Commit Graph

  • 8ee209a5ae
    use read lock in pkg collection (#2341) Alex Goodman 2023-11-21 13:48:25 -05:00
  • 4712246897
    Fix the attest command (#2337) Alex Goodman 2023-11-21 13:29:58 -05:00
  • ebeb768f59
    fix: add manual namespace mapping for org.springframework jars (#2345) Weston Steimel 2023-11-21 18:28:10 +00:00
  • d4733fac1d
    Add binary classifiers for MySQL and MariaDB (#2316) Duane May 2023-11-21 11:54:41 -05:00
  • 34774a0e10
    Enhance redis binary classifier (#2329) David Dooling 2023-11-21 10:24:59 -06:00
  • 1c582f0aa5
    chore(deps): bump anchore/sbom-action from 0.14.3 to 0.15.0 (#2344) dependabot[bot] 2023-11-21 11:12:43 -05:00
  • 8c1f087fd7 wip rename-top-level-json-fields Alex Goodman 2023-11-21 10:13:09 -05:00
  • 9d766c0325
    fix: add manual namespace mapping for org.springframework.security jars (#2343) Weston Steimel 2023-11-21 13:46:34 +00:00
  • 5751b43608
    fix: add manual namespace mapping for org.bouncycastle jars (#2342) Weston Steimel 2023-11-21 13:17:07 +00:00
  • 51d015d5ea
    Update developer docs to represent the current package layout (#2340) Alex Goodman 2023-11-20 15:06:18 -05:00
  • 5565bdef0c
    Remove the power-user command and related catalogers (#2306) Alex Goodman 2023-11-20 10:44:28 -05:00
  • 1676934c63
    Add "pretty" json configuration and change default behavior to be space-efficient (#2275) Alex Goodman 2023-11-20 10:29:34 -05:00
  • 7cfb5f630a
    chore(deps): update stereoscope to 3610f4ef3e83e8ff2edf8859e8916bce326fa260 (#2336) v0.97.1 anchore-actions-token-generator[bot] 2023-11-17 20:53:01 +00:00
  • ba80e490c2
    feat: allow for stdout to be buffered on each command (#2335) Christopher Angelo Phillips 2023-11-17 14:14:13 -05:00
  • 1c787f436f
    fix: prevent writing non-report output to stdout (#2324) v0.97.0 Keith Zantow 2023-11-16 17:45:25 -05:00
  • c7eb3f4c93
    chore(deps): bump github/codeql-action from 2.22.6 to 2.22.7 (#2332) dependabot[bot] 2023-11-16 09:22:23 -05:00
  • 11a8cde8e4
    export metadata type helper (#2328) Alex Goodman 2023-11-15 14:05:18 -05:00
  • dcd062cffb
    fix(java): add manual groupid mappings for org.apache.velocity jars (#2327) Weston Steimel 2023-11-15 17:44:36 +00:00
  • b9294976ef
    fix(java): skip maven bundle plugin logic if vendor id and symbolic name match (#2326) Weston Steimel 2023-11-15 17:44:15 +00:00
  • 3e8a2304e8
    Refine license searching from groupIDFromJavaMetadata to allow for having the artfactId in the groupId (#2313) Colm O hEigeartaigh 2023-11-15 15:04:31 +00:00
  • e04d90fc9a
    chore(deps): update tools to latest versions (#2325) anchore-actions-token-generator[bot] 2023-11-15 10:02:27 -05:00
  • 0f39917999
    chore(deps): update tools to latest versions (#2318) anchore-actions-token-generator[bot] 2023-11-14 12:01:47 -05:00
  • 0652998b9b
    Add license for golang stdlib (#2317) Colm O hEigeartaigh 2023-11-14 16:53:07 +00:00
  • 43bdf6e1b2
    chore(deps): bump github/codeql-action from 2.22.5 to 2.22.6 (#2321) dependabot[bot] 2023-11-14 11:35:59 -05:00
  • 9aa9e0e09a
    docs: Update README.md for dotnet-portable-executable (#2322) Benji Visser 2023-11-14 07:37:56 -08:00
  • 7ccbadff34
    Fall back to searching maven central using groupIDFromJavaMetadata (#2295) Colm O hEigeartaigh 2023-11-11 03:02:53 +00:00
  • 3f13d209a5
    rename file.Location.VirtualPath to AccessPath (#2288) Alex Goodman 2023-11-09 11:30:08 -06:00
  • baa3dc74d3
    chore(deps): update tools to latest versions (#2308) anchore-actions-token-generator[bot] 2023-11-09 08:07:59 -08:00
  • 58f310c390
    chore(deps): bump github.com/gkampitakis/go-snaps from 0.4.11 to 0.4.12 (#2310) dependabot[bot] 2023-11-09 08:06:50 -08:00
  • a383239217
    chore(deps): bump golang.org/x/net from 0.17.0 to 0.18.0 (#2311) dependabot[bot] 2023-11-09 08:06:19 -08:00
  • 0891d35e07
    include image labels in cycloneDX SBOM (#2294) v0.96.0 Benji Visser 2023-11-08 15:13:04 -08:00
  • 502971a1b2
    Add accessPath on Location objects to syft-json output (#2287) Alex Goodman 2023-11-08 17:05:30 -06:00
  • dc14dbb326
    SPDX file has duplicate sha256 tag in versionInfo (#2300) Colm O hEigeartaigh 2023-11-08 22:49:31 +00:00
  • bae5a2e741
    Check maven central as well for licenses in parents poms for nested jars (#2302) Colm O hEigeartaigh 2023-11-08 18:26:12 +00:00
  • 220655743b
    chore(deps): bump github.com/spf13/cobra from 1.7.0 to 1.8.0 (#2293) dependabot[bot] 2023-11-08 10:23:40 -08:00
  • 9fce006b8f
    chore(deps): update tools to latest versions (#2301) anchore-actions-token-generator[bot] 2023-11-08 09:33:59 -08:00
  • d91c2dd842
    fix: identify cyclone-json without $schema (#2303) Keith Zantow 2023-11-08 11:54:22 -05:00
  • 9b98785aab
    chore: setup release task before calling go releaser (#2297) v0.95.0 Christopher Angelo Phillips 2023-11-07 08:33:06 -08:00
  • ad977ee0a1
    chore(deps): update tools to latest versions (#2296) anchore-actions-token-generator[bot] 2023-11-07 06:44:39 -08:00
  • 9eac737fe2
    chore(deps): update tools to latest versions (#2289) anchore-actions-token-generator[bot] 2023-11-06 09:23:46 -05:00
  • 4ba92ac43b
    chore(deps): update CPE dictionary index (#2290) anchore-actions-token-generator[bot] 2023-11-06 09:23:24 -05:00
  • a4b895d31f
    chore(deps): bump golang.org/x/mod from 0.13.0 to 0.14.0 (#2292) dependabot[bot] 2023-11-06 14:12:40 +00:00
  • 9fa11f2339
    Wire though maven-url to java config (#2291) Colm O hEigeartaigh 2023-11-06 14:08:03 +00:00
  • 1470abaded
    Use case-insensitive matching for Go license files (#2286) Mark Severson 2023-11-03 12:47:09 -06:00
  • 2d582f78a1
    Add a new Java configuration option to recursively search parent poms… (#2274) Colm O hEigeartaigh 2023-11-03 14:33:02 +00:00
  • 793cef5086
    chore(deps): update tools to latest versions (#2280) anchore-actions-token-generator[bot] 2023-11-02 09:20:27 -04:00
  • b2f4d7eda2
    Follow convention for naming catalogers (#2277) Alex Goodman 2023-11-02 08:39:42 -04:00
  • 6c41f15975
    change dir resolver to include virtual path (#2259) Alex Goodman 2023-11-02 08:20:00 -04:00
  • 26cdbfc299
    fix: syft does not handle the case of parsing a jar with multiple poms (#2231) Colm O hEigeartaigh 2023-11-01 17:10:17 +00:00
  • dc9bc58480
    add PURLs when scanning Gradle lock files (#2278) Robbie Vanbrabant 2023-11-01 17:09:31 +00:00
  • a6d73e5659
    chore(deps): bump modernc.org/sqlite from 1.26.0 to 1.27.0 (#2279) dependabot[bot] 2023-11-01 10:35:20 -04:00
  • ee4e69285a test: remove dll files and updates tests to use versionResources (#2276) Christopher Angelo Phillips 2023-10-31 15:33:52 -04:00
  • 59c56a5666 fix: update dot net binary parsing logic to remove empty space (#2273) Christopher Angelo Phillips 2023-10-31 10:43:29 -04:00
  • 78ac2f9797
    Read a license from a parent pom stored in Maven Central (#2228) Colm O hEigeartaigh 2023-10-30 21:48:16 +00:00
  • 262423b1e8
    Update README.md to use canonical output format names (fixes #2269) (#2272) Tim Gerla 2023-10-30 17:25:30 -04:00
  • 1aaa644007
    Remove MetadataType from core package object and normalize JSON metadataType values (#1983) Alex Goodman 2023-10-30 12:12:04 -04:00
  • f442586ec9
    chore(deps): bump github.com/docker/docker (#2263) dependabot[bot] 2023-10-30 09:55:19 -04:00
  • 12877ed863
    chore(deps): update stereoscope to 5909e353ee88d7809f0e646c79f110a0e6b1d80d (#2265) anchore-actions-token-generator[bot] 2023-10-30 09:51:37 -04:00
  • 629aafc323
    chore(deps): update CPE dictionary index (#2271) anchore-actions-token-generator[bot] 2023-10-30 09:48:03 -04:00
  • f430788099
    chore: fix cpe generation task (#2270) William Murphy 2023-10-30 08:51:26 -04:00
  • 58850d3258
    chore(deps): bump github.com/google/uuid from 1.3.1 to 1.4.0 (#2262) dependabot[bot] 2023-10-27 09:55:04 -04:00
  • 2428d704e1
    chore(deps): bump github/codeql-action from 2.22.4 to 2.22.5 (#2261) dependabot[bot] 2023-10-27 09:54:23 -04:00
  • da07520121
    chore(deps): update tools to latest versions (#2258) anchore-actions-token-generator[bot] 2023-10-26 10:15:13 -04:00
  • ae27dcdfa9
    chore(deps): bump github.com/go-git/go-git/v5 from 5.9.0 to 5.10.0 (#2256) dependabot[bot] 2023-10-25 10:45:27 -04:00
  • 1daf18fee9
    feat: Perform case insensitive matching on Java license files (#2235) Colm O hEigeartaigh 2023-10-25 14:51:59 +01:00
  • 7392d607b6
    Split the sbom.Format interface by encode and decode use cases (#2186) Alex Goodman 2023-10-25 09:43:06 -04:00
  • 7315f83f9d
    Upgrade tool management (#2188) Alex Goodman 2023-10-25 09:08:43 -04:00
  • cd530924d0
    fix: 2179 jar chokes empty lines (#2254) Christopher Angelo Phillips 2023-10-24 14:03:47 -04:00
  • 73d5852119
    chore(deps): update CPE dictionary index (#2253) anchore-actions-token-generator[bot] 2023-10-24 13:22:02 -04:00
  • c4b464e616
    fix CPE workflow (#2252) Alex Goodman 2023-10-24 11:07:49 -04:00
  • 234ce4e1f3
    feat: add conaninfo.txt parser to detect conan packages in docker images (#2234) Stefan Profanter 2023-10-23 22:17:50 +02:00
  • f9433e7f9b
    chore(deps): update bootstrap tools to latest versions (#2245) anchore-actions-token-generator[bot] 2023-10-23 10:48:07 -04:00
  • 5a4778093d
    chore(deps): bump github.com/bmatcuk/doublestar/v4 from 4.6.0 to 4.6.1 (#2248) dependabot[bot] 2023-10-23 10:42:17 -04:00
  • bdbf927847
    chore(deps): bump github/codeql-action from 2.22.3 to 2.22.4 (#2249) dependabot[bot] 2023-10-23 10:41:54 -04:00
  • f3d95aa3a9
    fill version info from release and git directly (#2244) Alex Goodman 2023-10-23 09:05:43 -04:00
  • 671ff39933
    Add ruby.NewGemSpecCataloger to DirectoryCatalogers. (#1971) Chao Li 2023-10-23 20:49:57 +08:00
  • 263be01faa
    change homebrew release trigger (#2242) Alex Goodman 2023-10-20 14:31:41 -04:00
  • 8f6bdde666
    Label PRs when the json schema changes (#2240) v0.94.0 Alex Goodman 2023-10-20 13:00:15 -04:00
  • ef43294d0e
    Add download location when cataloging directory npm package lock (#2238) Christopher Angelo Phillips 2023-10-20 11:40:38 -04:00
  • e1ad340c2d
    fix: allow packages to be captured from DIST/EGG case (#2239) Christopher Angelo Phillips 2023-10-20 11:29:13 -04:00
  • 07f13049da
    Account for maven bundle plugin and fix filename matching (#2220) Alex Goodman 2023-10-19 17:57:23 -04:00
  • 6c7900f5b8
    chore(deps): bump actions/checkout from 4.1.0 to 4.1.1 (#2236) dependabot[bot] 2023-10-18 09:54:26 -04:00
  • 7018573bf7
    Remove internal string set (#2219) Alex Goodman 2023-10-17 12:52:11 -04:00
  • f3ad8cf250
    bump clio to get stderr reporting fix (#2232) Alex Goodman 2023-10-16 12:47:48 -04:00
  • 31f1d7dbf0
    Fix panic for empty input to Swift cataloger (#2226) Alex Goodman 2023-10-16 11:04:33 -04:00
  • 144ed725a7
    Add additional license filenames (#2227) Colm O hEigeartaigh 2023-10-16 14:20:00 +01:00
  • dcec2bc352
    chore(deps): bump github/codeql-action from 2.22.2 to 2.22.3 (#2229) dependabot[bot] 2023-10-16 08:59:39 -04:00
  • a8ceb73220
    chore: continue building snapshots for acceptance tests chore/build-syft-for-cli-tests Keith Zantow 2023-10-13 15:38:46 -04:00
  • 1b5e76977e
    chore: continue building snapshots for acceptance tests Keith Zantow 2023-10-13 15:04:16 -04:00
  • 2fc2588030
    chore: workaround goreleaser single-target running multiple hooks bug Keith Zantow 2023-10-13 11:37:47 -04:00
  • ecfba80ca7
    chore: snapshot cmd Keith Zantow 2023-10-13 10:32:35 -04:00
  • 8104163bb8
    chore: bootstrap environments for acceptance tests Keith Zantow 2023-10-13 10:19:42 -04:00
  • bd9b39d370
    Merge remote-tracking branch 'origin/main' into chore/build-syft-for-cli-tests Keith Zantow 2023-10-13 09:18:40 -04:00
  • 42aca2d7ad
    chore: cleanup Keith Zantow 2023-10-13 09:13:37 -04:00
  • 6c3755fbbe
    chore: attempt to avoid full snapshot build Keith Zantow 2023-10-13 09:13:01 -04:00
  • 1fe0921a5b
    chore(deps): bump github.com/charmbracelet/lipgloss from 0.9.0 to 0.9.1 (#2222) dependabot[bot] 2023-10-12 11:10:56 -04:00
  • 538fe5ee1d
    chore(deps): bump github/codeql-action from 2.22.1 to 2.22.2 (#2224) dependabot[bot] 2023-10-12 11:10:45 -04:00
  • 2687100e6a
    Detect a license file in the root directory or META-INF of a jar (#2213) Colm O hEigeartaigh 2023-10-12 16:09:53 +01:00
  • fe7a417fb2
    Parse donet dependency trees (#2143) Benji Visser 2023-10-11 14:01:24 -04:00
  • 7732cd3b48
    chore(deps): bump golang.org/x/net from 0.16.0 to 0.17.0 (#2214) dependabot[bot] 2023-10-11 13:52:07 -04:00