Commit Graph

  • 8a41d77250
    chore: prevent file resolver from bubbling errors in binary cataloger (#3410) v1.16.0 Christopher Angelo Phillips 2024-11-04 15:23:27 -05:00
  • eb56f2e4bb
    chore(deps): update stereoscope to cbd43fb4e5d348fe680066ee6329385fd6a4f827 (#3411) anchore-actions-token-generator[bot] 2024-11-04 10:20:27 -05:00
  • 849e325408
    chore(deps): update CPE dictionary index (#3414) anchore-actions-token-generator[bot] 2024-11-04 10:13:22 -05:00
  • 203df65a65
    chore(deps): bump github.com/adrg/xdg from 0.5.2 to 0.5.3 (#3408) dependabot[bot] 2024-11-01 11:43:54 -04:00
  • 2c70090d10
    chore(deps): bump github.com/charmbracelet/lipgloss from 0.13.1 to 1.0.0 (#3409) dependabot[bot] 2024-11-01 11:43:47 -04:00
  • 8f179e6961
    chore(deps): update stereoscope to 2ce1e520983b1c21d5150d7fae2b39e8e5ab9063 (#3405) anchore-actions-token-generator[bot] 2024-11-01 11:43:39 -04:00
  • 6a1e3f32fe
    Issue #3143 – fixed format conversion docs link (#3407) Artemii 2024-11-01 16:43:00 +01:00
  • fcf1350a0e
    feat: support dependencies and purl for Native Image SBOMs (#3399) Joel Rudsberg 2024-10-31 17:12:54 +01:00
  • 9302e20d62
    chore(deps): update stereoscope to 9c92fe30492ffeba14ed2e23ad1fd923341dda4f (#3398) anchore-actions-token-generator[bot] 2024-10-31 10:22:14 -04:00
  • a55b71d4ef
    feat: exclude devDependencies from package-lock.json parsing (#3371) Nathan Voss 2024-10-30 09:02:27 -07:00
  • df3998b4f1
    chore(deps): bump github.com/adrg/xdg from 0.5.1 to 0.5.2 (#3394) dependabot[bot] 2024-10-29 16:32:14 +00:00
  • 9dc9be645a
    chore(deps): bump anchore/sbom-action from 0.17.5 to 0.17.6 (#3393) dependabot[bot] 2024-10-29 10:07:28 -04:00
  • 798c18a698
    fix: stack overflow in spyingIoReadCloser (#3392) Keith Zantow 2024-10-29 08:23:57 -04:00
  • 1118ac4ace
    fix: bad pom files may cause infinite loop (#3391) Keith Zantow 2024-10-28 18:09:04 -04:00
  • 55cc1877ef
    chore(deps): update stereoscope to bcc40c6817524718277256d6b774ce643f98640a (#3388) v1.15.0 anchore-actions-token-generator[bot] 2024-10-28 19:48:04 +00:00
  • 367c699585
    chore(deps): bump actions/setup-go from 5.0.2 to 5.1.0 (#3384) dependabot[bot] 2024-10-28 14:09:45 -04:00
  • 46445ff29f
    chore(deps): bump github.com/charmbracelet/bubbletea from 1.1.1 to 1.1.2 (#3385) dependabot[bot] 2024-10-28 14:08:44 -04:00
  • 5faa6d34d5
    chore(deps): update tools to latest versions (#3383) anchore-actions-token-generator[bot] 2024-10-28 14:08:14 -04:00
  • c7c036660c
    chore(deps): update CPE dictionary index (#3387) anchore-actions-token-generator[bot] 2024-10-28 08:03:08 -04:00
  • a0c62da747
    chore(deps): bump actions/checkout from 4.2.1 to 4.2.2 (#3380) dependabot[bot] 2024-10-24 10:35:47 -04:00
  • 759b898df5
    feat: multi-level configuration and profiles (#3337) Keith Zantow 2024-10-23 12:15:59 -04:00
  • a00533c836
    feat: Java dependency graph information (#3363) Keith Zantow 2024-10-23 11:17:34 -04:00
  • b505317e10
    Expanded dpkg cataloger globs (#3373) Nathan Voss 2024-10-23 07:59:28 -07:00
  • 06d300e662
    Enable cargo-auditable-binary-cataloger for files/directories (#3376) Ariel Miculas-Trif 2024-10-23 17:55:04 +03:00
  • 80333d39e3
    chore(deps): bump github/codeql-action from 3.26.13 to 3.27.0 (#3374) dependabot[bot] 2024-10-23 10:47:12 -04:00
  • 11335466b6
    chore(deps): bump github.com/charmbracelet/lipgloss (#3375) dependabot[bot] 2024-10-23 10:46:52 -04:00
  • 260d80974f
    chore(deps): update stereoscope to 6db3c175f1f836e552b01ee70e5d5528cc04bce4 (#3362) anchore-actions-token-generator[bot] 2024-10-22 12:23:29 -04:00
  • fc524a0565
    chore(deps): bump actions/cache from 4.1.1 to 4.1.2 (#3364) dependabot[bot] 2024-10-22 12:23:13 -04:00
  • b5cde1304b
    chore(deps): bump anchore/sbom-action from 0.17.4 to 0.17.5 (#3365) dependabot[bot] 2024-10-22 12:22:27 -04:00
  • 6a2898e00d
    chore(deps): bump github.com/go-git/go-billy/v5 from 5.5.0 to 5.6.0 (#3367) dependabot[bot] 2024-10-22 12:22:19 -04:00
  • c5fba2d0e4
    rename testing license scanner v1.13.1-performance-fix Alex Goodman 2024-10-21 12:08:17 -04:00
  • 4fd1828ba9
    add single license scanner instance Alex Goodman 2024-10-18 16:26:10 -04:00
  • e4e985b9b0
    Create single license scanner for all catalogers (#3348) v1.14.2 Alex Goodman 2024-10-21 12:17:12 -04:00
  • 14355aac21
    chore(deps): update stereoscope to a38c93517fc7d67ca1af826ac529a06c05b571d2 (#3357) anchore-actions-token-generator[bot] 2024-10-21 10:05:43 -04:00
  • e38825a0a2
    chore(deps): update CPE dictionary index (#3358) anchore-actions-token-generator[bot] 2024-10-21 10:04:25 -04:00
  • 5a37b4a996
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.0 to 6.6.1 (#3361) dependabot[bot] 2024-10-21 14:02:07 +00:00
  • 56dbb342ef
    update to latest packageurl-go (#3347) Alex Goodman 2024-10-18 14:47:02 -04:00
  • 3267545097
    chore(deps): update tools to latest versions (#3342) anchore-actions-token-generator[bot] 2024-10-17 10:05:38 -04:00
  • 7adbdfe624
    chore(deps): update stereoscope to 9e57bce5efeb0ffe27770dd0b8eb2eef8b38512f (#3338) anchore-actions-token-generator[bot] 2024-10-17 10:05:18 -04:00
  • f2646d0156
    chore(deps): bump github.com/adrg/xdg from 0.5.0 to 0.5.1 (#3344) dependabot[bot] 2024-10-17 09:58:16 -04:00
  • 5b9601d9c6
    fix: use official CPE for linux kernel (#3343) Weston Steimel 2024-10-17 12:01:40 +00:00
  • 80c8bc1afb
    chore(deps): bump anchore/sbom-action from 0.17.3 to 0.17.4 (#3340) dependabot[bot] 2024-10-16 12:44:07 -04:00
  • d7194bb00f
    fix: improve mariadb binary classifer to detect older versions (#3339) Weston Steimel 2024-10-16 16:43:50 +00:00
  • 754cebee64
    fix: stop some log.Warn spam due parsing an empty string as a CPE (#3330) v1.14.1 William Murphy 2024-10-15 08:50:47 -04:00
  • 138c6e3420
    chore(deps): update stereoscope to 1cc8a41d447d0d092699be2b700b8ba62e870434 (#3334) anchore-actions-token-generator[bot] 2024-10-15 12:45:07 +00:00
  • 5c0df6386f
    chore(deps): update stereoscope to 1cc8a41d447d0d092699be2b700b8ba62e870434 (#3332) anchore-actions-token-generator[bot] 2024-10-14 21:37:26 +00:00
  • 7c69367b65
    chore(deps): update stereoscope to 93f8a11331e3d50f751e4d0ec5b63f3df309e9e5 (#3331) anchore-actions-token-generator[bot] 2024-10-14 20:03:16 +00:00
  • 39146aaf62
    chore(deps): bump anchore/sbom-action from 0.17.2 to 0.17.3 (#3326) dependabot[bot] 2024-10-14 11:46:47 -04:00
  • 67faca4208
    chore(deps): bump github/codeql-action from 3.26.12 to 3.26.13 (#3327) dependabot[bot] 2024-10-14 14:06:08 +00:00
  • f6e5405eb8
    chore(deps): update CPE dictionary index (#3323) anchore-actions-token-generator[bot] 2024-10-14 09:42:20 -04:00
  • e962c10da7
    fix: improve go binary semver extraction for traefik (#3325) Weston Steimel 2024-10-14 13:41:34 +00:00
  • 8095f7b8c1
    chore(deps): update stereoscope to 92e97a1cf36d162bad51ccc6aba0cce7a4dcfbf4 (#3322) anchore-actions-token-generator[bot] 2024-10-13 10:53:58 -04:00
  • 84877369e5
    chore(deps): update stereoscope to c04af061af62ab3ba6ab6760613526eaa7fcb163 (#3319) anchore-actions-token-generator[bot] 2024-10-11 12:30:20 -04:00
  • 6124d72a29
    chore(deps): bump github.com/bmatcuk/doublestar/v4 from 4.6.1 to 4.7.0 (#3321) dependabot[bot] 2024-10-11 10:09:14 -04:00
  • c2c8c793d2
    chore(deps): bump actions/upload-artifact from 4.4.1 to 4.4.3 (#3314) dependabot[bot] 2024-10-11 05:17:35 -04:00
  • fbff87fc6d
    shorten release docs (#3318) Alex Goodman 2024-10-11 05:17:01 -04:00
  • 0c71bf23c5
    docs: clearer deprecation message for --file (#3310) William Murphy 2024-10-10 13:11:45 -04:00
  • b62b0cb800
    [docs] Add mastodon link to README.md (#3306) Alan Pope 2024-10-10 15:28:55 +01:00
  • 223a52d07e
    chore(deps): update stereoscope to 5bc91bf166769e43d8d0f86c02e877c55eb04aed (#3313) anchore-actions-token-generator[bot] 2024-10-10 06:03:55 -04:00
  • 5d068f30c0
    chore(deps): bump actions/cache from 4.1.0 to 4.1.1 (#3312) dependabot[bot] 2024-10-10 06:01:06 -04:00
  • 5d165e0230
    chore(deps): bump github/codeql-action from 3.26.11 to 3.26.12 (#3307) dependabot[bot] 2024-10-09 08:07:36 -04:00
  • 56ed131247
    chore(deps): bump actions/checkout from 4.2.0 to 4.2.1 (#3308) dependabot[bot] 2024-10-09 08:07:14 -04:00
  • 37c179b530
    chore(deps): bump actions/upload-artifact from 4.4.0 to 4.4.1 (#3309) dependabot[bot] 2024-10-09 08:06:49 -04:00
  • a3bd5145d2 wire up bitnami cataloger to run on images by default spike-bitnami-cataloger Will Murphy 2024-10-08 14:14:23 -04:00
  • 6a33b80048 prototype: start bitnami cataloger Will Murphy 2024-10-08 09:31:33 -04:00
  • ccbee94b87
    feat: report unknowns in sbom (#2998) v1.14.0 Keith Zantow 2024-10-07 16:11:37 -04:00
  • 4d7ed9f749
    chore(deps): bump sigstore/cosign-installer from 3.6.0 to 3.7.0 (#3299) dependabot[bot] 2024-10-07 15:21:34 -04:00
  • 4c4e5cb06c
    chore(deps): update stereoscope to efa76446cc1c7e6c4117350943a2754b2453aec4 (#3301) anchore-actions-token-generator[bot] 2024-10-07 15:21:26 -04:00
  • 8b6159dbd8
    chore(deps): bump golang.org/x/net from 0.29.0 to 0.30.0 (#3304) dependabot[bot] 2024-10-07 15:20:38 -04:00
  • 7b30ce15d7
    chore(deps): bump actions/cache from 4.0.2 to 4.1.0 (#3305) dependabot[bot] 2024-10-07 15:20:29 -04:00
  • 27ee203495
    chore(deps): update CPE dictionary index (#3302) anchore-actions-token-generator[bot] 2024-10-07 15:20:12 -04:00
  • 3b9c55d28b
    Fix: Parse package.json with non-standard fields in 'author' section (#3300) Piotr Radkowski 2024-10-07 16:26:04 +02:00
  • 25f5c6729f
    chore(deps): bump github/codeql-action from 3.26.10 to 3.26.11 (#3298) dependabot[bot] 2024-10-05 09:25:01 -04:00
  • 0d457142cc
    chore: add pull request template (#3294) William Murphy 2024-10-05 09:05:11 -04:00
  • fc8457418a
    chore(deps): update tools to latest versions (#3296) anchore-actions-token-generator[bot] 2024-10-05 07:32:32 -04:00
  • 13c6876906
    Track supporting DPKG evidence (#3228) Alex Goodman 2024-10-04 11:07:29 -04:00
  • 770fdc53ea
    Fix: make failed CPE validation correctly return error (#2762) William Murphy 2024-10-03 16:42:57 -04:00
  • 32c0d1e673
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.5.9 to 6.6.0 (#3293) dependabot[bot] 2024-10-03 10:14:13 -04:00
  • 263ea6b1bb
    feat: update haproxy classifier (#3277) witchcraze 2024-10-03 04:10:39 +09:00
  • cc4f62b3d4
    chore(deps): update tools to latest versions (#3291) anchore-actions-token-generator[bot] 2024-10-02 09:07:25 -04:00
  • dbad17de9e
    fix: don't use builtin scanner in licensecheck (#3290) Niv Govrin 2024-10-01 20:53:54 +03:00
  • 93beceb4a2
    chore(deps): update CPE dictionary index (#3288) anchore-actions-token-generator[bot] 2024-10-01 10:50:15 -04:00
  • 9b242b0309
    chore(deps): bump github/codeql-action from 3.26.9 to 3.26.10 (#3289) dependabot[bot] 2024-10-01 10:48:46 -04:00
  • edd910f88f [wip] more concurrent catalogers more-concurrent-catalogers Alex Goodman 2024-10-01 10:18:44 -04:00
  • f5f8005fe0
    update redis classifier (#3281) witchcraze 2024-10-01 04:37:47 +09:00
  • 2a3d171c10
    fix: improve node classifier version matching (#3284) witchcraze 2024-09-27 21:53:35 +09:00
  • 1a746b2c05
    fix: update ruby classifier for -rc, -dev, etc. versions (#3285) witchcraze 2024-09-27 21:51:50 +09:00
  • e37c4686c2
    chore(deps): update CPE dictionary index (#3262) anchore-actions-token-generator[bot] 2024-09-26 13:49:18 -04:00
  • 5393cd5dec
    chore(deps): bump github.com/docker/docker (#3264) dependabot[bot] 2024-09-26 13:49:02 -04:00
  • f9ef9cf1dc
    chore(deps): bump github/codeql-action from 3.26.8 to 3.26.9 (#3275) dependabot[bot] 2024-09-26 13:48:45 -04:00
  • 16122eb32d
    chore(deps): update stereoscope to dc10ea61fd18efa45b516eda4de8bc19d8322429 (#3280) anchore-actions-token-generator[bot] 2024-09-26 13:48:33 -04:00
  • 39b2bf5518
    chore(deps): bump actions/checkout from 4.1.7 to 4.2.0 (#3283) dependabot[bot] 2024-09-26 13:48:12 -04:00
  • d7005d7d8c
    add awaiting response management (#3272) Alex Goodman 2024-09-25 08:56:21 -04:00
  • 92c1ddec5a
    fix: correct excluded mount point comparison to file paths (#3269) Christian Dupuis 2024-09-24 23:05:16 +02:00
  • 01de99b253
    Add JVM cataloger (#3217) v1.13.0 1.13.x Alex Goodman 2024-09-23 17:21:38 -04:00
  • 7815d8e4d9
    feat: classifier for Dart lang binaries (#3265) Laurent Goderre 2024-09-23 14:21:31 -04:00
  • 963ea594c8
    Add compliance policy for empty name and version (#3257) Alex Goodman 2024-09-20 12:50:47 -04:00
  • 60bbd24031
    chore(deps): bump github.com/github/go-spdx/v2 from 2.3.1 to 2.3.2 (#3254) dependabot[bot] 2024-09-20 10:50:16 -04:00
  • 7c12e3f3b3
    chore(deps): bump peter-evans/create-pull-request from 7.0.3 to 7.0.5 (#3255) dependabot[bot] 2024-09-20 10:50:03 -04:00
  • 9b5cf1db51
    chore(deps): bump github/codeql-action from 3.26.7 to 3.26.8 (#3256) dependabot[bot] 2024-09-20 10:49:55 -04:00