Commit Graph

  • a08ea86aa6
    chore(deps): update tools to latest versions (#3259) anchore-actions-token-generator[bot] 2024-09-20 10:49:37 -04:00
  • 98c96ce361
    chore(deps): bump github.com/docker/docker (#3260) dependabot[bot] 2024-09-20 10:49:22 -04:00
  • 6a95a5f2ed
    feat: add binary classifiers for lighttp, proftpd, zstd, xz, gzip, jq, and sqlcipher (#3252) Krystian G. 2024-09-19 15:21:02 +02:00
  • cb0de97bc3
    fix: capture-snippet.sh can handle leading whitespaces now (#3249) (#3250) Krystian G. 2024-09-19 15:15:54 +02:00
  • 50016c3172
    chore(deps): update tools to latest versions (#3251) anchore-actions-token-generator[bot] 2024-09-19 09:15:12 -04:00
  • a2f12fef0c
    chore(deps): update tools to latest versions (#3247) anchore-actions-token-generator[bot] 2024-09-18 13:13:24 -04:00
  • 7934696463
    chore(deps): update tools to latest versions (#3243) anchore-actions-token-generator[bot] 2024-09-17 12:30:07 -04:00
  • b9efac4d78
    chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.9.0 to 0.9.1 (#3242) dependabot[bot] 2024-09-16 11:54:12 -04:00
  • 48c1c45d12
    chore(deps): bump github/codeql-action from 3.26.6 to 3.26.7 (#3241) dependabot[bot] 2024-09-16 11:54:01 -04:00
  • 9cc3641ac6
    chore(deps): bump peter-evans/create-pull-request from 7.0.2 to 7.0.3 (#3240) dependabot[bot] 2024-09-16 11:53:51 -04:00
  • 7b4feb7c16
    chore(deps): update tools to latest versions (#3231) anchore-actions-token-generator[bot] 2024-09-16 09:09:11 -04:00
  • 41e9630409
    chore(deps): update CPE dictionary index (#3232) anchore-actions-token-generator[bot] 2024-09-16 09:08:50 -04:00
  • 58100fec9f
    chore(deps): update tools to latest versions (#3205) anchore-actions-token-generator[bot] 2024-09-13 15:05:50 -04:00
  • 834027e32d
    chore(deps): bump github.com/charmbracelet/bubbletea from 1.1.0 to 1.1.1 (#3225) dependabot[bot] 2024-09-13 13:51:17 -04:00
  • 2b4d5c275f
    chore(deps): bump peter-evans/create-pull-request from 7.0.1 to 7.0.2 (#3226) dependabot[bot] 2024-09-13 11:31:09 -04:00
  • 38e51f16ec
    chore(deps): bump modernc.org/sqlite from 1.33.0 to 1.33.1 (#3229) dependabot[bot] 2024-09-13 11:30:58 -04:00
  • 1b863268df
    feat: --enrich flag for data enrichment feature enablement (#3182) Keith Zantow 2024-09-12 10:45:18 -04:00
  • fcd5ec951d
    chore: make ci-check.sh an executable file (#3220) v1.12.2 Ryuichi Okumura 2024-09-11 23:02:37 +09:00
  • 362de2f3b6
    chore: ci-check.sh script +x chore/ci-check-permissions Keith Zantow 2024-09-11 09:59:02 -04:00
  • 61a9fde01c
    chore(deps): bump github.com/opencontainers/runc from 1.1.12 to 1.1.14 (#3219) dependabot[bot] 2024-09-10 21:20:43 +00:00
  • c33a51d3d8
    chore: restore ci-check.sh script (#3218) v1.12.1 Keith Zantow 2024-09-10 15:19:05 -04:00
  • dbc4238f63
    Add haskell binaries cataloger (#3078) v1.12.0 Laurent Goderre 2024-09-10 10:58:20 -04:00
  • fce14fd537
    chore(deps): update CPE dictionary index (#3206) anchore-actions-token-generator[bot] 2024-09-10 10:36:50 -04:00
  • 98bd4e99b6
    chore(deps): bump golang.org/x/net from 0.28.0 to 0.29.0 (#3203) dependabot[bot] 2024-09-10 10:35:43 -04:00
  • 9c2799e379
    Add the Ocaml ecosystem (#3112) Laurent Goderre 2024-09-10 10:35:18 -04:00
  • dafc6ad034
    chore(deps): bump github.com/charmbracelet/bubbles from 0.19.0 to 0.20.0 (#3209) dependabot[bot] 2024-09-09 16:28:01 -04:00
  • 16f89840fd
    chore(deps): bump modernc.org/sqlite from 1.32.0 to 1.33.0 (#3210) dependabot[bot] 2024-09-09 16:27:52 -04:00
  • 2475f7f696
    chore(deps): bump github.com/docker/docker (#3211) dependabot[bot] 2024-09-09 16:27:43 -04:00
  • f735a428eb
    chore(deps): bump github.com/dave/jennifer from 1.7.0 to 1.7.1 (#3212) dependabot[bot] 2024-09-09 16:27:33 -04:00
  • ba7bf6b85e
    dont cleanup cache in forks (#3214) Alex Goodman 2024-09-09 16:27:21 -04:00
  • b153b1d594
    less verbose java logging when non-fatal issues arise (#3208) Alex Goodman 2024-09-09 11:27:59 -04:00
  • 0a3f513f92
    Slim down docker cache size (#3190) Alex Goodman 2024-09-09 11:15:13 -04:00
  • deabd4115a
    chore(deps): bump peter-evans/create-pull-request from 7.0.0 to 7.0.1 (#3196) dependabot[bot] 2024-09-05 15:06:23 -04:00
  • ff0bae67bd
    chore(deps): bump golang.org/x/mod from 0.20.0 to 0.21.0 (#3197) dependabot[bot] 2024-09-05 15:05:15 -04:00
  • a343825685
    fix: haproxy classifier for versions with -dev suffix (#3180) witchcraze 2024-09-06 03:52:19 +09:00
  • 7c96a10cbe
    chore(deps): bump github.com/Masterminds/sprig/v3 from 3.2.3 to 3.3.0 (#3177) dependabot[bot] 2024-09-03 12:22:43 -04:00
  • 8c690d000d
    chore(deps): update CPE dictionary index (#3183) anchore-actions-token-generator[bot] 2024-09-03 12:22:30 -04:00
  • 8ade391658
    chore(deps): bump actions/upload-artifact from 4.3.6 to 4.4.0 (#3184) dependabot[bot] 2024-09-03 12:22:16 -04:00
  • e299a95120
    chore(deps): bump peter-evans/create-pull-request from 6.1.0 to 7.0.0 (#3187) dependabot[bot] 2024-09-03 12:22:07 -04:00
  • f2caf45695
    fix: properly decode SPDX license expressions in CycloneDX format (#3175) Mikail 2024-08-29 17:05:43 +02:00
  • 731fc77641
    chore(deps): bump github.com/docker/docker (#3168) dependabot[bot] 2024-08-29 14:16:50 +00:00
  • 3499d92c6d
    chore(deps): bump github.com/charmbracelet/bubbletea (#3171) dependabot[bot] 2024-08-29 14:16:43 +00:00
  • 19d2735aff
    chore(deps): bump github/codeql-action from 3.26.5 to 3.26.6 (#3173) dependabot[bot] 2024-08-29 14:16:34 +00:00
  • 11d77b4a94
    fix: cycles resolving relative path parent poms with parent-defined variables (#3170) Keith Zantow 2024-08-28 15:12:13 -04:00
  • 2c25f81b68
    fix: improve generated cpes for binaries with existing classifiers (#3169) Weston Steimel 2024-08-28 16:46:35 +01:00
  • 04e3371cce
    fix: add log time of task (#3105) GGMU 2024-08-28 18:04:26 +03:00
  • 5ab43bafec
    fix: improve known CPEs and set NVD as source for all current binary classifiers (#3167) Weston Steimel 2024-08-27 17:36:34 +01:00
  • e9a8c27be1
    respond to authoratative CPEs from catalogers (#3166) Alex Goodman 2024-08-27 10:26:35 -04:00
  • 4ee6c179f8
    set cataloger names within package cataloger task (#3165) Alex Goodman 2024-08-27 09:23:43 -04:00
  • 99be365f62
    fix: use official CPE for curl binary cataloger (#3164) Weston Steimel 2024-08-27 14:03:19 +01:00
  • cf9bb13f2b
    chore(deps): update tools to latest versions (#3160) anchore-actions-token-generator[bot] 2024-08-26 10:07:59 -04:00
  • 0cd6185716
    chore(deps): update CPE dictionary index (#3161) anchore-actions-token-generator[bot] 2024-08-26 10:07:44 -04:00
  • 6549ec9831
    chore(deps): bump github/codeql-action from 3.26.4 to 3.26.5 (#3162) dependabot[bot] 2024-08-26 10:07:18 -04:00
  • b6b5c8e308
    fix ELF package correlations (#3151) Alex Goodman 2024-08-26 08:44:39 -04:00
  • dad253785e
    chore(deps): update tools to latest versions (#3144) anchore-actions-token-generator[bot] 2024-08-23 14:42:12 -04:00
  • cff9d494df
    feat: detect curl binaries (#3146) KrysGor 2024-08-23 20:41:08 +02:00
  • 9ab3de1819
    chore(deps): bump anchore/sbom-action from 0.17.1 to 0.17.2 (#3155) dependabot[bot] 2024-08-22 13:52:58 -04:00
  • 6f0230879a
    chore(deps): bump github/codeql-action from 3.26.3 to 3.26.4 (#3154) dependabot[bot] 2024-08-22 13:52:48 -04:00
  • 691f34ce27
    chore(deps): update stereoscope to e6d086e8bef5fab4fcfbd60c9a759c4cb229decf (#3152) anchore-actions-token-generator[bot] 2024-08-22 13:52:34 -04:00
  • ac977246c9
    chore(deps): bump github.com/charmbracelet/bubbles from 0.18.0 to 0.19.0 (#3148) dependabot[bot] 2024-08-22 13:52:06 -04:00
  • 78d48b4209
    chore(deps): bump github.com/charmbracelet/lipgloss (#3147) dependabot[bot] 2024-08-22 13:51:57 -04:00
  • bd80eeafac
    chore(deps): bump github.com/anchore/stereoscope (#3153) dependabot[bot] 2024-08-22 13:51:50 -04:00
  • 73b9d5aa42
    fix: mysql 8.0.3x binary detection (#3142) Keith Zantow 2024-08-21 09:48:28 -04:00
  • f786233e97
    chore(deps): bump github/codeql-action from 3.26.2 to 3.26.3 (#3139) dependabot[bot] 2024-08-20 23:04:58 +00:00
  • 95b4a88256
    fix: logging for remote network calls (#3140) v1.11.1 Keith Zantow 2024-08-20 11:45:33 -04:00
  • 511cc9c2d5
    chore(deps): update CPE dictionary index (#3135) anchore-actions-token-generator[bot] 2024-08-19 12:49:43 -04:00
  • 360983f75b
    chore(deps): bump github.com/charmbracelet/bubbletea (#3137) dependabot[bot] 2024-08-19 12:48:24 -04:00
  • 4b7ae0ed3b
    chore(deps): update tools to latest versions (#3121) anchore-actions-token-generator[bot] 2024-08-16 17:56:36 +00:00
  • 4ff60ee837
    chore(deps): bump github.com/docker/docker (#3123) dependabot[bot] 2024-08-15 13:50:51 -04:00
  • 965000dcbb
    chore(deps): bump anchore/sbom-action from 0.17.0 to 0.17.1 (#3124) dependabot[bot] 2024-08-15 13:16:47 -04:00
  • a447884084
    chore(deps): bump github/codeql-action from 3.26.0 to 3.26.2 (#3129) dependabot[bot] 2024-08-15 13:16:39 -04:00
  • cd3b828905
    fix: add nil check to CycloneDX toBomProperties (#3119) Lucas Rodriguez 2024-08-13 15:02:15 -05:00
  • 3161e1847e
    fix: read CycloneDX BOM components from metadata (#3092) Lukas Voetmand 2024-08-12 22:37:23 +02:00
  • df1e5b57fe
    fix: improve groupid extraction for Jenkins plugins (#2815) Weston Steimel 2024-08-12 17:01:44 +00:00
  • d2b33f1acb
    chore(deps): update CPE dictionary index (#3116) anchore-actions-token-generator[bot] 2024-08-12 16:57:47 +00:00
  • 91cf066db6
    support .kar files (#3113) GGMU 2024-08-12 19:10:03 +03:00
  • c19cf626ab
    chore: fix some comments (#3114) luozexuan 2024-08-13 00:08:04 +08:00
  • cf85450e08
    chore: fix failing python relationship test (#3117) Keith Zantow 2024-08-12 12:07:47 -04:00
  • 49d4e32241
    update-slack-to-discourse (#3111) Alan Pope 2024-08-12 11:49:10 +01:00
  • 19cc664cf8
    test: increase java purl generation test coverage (#3110) v1.11.0 Weston Steimel 2024-08-09 10:14:10 +00:00
  • 64a9ecbf7a
    chore(deps): bump modernc.org/sqlite from 1.31.1 to 1.32.0 (#3106) dependabot[bot] 2024-08-08 15:49:45 -04:00
  • 6267d69930
    chore(deps): bump sigstore/cosign-installer from 3.5.0 to 3.6.0 (#3107) dependabot[bot] 2024-08-08 15:49:37 -04:00
  • 1fb47d908e
    chore(deps): update tools to latest versions (#3099) anchore-actions-token-generator[bot] 2024-08-07 14:26:05 -04:00
  • 2339743c8c
    chore(deps): bump github/codeql-action from 3.25.15 to 3.26.0 (#3101) dependabot[bot] 2024-08-07 14:25:52 -04:00
  • 9031592649
    chore(deps): bump actions/upload-artifact from 4.3.5 to 4.3.6 (#3102) dependabot[bot] 2024-08-07 14:25:44 -04:00
  • 47d192d79b
    chore(deps): bump github.com/google/go-containerregistry (#3103) dependabot[bot] 2024-08-07 14:25:36 -04:00
  • 040b683da8
    chore(deps): bump golang.org/x/net from 0.27.0 to 0.28.0 (#3104) dependabot[bot] 2024-08-07 14:25:28 -04:00
  • bb952ed25a
    Draft: Identity proof - do NOT merge identity-proof Alan Pope 2024-08-07 08:12:41 +01:00
  • dcd87d1fef
    chore(deps): bump actions/upload-artifact from 4.3.4 to 4.3.5 (#3095) dependabot[bot] 2024-08-06 13:17:36 -04:00
  • 214a0498e0
    chore(deps): update CPE dictionary index (#3094) anchore-actions-token-generator[bot] 2024-08-06 13:07:48 -04:00
  • 0f9df805c1
    chore(deps): bump golang.org/x/mod from 0.19.0 to 0.20.0 (#3096) dependabot[bot] 2024-08-06 13:07:33 -04:00
  • 703330abd0
    chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.6 to 0.5.7 (#3097) dependabot[bot] 2024-08-06 13:07:21 -04:00
  • 9d40d1152e
    feat: improved java maven property resolution (#2769) Gijs Calis 2024-08-05 17:30:47 +02:00
  • cc15edca62
    fix: use organization for package supplier when reading Java vendor fields (#3093) Harippriya Sivapatham 2024-08-04 01:30:55 +05:30
  • 623532e3ed
    chore(deps): update tools to latest versions (#3091) anchore-actions-token-generator[bot] 2024-08-02 13:25:09 -04:00
  • 48f1e975f0
    fix: update 'guessMainPackageNameAndVersionFromPomInfo' and 'artifactIDMatchesFilename' (#3054) Dor Hayun 2024-08-01 20:47:15 +03:00
  • c84cb2cf84
    fix: update mainModuleVersion function to always prefix v to findings (#3087) Christopher Angelo Phillips 2024-08-01 11:29:07 -04:00
  • 05a10e8bed
    chore: update release script to use gh from binny (#3084) Keith Zantow 2024-07-31 20:10:17 -04:00
  • 92d63df6f5
    Added the SWI Prolog (swipl) ecosystem (#3076) Laurent Goderre 2024-07-31 16:13:26 -04:00
  • a4b5dcd0df
    fix: improve determinism in java archive identification (#3085) v1.10.0 Keith Zantow 2024-07-30 12:02:52 -04:00