2 updates (#4678) dependabot[bot] 2026-03-19 10:25:19 -04:00
  • 0c8eef65f0
    chore(deps): bump google.golang.org/grpc from 1.78.0 to 1.79.3 (#4675) dependabot[bot] 2026-03-18 16:55:30 -04:00
  • 4d42f8af32
    chore(deps): bump the go-minor-patch group with 2 updates (#4674) dependabot[bot] 2026-03-18 16:13:35 -04:00
  • e38851143e
    chore: centralize temp files and prefer streaming IO (#4668) Will Murphy 2026-03-18 10:53:51 -04:00