Commit Graph

  • 21b22555d2
    chore(deps): bump actions/checkout from 4.1.3 to 4.1.4 (#2809) dependabot[bot] 2024-04-24 15:19:03 -04:00
  • 6676bb7459 fix lint spike-lazy-union-reader Will Murphy 2024-04-24 13:31:08 -04:00
  • 20b692df04 newLazyUnionReader cannot return err Will Murphy 2024-04-24 12:51:49 -04:00
  • 434f100add clean up lazy union reader Will Murphy 2024-04-24 11:54:02 -04:00
  • 5326efcef1
    chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.3 to 0.5.4 (#2810) dependabot[bot] 2024-04-24 12:04:09 -04:00
  • bad5cf2af8 more passing lazy union reader tests Will Murphy 2024-04-24 11:00:50 -04:00
  • 20a26a0dfe very WIP: lazy union reader Will Murphy 2024-04-24 10:29:53 -04:00
  • b90e7f9437
    Fix removing labels in 'Detect schema changes' job (#2772) Gijs Calis 2024-04-23 20:42:57 +02:00
  • fbdd4ee015
    chore(deps): bump github.com/docker/docker (#2805) dependabot[bot] 2024-04-23 14:32:34 -04:00
  • f154bf570d
    Display which provider caused which error in output (#2757) William Murphy 2024-04-23 14:27:39 -04:00
  • 99b58db497
    fix: prefer non-deprecated CPEs and include jenkins plugins from plugins.jenkins.io (#2806) Weston Steimel 2024-04-23 16:11:47 +01:00
  • 8d960e62c6
    feat: index known CPEs for PHP Composer packagist.org packages (#2804) Weston Steimel 2024-04-23 15:42:59 +01:00
  • 27a8a1be03
    chore(deps): bump github/codeql-action from 3.25.1 to 3.25.2 (#2802) dependabot[bot] 2024-04-23 09:54:36 -04:00
  • 4ccbd17255
    chore(deps): bump actions/upload-artifact from 4.3.2 to 4.3.3 (#2803) dependabot[bot] 2024-04-23 09:54:28 -04:00
  • 891e61a2ef
    fix: improvements to known CPE index construction (#2801) Weston Steimel 2024-04-23 14:28:18 +01:00
  • f7d3d552ce
    fix: exclude known instrumentation jars from being erroneously identified (#2796) Keith Zantow 2024-04-22 15:03:17 -04:00
  • 12ea9912b4
    feat: index known cpes for PHP extensions (#2777) Weston Steimel 2024-04-22 18:43:19 +01:00
  • cf6f92f2c8
    chore(deps): bump actions/checkout from 4.1.2 to 4.1.3 (#2799) dependabot[bot] 2024-04-22 13:29:13 -04:00
  • 6440f26b5a
    fix: return empty string if dereferncing pom var fails (#2797) William Murphy 2024-04-19 15:38:36 -04:00
  • f2633800ce
    chore(deps): bump github.com/docker/docker (#2793) dependabot[bot] 2024-04-19 15:06:57 -04:00
  • 4f227bf447
    chore(deps): bump modernc.org/sqlite from 1.29.7 to 1.29.8 (#2794) dependabot[bot] 2024-04-19 15:06:44 -04:00
  • d70eb3d04b
    chore(deps): bump actions/upload-artifact from 4.3.1 to 4.3.2 (#2795) dependabot[bot] 2024-04-19 15:06:32 -04:00
  • fe4819bc08
    chore: cleanup redundant code (#2791) guangwu 2024-04-20 00:12:48 +08:00
  • b26b38d6c5
    chore(deps): update tools to latest versions (#2789) anchore-actions-token-generator[bot] 2024-04-18 12:40:08 -04:00
  • 31969136e3
    chore(deps): bump github.com/spdx/tools-golang from 0.5.3 to 0.5.4 (#2790) dependabot[bot] 2024-04-18 12:39:42 -04:00
  • e4fc1af3b8
    fix(java): improvements to maven groupid lookups java-groupid-lookup-improvements Weston Steimel 2024-04-17 16:07:05 +01:00
  • f6845474bd
    chore(deps): bump github/codeql-action from 3.25.0 to 3.25.1 (#2786) dependabot[bot] 2024-04-17 10:46:34 -04:00
  • e1cadead1d
    chore(deps): bump peter-evans/create-pull-request from 6.0.3 to 6.0.4 (#2787) dependabot[bot] 2024-04-17 10:46:24 -04:00
  • 3e71f46fc8
    Fix: repeatedly dereference pom variables (#2781) William Murphy 2024-04-16 15:44:02 -04:00
  • 3b01e13f92
    chore(deps): bump modernc.org/sqlite from 1.29.6 to 1.29.7 (#2783) dependabot[bot] 2024-04-16 11:05:35 -04:00
  • bdb6f1849a
    fix: improve CPE index generation for Jenkins Plugins cpe-index-generation-jenkins-plugins Weston Steimel 2024-04-15 17:01:36 +01:00
  • 25c2e60358
    chore(deps): update CPE dictionary index (#2780) anchore-actions-token-generator[bot] 2024-04-15 11:15:38 -04:00
  • dc7fa21980
    chore(deps): bump github/codeql-action from 3.24.10 to 3.25.0 (#2779) dependabot[bot] 2024-04-15 10:00:54 -04:00
  • f28023aedb
    feat: index known cpes for PHP extensions Weston Steimel 2024-04-15 10:11:43 +01:00
  • 587690b875
    chore: fix broken cpe index generation task (#2778) Weston Steimel 2024-04-15 14:39:57 +01:00
  • 21eaa5c82b
    chore(deps): bump github.com/docker/docker (#2773) dependabot[bot] 2024-04-12 15:33:27 -04:00
  • 081ec04b3f
    chore(deps): bump peter-evans/create-pull-request from 6.0.2 to 6.0.3 (#2774) dependabot[bot] 2024-04-12 15:31:36 -04:00
  • dde5d349b1
    fix: more robust go main version extraction (#2767) v1.2.0 Keith Zantow 2024-04-11 11:58:51 -04:00
  • a5d77b9263
    chore(deps): update tools to latest versions (#2768) anchore-actions-token-generator[bot] 2024-04-11 11:53:55 -04:00
  • c9aab4863b
    fix: binary character in java version (#2766) Laurent Goderre 2024-04-11 10:32:24 -04:00
  • af1a065d2a
    chore(deps): update tools to latest versions (#2760) anchore-actions-token-generator[bot] 2024-04-09 12:03:12 -04:00
  • 88cef1e05c
    chore(deps): bump modernc.org/sqlite from 1.29.5 to 1.29.6 (#2761) dependabot[bot] 2024-04-09 12:02:56 -04:00
  • 870d97ca5a
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.5.6 to 6.5.8 (#2754) dependabot[bot] 2024-04-08 12:19:45 -04:00
  • e681bc4780
    chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.2 to 0.5.3 (#2755) dependabot[bot] 2024-04-08 12:19:32 -04:00
  • c31696f131
    chore(deps): bump github/codeql-action from 3.24.9 to 3.24.10 (#2756) dependabot[bot] 2024-04-08 12:19:20 -04:00
  • 67781e98a2
    chore(deps): bump golang.org/x/mod from 0.16.0 to 0.17.0 (#2751) dependabot[bot] 2024-04-05 19:22:00 +00:00
  • 619ace65c3
    Differentiate between JRE and JDK (#2748) Laurent Goderre 2024-04-05 15:10:58 -04:00
  • 3e4e3bb1d4
    chore(deps): bump golang.org/x/net from 0.23.0 to 0.24.0 (#2752) dependabot[bot] 2024-04-05 15:10:15 -04:00
  • 1e31356c49
    chore(deps): update tools to latest versions (#2744) v1.1.1 anchore-actions-token-generator[bot] 2024-04-04 10:34:19 -04:00
  • 0fa925e5af
    chore(deps): bump golang.org/x/net from 0.22.0 to 0.23.0 (#2747) dependabot[bot] 2024-04-04 10:34:03 -04:00
  • e100776f22
    chore: update anchore/packageurl-go to use latest commits (#2746) Christopher Angelo Phillips 2024-04-04 10:33:51 -04:00
  • e0233625cb
    feat: cataloger for PHP Pecl and PEAR packages (#2604) Laurent Goderre 2024-04-02 11:55:56 -04:00
  • e0f5b5a787
    chore(deps): bump github.com/go-git/go-git/v5 from 5.11.0 to 5.12.0 (#2743) dependabot[bot] 2024-04-01 14:14:07 -04:00
  • 9c42c83229
    chore(deps): update tools to latest versions (#2741) anchore-actions-token-generator[bot] 2024-03-30 17:51:21 -04:00
  • 01340b2a5c
    fix: conan poco project cpe (#2740) Keith Zantow 2024-03-28 16:56:24 -04:00
  • 16edb40c72
    chore(deps): bump github.com/distribution/reference from 0.5.0 to 0.6.0 (#2738) dependabot[bot] 2024-03-28 12:22:00 -04:00
  • 5a865d0d90
    chore(deps): bump anchore/sbom-action from 0.15.9 to 0.15.10 (#2737) dependabot[bot] 2024-03-27 17:52:22 +00:00
  • 410867ca0c
    fix: panic scanning binaries without symtab (#2739) Keith Zantow 2024-03-27 13:51:45 -04:00
  • 469b4c13bb
    chore: remove useless code (#2716) guangwu 2024-03-27 00:21:03 +08:00
  • 57e9cc52a4
    chore(deps): bump google.golang.org/protobuf from 1.31.0 to 1.33.0 (#2731) dependabot[bot] 2024-03-26 11:52:50 -04:00
  • 55fff0f4a1
    chore(deps): bump github/codeql-action from 3.24.8 to 3.24.9 (#2732) dependabot[bot] 2024-03-26 11:50:31 -04:00
  • 2a7b4f3761
    chore(deps): update tools to latest versions (#2733) anchore-actions-token-generator[bot] 2024-03-26 11:50:21 -04:00
  • fe3704d4a9
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.5.5 to 6.5.6 (#2734) dependabot[bot] 2024-03-26 11:50:07 -04:00
  • 059cfd6730
    update release token from readonly to write token (#2735) Hung Nguyen 2024-03-26 09:06:55 -04:00
  • f4e18961b9
    Adding the ability to retrieve remote licenses from package.lock (#2708) v1.1.0 Colm O hEigeartaigh 2024-03-21 17:20:04 +00:00
  • 0d5ebed74a
    dont include labels for dependabot ecosystems (#2720) Alex Goodman 2024-03-21 12:16:01 -04:00
  • 8f7305ef78
    chore(deps): bump fountainhead/action-wait-for-check from 1.1.0 to 1.2.0 (#2717) dependabot[bot] 2024-03-21 12:15:30 -04:00
  • c199b80b88
    chore(deps): update tools to latest versions (#2726) anchore-actions-token-generator[bot] 2024-03-21 12:15:06 -04:00
  • df547020ef
    chore(deps): bump github/codeql-action from 3.24.7 to 3.24.8 (#2725) dependabot[bot] 2024-03-21 12:14:51 -04:00
  • 37094c9751
    chore(deps): bump actions/cache from 4.0.1 to 4.0.2 (#2728) dependabot[bot] 2024-03-21 12:14:43 -04:00
  • c83556e7b6
    chore(deps): bump github.com/docker/docker (#2730) dependabot[bot] 2024-03-21 12:14:32 -04:00
  • 3ac1cd7a9f
    updating credentials to scoped permissions (#2722) Hung Nguyen 2024-03-20 17:35:07 -04:00
  • 96d2b4a368
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.5.4 to 6.5.5 (#2718) dependabot[bot] 2024-03-15 10:33:11 -04:00
  • 807de976c4
    chore(deps): bump github.com/google/go-containerregistry (#2719) dependabot[bot] 2024-03-15 10:32:51 -04:00
  • cf17bd69b2
    Add detection for Oracle GraalVM (#2705) Laurent Goderre 2024-03-14 11:40:07 -04:00
  • 1c8d29d577
    chore(deps): bump docker/login-action from 3.0.0 to 3.1.0 (#2714) dependabot[bot] 2024-03-14 11:16:16 -04:00
  • 6a2517b5d2
    Add ELF binary package cataloger (#2396) brian-ebarb 2024-03-14 10:16:03 -05:00
  • 7ab6fc3fe4
    chore(deps): bump modernc.org/sqlite from 1.29.3 to 1.29.5 (#2710) dependabot[bot] 2024-03-14 09:58:56 -04:00
  • 2051a62ded
    chore(deps): bump github/codeql-action from 3.24.6 to 3.24.7 (#2711) dependabot[bot] 2024-03-14 09:58:42 -04:00
  • 78ad3d648f [wip] prototype binary relationships add-elf-binary-relationships Alex Goodman 2024-03-13 18:09:19 -04:00
  • 1b3e57c264 remove unreleated swift change Alex Goodman 2024-03-13 17:09:08 -04:00
  • ad7edba2a5 remove dead test code Alex Goodman 2024-03-13 17:07:52 -04:00
  • e51d4bcda1 less verbose logging Alex Goodman 2024-03-13 17:05:56 -04:00
  • d8113b5f07 bump JSON schema to v16.0.6 + expand test fixtures Alex Goodman 2024-03-13 15:51:03 -04:00
  • a35f64c971 feat: elf_binary_package_cataloger Brian Ebarb 2024-03-13 14:34:06 -05:00
  • 5534c38d0f
    chore(deps): bump peter-evans/create-pull-request from 6.0.1 to 6.0.2 (#2712) dependabot[bot] 2024-03-13 13:47:47 -04:00
  • 47fc909700
    Show binary exports, entrypoint, and imports (#2626) Alex Goodman 2024-03-12 18:04:02 -04:00
  • 2e2a9377ea
    chore(deps): bump actions/checkout from 4.1.1 to 4.1.2 (#2703) dependabot[bot] 2024-03-12 13:18:44 -04:00
  • 4ca79c7626
    chore(deps): bump github.com/knqyf263/go-rpmdb (#2701) dependabot[bot] 2024-03-11 11:48:05 -04:00
  • 3743f5ae53
    chore: reduce duplicate case SwiftPkg (#2696) guangwu 2024-03-08 02:15:31 +08:00
  • ebb9d4edb6
    chore: remove deprecated os.SEEK_SET os.SEEK_CUR (#2693) guangwu 2024-03-08 02:10:48 +08:00
  • e2a9d891b2
    chore(deps): bump github.com/docker/docker (#2698) dependabot[bot] 2024-03-07 13:00:14 -05:00
  • 5b09c154bb
    chore(deps): bump modernc.org/sqlite from 1.29.2 to 1.29.3 (#2699) dependabot[bot] 2024-03-07 13:00:02 -05:00
  • 1b121ac3f4
    chore(deps): bump golang.org/x/net from 0.21.0 to 0.22.0 (#2689) v1.0.1 dependabot[bot] 2024-03-06 14:25:56 -05:00
  • f9e09aef19
    docs: add simplest example from regsitry (#2691) Keith Zantow 2024-03-06 14:25:37 -05:00
  • d2ac672f8f
    chore(deps): update tools to latest versions (#2688) anchore-actions-token-generator[bot] 2024-03-06 14:25:13 -05:00
  • 5e3fde04a5
    chore(deps): bump anchore/sbom-action from 0.15.8 to 0.15.9 (#2694) dependabot[bot] 2024-03-06 14:24:56 -05:00
  • e214645394
    chore(deps): bump github.com/charmbracelet/lipgloss from 0.9.1 to 0.10.0 (#2695) dependabot[bot] 2024-03-06 14:24:46 -05:00
  • 5bd1cd5c13
    chore(deps): bump golang.org/x/mod from 0.15.0 to 0.16.0 (#2690) dependabot[bot] 2024-03-05 10:15:18 -05:00
  • fe4f17286f
    chore(deps): bump github.com/stretchr/testify from 1.8.4 to 1.9.0 (#2684) dependabot[bot] 2024-03-01 13:51:18 -05:00