Commit Graph

  • 650f71cbe0
    chore: update to latest stereoscope (#2151) Christopher Angelo Phillips 2023-09-19 15:22:10 -04:00
  • 30885ed92e
    chore(deps): bump github/codeql-action from 2.21.7 to 2.21.8 (#2150) dependabot[bot] 2023-09-19 14:37:54 -04:00
  • 51243aa65f
    chore(deps): update stereoscope to 41288870305034fade27388afa7326c44eb8ff17 (#2149) anchore-actions-token-generator[bot] 2023-09-19 09:07:15 -04:00
  • 23e3de75e3
    Add containerd support (#1793) Shane Dell 2023-09-18 11:33:43 -04:00
  • 594ba5f295
    chore: pin workflow checkout for cpe update-cpe-dictionary-index (#2141) Christopher Angelo Phillips 2023-09-15 16:00:15 -04:00
  • 5d48882a78
    Add GitHub actions and shared workflow usage catalogers (#2140) Alex Goodman 2023-09-15 14:51:21 -04:00
  • ec4d595920
    feat: add dependency information to conan lockfile parser (#2131) Stefan Profanter 2023-09-15 20:31:08 +02:00
  • 094b41b301
    chore: pin and update all workflow dependencies; add permission scopes (#2138) Christopher Angelo Phillips 2023-09-15 14:18:42 -04:00
  • 2eb2d55551
    chore: pin all cli test FROM lines to linux/amd64 (#2137) William Murphy 2023-09-15 12:49:02 -04:00
  • a46d12270f
    fix: encode and decode FileLicenses and FileContents in Syft JSON (#2083) Keith Zantow 2023-09-13 16:14:20 -04:00
  • 3e16c6813f
    feat: add cyclonedx schema version selection (#2123) Christopher Angelo Phillips 2023-09-13 14:50:22 -04:00
  • 5035d9ca1a
    fix: allow cyclonedx json input with no components (#2127) Ahmet Taha 2023-09-13 19:14:14 +02:00
  • c21b16d924
    chore(deps): bump docker/login-action from 2 to 3 (#2119) dependabot[bot] 2023-09-13 10:34:19 -04:00
  • 4a2fc226dd
    chore(deps): bump github.com/go-git/go-git/v5 from 5.8.1 to 5.9.0 (#2125) dependabot[bot] 2023-09-13 10:33:47 -04:00
  • 7de5643227
    fix source-version typo in flag description (#2126) Alex Goodman 2023-09-13 10:05:24 -04:00
  • 9de4129638
    chore: enforce race detector (#2122) William Murphy 2023-09-12 13:09:18 -04:00
  • 3a45653cfa
    chore(deps): update stereoscope to 2fc2d6c2503b6e2212e04c64ceffd57c3395ae70 (#2117) anchore-actions-token-generator[bot] 2023-09-12 11:49:20 -04:00
  • b82c0ffc34
    fix(help): power-user help text to indicate it supports file-system (#2113) v0.90.0 GGMU 2023-09-11 19:12:04 +03:00
  • b2be411f77
    chore(deps): bump tibdex/github-app-token from 1 to 2 (#2116) dependabot[bot] 2023-09-11 09:56:22 -04:00
  • ec22f4b773
    chore(deps): update CPE dictionary index (#2114) anchore-actions-token-generator[bot] 2023-09-11 09:42:59 -04:00
  • e3c525b4b8
    chore(deps): update stereoscope to 057dda3667e7f2b5e6ec6716747badd5f403c6de (#2109) anchore-actions-token-generator[bot] 2023-09-08 14:10:00 -04:00
  • d54d20a563 use new atomic stager struct fix-go-progress-race Will Murphy 2023-09-08 10:13:52 -04:00
  • abfd244dc5 test for race conditions Will Murphy 2023-09-08 08:42:19 -04:00
  • 8e9d1d5e91 Fix race in current stage fo go-progress Will Murphy 2023-09-08 07:48:42 -04:00
  • 3842d28e90
    fix: update codeql-analysis for go 1.21 (#2108) Christopher Angelo Phillips 2023-09-07 15:54:42 -04:00
  • 9f22ab6137
    Bump the golang.org/x/exp dependency and fix a build breakage. (#2088) dlorenc 2023-09-07 14:55:52 -04:00
  • 1315cfd787
    chore(deps): bump actions/checkout from 3 to 4 (#2094) dependabot[bot] 2023-09-07 09:57:51 -04:00
  • 212aa9b6cf
    chore(deps): bump github.com/gkampitakis/go-snaps from 0.4.7 to 0.4.10 (#2106) dependabot[bot] 2023-09-07 09:56:41 -04:00
  • 46e4ac1474
    chore(deps): update bootstrap tools to latest versions (#2086) anchore-actions-token-generator[bot] 2023-09-07 09:30:44 -04:00
  • 6800a5f64b
    chore(deps): update CPE dictionary index (#2089) anchore-actions-token-generator[bot] 2023-09-07 09:30:18 -04:00
  • 9caf51596e
    chore(deps): bump github.com/saferwall/pe from 1.4.4 to 1.4.5 (#2096) dependabot[bot] 2023-09-07 09:29:06 -04:00
  • 7645d5759d
    chore(deps): bump github.com/docker/docker (#2098) dependabot[bot] 2023-09-07 09:27:21 -04:00
  • ce32f8bb74
    chore(deps): bump golang.org/x/net from 0.14.0 to 0.15.0 (#2099) dependabot[bot] 2023-09-07 09:26:56 -04:00
  • f8ab7c4695
    feat(cmd/update): add UA header with current ver when check for update (#2100) Đỗ Trọng Hải 2023-09-06 22:43:01 +07:00
  • 305ee87052
    fix(cdx): validate external refs before encoding (#2091) Đỗ Trọng Hải 2023-09-05 21:39:51 +07:00
  • 49e7f399f9
    expose cobra command in cli package (#2097) Alex Goodman 2023-09-05 10:33:38 -04:00
  • 007b034ee3
    fix: correct group IDs for commons-codec, okhttp, okio, and add integration tests for Java PURL generation (#2075) William Murphy 2023-08-31 16:57:55 -04:00
  • b454160549
    tidy gomod and gitignore (#2082) v0.89.0 Alex Goodman 2023-08-31 10:50:32 -04:00
  • 36d794febe
    fix quiet flag (#2081) Alex Goodman 2023-08-31 10:40:11 -04:00
  • 51d38f8e59
    fix: in some cases, try to use pom info to guess name and version to top level jar (#2080) William Murphy 2023-08-31 10:19:55 -04:00
  • cfebae27f5
    fix: don't panic on universal go binaries (#2078) William Murphy 2023-08-30 08:37:50 -04:00
  • 2b7a9d0be3
    chore: update CLI to CLIO (#2001) Keith Zantow 2023-08-29 15:52:26 -04:00
  • b03e9c6868
    Add registry certificate verification support (#1734) 5p2O5pe25ouT 2023-08-29 23:45:20 +08:00
  • cedfa05e93
    fix: CPE generation for django (#2068) witchcraze 2023-08-28 21:28:01 +09:00
  • dd09e0362e
    chore: update quill to the latest version (#2065) v0.88.0 Keith Zantow 2023-08-25 16:45:04 -04:00
  • 4ae94c37eb
    fix: duplicate entries in cyclonedx dependency list (#2063) Keith Zantow 2023-08-25 12:19:01 -04:00
  • d08e2be768
    Fix panic in pom parsing (#2064) William Murphy 2023-08-25 12:04:57 -04:00
  • faa902209e
    Fix: don't validate pom declared group (#2054) William Murphy 2023-08-24 13:28:40 -04:00
  • 9a2a988e7f
    chore: trace log pom property reflect usage (#2059) William Murphy 2023-08-24 11:28:44 -04:00
  • 5ceef48949
    fix: do not double-prefix symlink paths that already contain volume names (#2051) Chris Selzo 2023-08-24 07:45:22 -07:00
  • 1848aa22cf
    feat: add bash classifier (#2055) witchcraze 2023-08-24 23:13:59 +09:00
  • 62f689824c
    Detect golang boring crypto and fipsonly modules (#2021) Sirish Bathina 2023-08-24 03:49:59 -10:00
  • 07ac640ac5
    fix: properly parse conan ref and include user and channel (#2034) Stefan Profanter 2023-08-23 19:51:07 +02:00
  • a2b389523d
    chore(deps): bump github.com/charmbracelet/lipgloss from 0.7.1 to 0.8.0 (#2053) dependabot[bot] 2023-08-23 13:41:17 -04:00
  • 17d4203bbb
    Enable reading non-utf-8 encodings for java pom.xml files (#2047) Alex Goodman 2023-08-23 10:06:34 -04:00
  • ee121cff21
    feat: 1944 - update purl generation to use a consistent groupID (#2033) Christopher Angelo Phillips 2023-08-22 10:47:07 -04:00
  • cf37b17869
    chore(deps): bump github.com/google/uuid from 1.3.0 to 1.3.1 (#2049) dependabot[bot] 2023-08-22 10:42:19 -04:00
  • ee656fe088
    chore(deps): update bootstrap tools to latest versions (#2048) anchore-actions-token-generator[bot] 2023-08-22 08:48:42 -04:00
  • f58425a305
    chore(deps): bump github.com/jinzhu/copier from 0.3.5 to 0.4.0 (#2045) dependabot[bot] 2023-08-21 10:37:11 -04:00
  • 01c7709e0d
    chore(deps): update CPE dictionary index (#2043) anchore-actions-token-generator[bot] 2023-08-21 09:33:41 -04:00
  • cb0214ec1d
    fill out new version notice (#2042) Alex Goodman 2023-08-18 16:03:11 -04:00
  • 4c3e49957c
    chore: more lenient java groupID lookups fix/more-lenient-java-groupid Keith Zantow 2023-08-17 14:38:28 -04:00
  • 4762ba0943
    feat: use java package names to determine known groupids (#2032) v0.87.1 Keith Zantow 2023-08-17 12:55:25 -04:00
  • d1635971a1
    fix: inconsistent removal of binaries by overlap (#2036) Keith Zantow 2023-08-17 11:27:31 -04:00
  • 9467bd66c2
    fix: CycloneDX relationships not output or decoded properly (#1974) Mark Galpin 2023-08-17 08:02:12 -07:00
  • 59107324ce
    chore: restore cataloger.DefaultConfig (#2028) Keith Zantow 2023-08-14 16:28:07 -04:00
  • b3d7ba569b
    fix: read direct package files when decoding SPDX tag-value (#2014) v0.87.0 Keith Zantow 2023-08-14 11:37:24 -04:00
  • c7fe58683d
    chore(deps): update bootstrap tools to latest versions (#2022) anchore-actions-token-generator[bot] 2023-08-14 11:36:15 -04:00
  • 28b06dae25
    chore(deps): update CPE dictionary index (#2025) anchore-actions-token-generator[bot] 2023-08-14 11:35:57 -04:00
  • 99344f506d
    chore: update snapshot verison Keith Zantow 2023-08-11 13:46:22 -04:00
  • fea371e36f
    chore: ensure syft binary is up-to-date when running CLI tests locally Keith Zantow 2023-08-10 17:49:28 -04:00
  • a90cff1cd2
    chore(deps): update bootstrap tools to latest versions (#2012) anchore-actions-token-generator[bot] 2023-08-10 13:20:09 -04:00
  • 82eafeaf4a
    chore(deps): bump github.com/vifraa/gopom from 0.2.2 to 1.0.0 (#2008) dependabot[bot] 2023-08-09 17:22:51 -04:00
  • 541c8d339b
    1948-filter-pkg-by-type (#2011) Christopher Angelo Phillips 2023-08-09 16:05:52 -04:00
  • 6bf6f85584
    chore(deps): bump github.com/dave/jennifer from 1.6.1 to 1.7.0 (#2009) dependabot[bot] 2023-08-09 14:46:11 -04:00
  • c7272fd6a5
    fix: SPDX license values and download location (#2007) Keith Zantow 2023-08-08 15:55:50 -04:00
  • 466da7cbda
    931: binary cataloger exclusion defaults for ownership by overlap (#1948) Christopher Angelo Phillips 2023-08-08 13:00:52 -04:00
  • 2fc65094b7
    chore(deps): bump golang.org/x/net from 0.13.0 to 0.14.0 (#2004) dependabot[bot] 2023-08-07 10:34:00 -04:00
  • d7ff77072a
    chore(deps): bump modernc.org/sqlite from 1.24.0 to 1.25.0 (#1998) dependabot[bot] 2023-08-04 14:24:31 -04:00
  • 78660022bf
    test: add coverage for new rpmdb paths (#1999) Christopher Angelo Phillips 2023-08-04 13:04:36 -04:00
  • aaf767f8d3
    chore: improve spdx purl decoding (#1996) Keith Zantow 2023-08-04 11:43:21 -04:00
  • 79014ed8c8
    fix: gradle lockfile parser groupId handling (#1995) Keith Zantow 2023-08-04 11:42:26 -04:00
  • e774006052
    fix: update glob to use newer usr/lib/sysimage path (#1997) Christopher Angelo Phillips 2023-08-03 19:23:50 -04:00
  • 1d6d5f7f5f
    fix: opkg search glob (#1994) Nicholas R. Smith 2023-08-03 12:33:11 -07:00
  • 433a7b8a42
    feat: nginx binary classifier (#1988) Sem Provoost 2023-08-03 19:09:31 +02:00
  • e55277f26d
    Expand deb cataloger to include opkg (#1985) Nicholas R. Smith 2023-08-03 09:33:14 -07:00
  • c2b4231cc3
    chore(deps): update bootstrap tools to latest versions (#1991) anchore-actions-token-generator[bot] 2023-08-03 10:53:29 -04:00
  • c150b4e358
    chore(deps): bump github.com/google/go-containerregistry (#1993) dependabot[bot] 2023-08-03 10:53:09 -04:00
  • 3f0475efb7
    chore: update bubbly to fix hanging (#1990) Keith Zantow 2023-08-02 10:28:35 -04:00
  • 2e376d067f
    chore(deps): bump golang.org/x/net from 0.12.0 to 0.13.0 (#1989) dependabot[bot] 2023-08-02 14:16:49 +00:00
  • 8e893dfc20
    feat: use originator logic to fill supplier (#1980) Christopher Angelo Phillips 2023-08-01 17:19:49 -04:00
  • 756d0f29af
    add metadata types to all cpe test fixtures (#1982) Alex Goodman 2023-07-31 16:35:09 -04:00
  • e2f7befbfb
    fix: default image source name to user input (#1979) v0.86.1 Keith Zantow 2023-07-31 13:29:18 -04:00
  • f14742b3f3
    chore(deps): update stereoscope to d1f3d766295ed3c8362ac1be68070e2a1dba4d03 (#1975) v0.86.0 anchore-actions-token-generator[bot] 2023-07-31 12:02:33 -04:00
  • 4fb9970481 Prevent hang if stderr is tty but stdout is not fix-tty-selection Will Murphy 2023-07-29 13:36:27 -04:00
  • 3aae316456
    chore: update to latest commit in tools-golang (#1969) Christopher Angelo Phillips 2023-07-27 15:29:22 -04:00
  • 063e9da65d
    Guess unpinned versions in python requirements.txt (#1966) Alex Goodman 2023-07-27 14:26:59 -04:00
  • bf1102c3f1
    chore(deps): bump github.com/vifraa/gopom from 0.2.1 to 0.2.2 (#1965) dependabot[bot] 2023-07-27 13:28:42 -04:00
  • bbd2d42dbb
    Fix panic condition on docker pull failure (#1968) Alex Goodman 2023-07-27 11:32:02 -04:00
  • d84120f499
    bump JSON schema to account for simplified python env markers (#1967) Alex Goodman 2023-07-27 10:13:17 -04:00