Commit Graph

  • 7071f1e498
    feat: Added functionality to convert major, minor, patch to version for binary classifier (#2864) Laurent Goderre 2024-05-23 12:17:12 -04:00
  • 3875e4a67d
    chore(deps): bump github.com/knqyf263/go-rpmdb from 0.1.0 to 0.1.1 (#2896) dependabot[bot] 2024-05-23 12:06:44 -04:00
  • a0f0332e30
    chore(deps): update tools to latest versions (#2887) anchore-actions-token-generator[bot] 2024-05-23 13:39:09 +00:00
  • ea50c6153d
    --- (#2889) dependabot[bot] 2024-05-23 09:26:12 -04:00
  • b41d5cced5
    chore: update spdx license list to 3.24.0 (#2895) Christopher Angelo Phillips 2024-05-23 09:10:36 -04:00
  • 68daa42f86
    --- (#2888) dependabot[bot] 2024-05-23 08:11:03 -04:00
  • 2356787053
    Go Mod Cataloger: Remove Replaced Packages (#2891) Russell Haering 2024-05-22 11:26:40 -07:00
  • 2d318cffaa
    chore(deps): bump actions/checkout from 4.1.5 to 4.1.6 (#2879) dependabot[bot] 2024-05-20 13:46:57 -04:00
  • 49c458b113
    chore: Reduce length of readme, moving lengthy content to the wiki (#2882) Alan Pope 2024-05-20 18:46:32 +01:00
  • 1144407591
    chore(deps): bump github.com/docker/docker (#2880) dependabot[bot] 2024-05-20 12:30:50 -04:00
  • 15808fbd04
    chore(deps): bump github.com/saferwall/pe from 1.5.2 to 1.5.3 (#2881) dependabot[bot] 2024-05-20 12:25:05 -04:00
  • 13ae56e3ef
    chore(deps): bump modernc.org/sqlite from 1.29.9 to 1.29.10 (#2885) dependabot[bot] 2024-05-20 11:59:28 -04:00
  • 1bec1fc5d3
    fix: DecoderCollection discarding input from non-seekable Readers (#2878) Russell Haering 2024-05-16 12:17:11 -07:00
  • 15c9fe092a
    chore(deps): update tools to latest versions (#2863) anchore-actions-token-generator[bot] 2024-05-14 15:06:21 -04:00
  • 338ce51fd8
    Fix outdated spdx links (#2865) Take 2024-05-15 02:58:36 +09:00
  • 048df17e3d
    Use values in relationship To/From fields (#2871) Alex Goodman 2024-05-14 13:48:33 -04:00
  • 7ad7627d5d
    add support for RPM DB package relationships (#2872) Alex Goodman 2024-05-14 13:48:19 -04:00
  • e767bcff4b
    fix: capture dependencies when parsing SPDX SBOMs (#2869) Russell Haering 2024-05-14 06:57:48 -07:00
  • 4a18895545
    Add abstraction for adding relationships from package cataloger results (#2853) Alex Goodman 2024-05-14 09:27:36 -04:00
  • fae6f5d372
    chore(deps): bump github/codeql-action from 3.25.4 to 3.25.5 (#2867) dependabot[bot] 2024-05-13 12:27:14 -04:00
  • ee75aafa37
    chore: fix small tooling error for go.mod (#2868) Christopher Angelo Phillips 2024-05-13 11:47:21 -04:00
  • c200896a96
    fix pruning binary packages when considering ELF packages (#2862) v1.4.1 Alex Goodman 2024-05-09 15:35:22 -04:00
  • 4194a2cd34
    feat: add relationships to ELF package discovery (#2715) v1.4.0 Brian Ebarb 2024-05-09 12:53:59 -05:00
  • 74b01a1c38
    README.md: link to official wiki (#2858) Jörg Thalheim 2024-05-09 19:49:37 +02:00
  • b2ca5fbf89
    fix Windows file paths in local go mod cache (#2654) William Murphy 2024-05-09 13:08:58 -04:00
  • 1892f24002
    chore(deps): bump github.com/docker/docker (#2859) dependabot[bot] 2024-05-09 12:02:36 -04:00
  • 88aaab2841
    chore(deps): bump github.com/charmbracelet/bubbletea (#2860) dependabot[bot] 2024-05-09 12:02:28 -04:00
  • 5044f48cd6
    chore(deps): bump github/codeql-action from 3.25.3 to 3.25.4 (#2855) dependabot[bot] 2024-05-08 10:33:38 -04:00
  • 6c2e8c8c4b
    chore(deps): bump github.com/sassoftware/go-rpmutils from 0.3.0 to 0.4.0 (#2856) dependabot[bot] 2024-05-08 10:33:11 -04:00
  • ada8f009d2
    Add relationships for ALPM packages (arch linux) (#2851) Alex Goodman 2024-05-07 13:29:46 -04:00
  • e7b6284039
    Add binary classifier for ArangoDB (#2830) Laurent Goderre 2024-05-07 12:06:32 -04:00
  • 78625164c6
    chore(deps): bump golang.org/x/net from 0.24.0 to 0.25.0 (#2849) dependabot[bot] 2024-05-07 12:05:43 -04:00
  • c0635a77a9
    chore(deps): bump actions/checkout from 4.1.4 to 4.1.5 (#2850) dependabot[bot] 2024-05-07 12:05:33 -04:00
  • 3713d97b7b
    chore: use ruleguard to test for missing defer statements (#2837) William Murphy 2024-05-07 05:42:29 -04:00
  • 430c55a5b0
    remove homebrew update workflow (#2846) Alex Goodman 2024-05-06 15:38:12 -04:00
  • 49e93646eb
    Restore version file update on release (#2844) Alex Goodman 2024-05-06 15:14:43 -04:00
  • 4481669f68 alternative homebrew updater fix-homebrew-updater Alex Goodman 2024-05-06 15:12:12 -04:00
  • 5ca26ed3ca
    fix: Add missing CPE for traefik, memcached, and postgres binaries (#2845) Laurent Goderre 2024-05-06 15:06:30 -04:00
  • e353214ef8
    Add detection for newer version of ErLang/OTP (#2829) Laurent Goderre 2024-05-06 11:47:54 -04:00
  • a56eff90d6
    fix ui race for package count (#2839) Alex Goodman 2024-05-06 11:45:52 -04:00
  • 00ff3ffda9
    chore(deps): update CPE dictionary index (#2841) anchore-actions-token-generator[bot] 2024-05-06 11:44:19 -04:00
  • 9de533996e
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.5.8 to 6.5.9 (#2842) dependabot[bot] 2024-05-06 11:44:05 -04:00
  • 7aae7470e2
    chore(deps): bump modernc.org/sqlite from 1.29.8 to 1.29.9 (#2843) dependabot[bot] 2024-05-06 11:43:55 -04:00
  • 3e21379492 [wip] dotnet-field-indirection Alex Goodman 2024-05-03 16:12:00 -04:00
  • d6604adaaf
    chore(deps): bump github.com/charmbracelet/bubbletea (#2838) dependabot[bot] 2024-05-03 09:50:20 -04:00
  • b00c492b0b wire up settings chore-custom-defer-lint Will Murphy 2024-05-02 11:50:35 -04:00
  • 34f9e6fec9 make new linter pass linting Will Murphy 2024-05-02 11:15:19 -04:00
  • 552cf45224 ensure custom linter is built Will Murphy 2024-05-02 11:11:08 -04:00
  • 1af07a4775 initial working build of custom linter Will Murphy 2024-05-02 11:07:01 -04:00
  • 34ca9a8412
    add security policy (#2835) Alex Goodman 2024-05-02 10:45:17 -04:00
  • f51b39ca04
    chore(deps): bump actions/setup-go from 5.0.0 to 5.0.1 (#2834) dependabot[bot] 2024-05-02 10:12:10 -04:00
  • 9bbb42620a
    chore(deps): update stereoscope to 2e9894674185d121917b283f773c2b5830f8b360 (#2831) anchore-actions-token-generator[bot] 2024-05-02 09:38:23 -04:00
  • 0b4de3d0c7
    chore(deps): bump github.com/charmbracelet/bubbletea (#2833) dependabot[bot] 2024-05-02 09:36:49 -04:00
  • 80d196a8c9
    chore: fix function name in comment (#2771) camcui 2024-05-02 02:04:02 +08:00
  • ed40833b30
    chore: enable go-critic deferInLoop lint (#2825) William Murphy 2024-05-01 12:59:35 -04:00
  • 93a7d2ee27
    fix: better clean up of file handles (#2823) William Murphy 2024-05-01 12:58:17 -04:00
  • 93a99e36c2
    chore(deps): bump github.com/docker/docker (#2827) dependabot[bot] 2024-05-01 11:03:31 -04:00
  • b0c88ddea9
    fix(spdx): include required fields (#2168) Keith Zantow 2024-04-30 13:28:42 -04:00
  • 047e31a969
    fix: add correct vendor for dnsmasq CPE (#2659) Keith Zantow 2024-04-30 13:24:01 -04:00
  • 25b55e1704
    fix: close temp rpmdb file (#2792) guangwu 2024-05-01 00:47:17 +08:00
  • 02dc2dfa9b
    chore(deps): bump github/codeql-action from 3.25.2 to 3.25.3 (#2817) dependabot[bot] 2024-04-30 16:27:14 +00:00
  • 5b03788300
    Fill in SPDX originator for all supported package types (#2822) Alex Goodman 2024-04-29 16:33:00 -04:00
  • 9901ea8fe9
    chore(deps): bump anchore/sbom-action from 0.15.10 to 0.15.11 (#2821) dependabot[bot] 2024-04-29 12:40:43 -04:00
  • 87cd6c8c48
    update spdx license list to 3.23 (#2818) v1.3.0 Alex Goodman 2024-04-26 10:50:55 -04:00
  • d3310a1830
    fix: re-use embedded union reader if possible (#2814) William Murphy 2024-04-26 10:21:38 -04:00
  • 8640f978ba
    feat: index known CPEs for go modules (#2816) Weston Steimel 2024-04-26 14:55:05 +01:00
  • 13b06dad45
    chore(deps): bump peter-evans/create-pull-request from 6.0.4 to 6.0.5 (#2812) dependabot[bot] 2024-04-25 10:32:10 -04:00
  • 9604e3dc9c
    feat: support multiple known CPEs in index (#2813) Weston Steimel 2024-04-25 15:22:26 +01:00
  • f2fc10aa86
    chore(deps): update stereoscope to 8b297badafd5d81fa1187b26ae34dd2a7ce7e425 (#2807) anchore-actions-token-generator[bot] 2024-04-24 15:19:13 -04:00
  • 21b22555d2
    chore(deps): bump actions/checkout from 4.1.3 to 4.1.4 (#2809) dependabot[bot] 2024-04-24 15:19:03 -04:00
  • 6676bb7459 fix lint spike-lazy-union-reader Will Murphy 2024-04-24 13:31:08 -04:00
  • 20b692df04 newLazyUnionReader cannot return err Will Murphy 2024-04-24 12:51:49 -04:00
  • 434f100add clean up lazy union reader Will Murphy 2024-04-24 11:54:02 -04:00
  • 5326efcef1
    chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.3 to 0.5.4 (#2810) dependabot[bot] 2024-04-24 12:04:09 -04:00
  • bad5cf2af8 more passing lazy union reader tests Will Murphy 2024-04-24 11:00:50 -04:00
  • 20a26a0dfe very WIP: lazy union reader Will Murphy 2024-04-24 10:29:53 -04:00
  • b90e7f9437
    Fix removing labels in 'Detect schema changes' job (#2772) Gijs Calis 2024-04-23 20:42:57 +02:00
  • fbdd4ee015
    chore(deps): bump github.com/docker/docker (#2805) dependabot[bot] 2024-04-23 14:32:34 -04:00
  • f154bf570d
    Display which provider caused which error in output (#2757) William Murphy 2024-04-23 14:27:39 -04:00
  • 99b58db497
    fix: prefer non-deprecated CPEs and include jenkins plugins from plugins.jenkins.io (#2806) Weston Steimel 2024-04-23 16:11:47 +01:00
  • 8d960e62c6
    feat: index known CPEs for PHP Composer packagist.org packages (#2804) Weston Steimel 2024-04-23 15:42:59 +01:00
  • 27a8a1be03
    chore(deps): bump github/codeql-action from 3.25.1 to 3.25.2 (#2802) dependabot[bot] 2024-04-23 09:54:36 -04:00
  • 4ccbd17255
    chore(deps): bump actions/upload-artifact from 4.3.2 to 4.3.3 (#2803) dependabot[bot] 2024-04-23 09:54:28 -04:00
  • 891e61a2ef
    fix: improvements to known CPE index construction (#2801) Weston Steimel 2024-04-23 14:28:18 +01:00
  • f7d3d552ce
    fix: exclude known instrumentation jars from being erroneously identified (#2796) Keith Zantow 2024-04-22 15:03:17 -04:00
  • 12ea9912b4
    feat: index known cpes for PHP extensions (#2777) Weston Steimel 2024-04-22 18:43:19 +01:00
  • cf6f92f2c8
    chore(deps): bump actions/checkout from 4.1.2 to 4.1.3 (#2799) dependabot[bot] 2024-04-22 13:29:13 -04:00
  • 6440f26b5a
    fix: return empty string if dereferncing pom var fails (#2797) William Murphy 2024-04-19 15:38:36 -04:00
  • f2633800ce
    chore(deps): bump github.com/docker/docker (#2793) dependabot[bot] 2024-04-19 15:06:57 -04:00
  • 4f227bf447
    chore(deps): bump modernc.org/sqlite from 1.29.7 to 1.29.8 (#2794) dependabot[bot] 2024-04-19 15:06:44 -04:00
  • d70eb3d04b
    chore(deps): bump actions/upload-artifact from 4.3.1 to 4.3.2 (#2795) dependabot[bot] 2024-04-19 15:06:32 -04:00
  • fe4819bc08
    chore: cleanup redundant code (#2791) guangwu 2024-04-20 00:12:48 +08:00
  • b26b38d6c5
    chore(deps): update tools to latest versions (#2789) anchore-actions-token-generator[bot] 2024-04-18 12:40:08 -04:00
  • 31969136e3
    chore(deps): bump github.com/spdx/tools-golang from 0.5.3 to 0.5.4 (#2790) dependabot[bot] 2024-04-18 12:39:42 -04:00
  • e4fc1af3b8
    fix(java): improvements to maven groupid lookups java-groupid-lookup-improvements Weston Steimel 2024-04-17 16:07:05 +01:00
  • f6845474bd
    chore(deps): bump github/codeql-action from 3.25.0 to 3.25.1 (#2786) dependabot[bot] 2024-04-17 10:46:34 -04:00
  • e1cadead1d
    chore(deps): bump peter-evans/create-pull-request from 6.0.3 to 6.0.4 (#2787) dependabot[bot] 2024-04-17 10:46:24 -04:00
  • 3e71f46fc8
    Fix: repeatedly dereference pom variables (#2781) William Murphy 2024-04-16 15:44:02 -04:00
  • 3b01e13f92
    chore(deps): bump modernc.org/sqlite from 1.29.6 to 1.29.7 (#2783) dependabot[bot] 2024-04-16 11:05:35 -04:00
  • bdb6f1849a
    fix: improve CPE index generation for Jenkins Plugins cpe-index-generation-jenkins-plugins Weston Steimel 2024-04-15 17:01:36 +01:00