Commit Graph

  • 63927ab49f
    chore(deps): update anchore dependencies (#4552) v1.40.1 anchore-actions-token-generator[bot] 2026-01-15 21:33:35 +00:00
  • 308b8030e7
    chore(deps): update tools to latest versions (#4551) anchore-actions-token-generator[bot] 2026-01-15 07:30:10 -05:00
  • 93ede85c9a
    qt bin classifier, fixed #4467 Rez Moss 2026-01-14 09:54:02 -05:00
  • af3503f3b5
    qt bin classifier, fixed #4467 Rez Moss 2026-01-13 16:36:07 -05:00
  • 873173da10
    qt bin classifier, fixed #4467 Rez Moss 2026-01-13 16:28:32 -05:00
  • 6d8a03b375
    chore(deps): update tools to latest versions (#4545) anchore-actions-token-generator[bot] 2026-01-12 11:05:17 -05:00
  • 55a190aed1
    chore(deps): update tools to latest versions (#4542) anchore-actions-token-generator[bot] 2026-01-09 13:14:13 -05:00
  • 695bbcc4f9
    chore(deps): bump the go-minor-patch group with 4 updates (#4543) dependabot[bot] 2026-01-09 13:13:56 -05:00
  • 6d206910f0
    chore(deps): bump anchore/sbom-action (#4544) dependabot[bot] 2026-01-09 13:13:44 -05:00
  • 2f3a504acf
    Feat/catalog mongodb bin (#4541) Rez Moss 2026-01-08 12:18:51 -05:00
  • d24e843c45
    chore(deps): update tools to latest versions (#4537) anchore-actions-token-generator[bot] 2026-01-08 11:56:50 -05:00
  • 83a4528fff
    chore: sync generated file immediately (#4538) Will Murphy 2026-01-08 09:01:17 -05:00
  • 11e871566b
    chore(deps): update anchore dependencies (#4535) v1.40.0 anchore-actions-token-generator[bot] 2026-01-08 12:16:49 +00:00
  • cc1a7dfae8
    chore: fix some comments to improve readability (#4533) promalert 2026-01-07 23:48:40 +08:00
  • 3a3a86eb01
    fixed #4430 exclude dev pnpm pkg (#4487) Rez Moss 2026-01-07 10:39:16 -05:00
  • 6509b7079e
    add istio classifier (#4521) witchcraze 2026-01-08 00:36:39 +09:00
  • 7f1d57d06f
    feat: detect older bitnami img packages (#4532) Rez Moss 2026-01-07 10:07:33 -05:00
  • ed339e4fed
    fix: ensure java image build failures stop the build (#4531) Alex Goodman 2026-01-06 11:43:51 -05:00
  • 3ea6a03cd0
    chore(deps): bump the go-minor-patch group with 3 updates (#4524) dependabot[bot] 2026-01-06 15:25:43 +00:00
  • 81dd955871
    add envoy binary classifier (#4530) witchcraze 2026-01-06 22:45:01 +09:00
  • 48948ddb8f
    add container support for graalvm fixture (#4528) Alex Goodman 2026-01-05 14:18:12 -05:00
  • 63273b1b00
    chore(deps): bump the actions-minor-patch group across 1 directory with 2 updates (#4525) dependabot[bot] 2026-01-05 12:48:30 -05:00
  • 92e523caa6
    chore(deps): bump actions/download-artifact from 6.0.0 to 7.0.0 (#4526) dependabot[bot] 2026-01-05 12:48:20 -05:00
  • 9b33b8a3d6
    chore(deps): bump actions/upload-artifact from 4.4.3 to 6.0.0 (#4527) dependabot[bot] 2026-01-05 12:48:13 -05:00
  • 29a0b19a21
    Group dependabot updates (#4522) Alex Goodman 2026-01-05 11:57:38 -05:00
  • ea43506196
    fix: corrects handling of UNC root paths in windows. Luis Miguel Santos 2026-01-05 11:32:07 -05:00
  • 2c96279df9
    fix: traefik binary classifier (#4499) Rez Moss 2026-01-05 11:14:00 -05:00
  • 488511f69d
    chore(deps): bump modernc.org/sqlite from 1.41.0 to 1.42.2 (#4513) dependabot[bot] 2026-01-05 10:46:39 -05:00
  • 11fed90075
    Migrate CI to runs-on (#4351) Alex Goodman 2026-01-05 09:53:06 -05:00
  • c8184bdb4c
    add grafana classifier (#4516) witchcraze 2026-01-05 23:51:41 +09:00
  • 15af992225
    add valkey classifier (#4509) witchcraze 2026-01-05 23:40:35 +09:00
  • 1e15428c6f
    chore(deps): bump anchore/sbom-action from 0.20.11 to 0.21.0 (#4501) dependabot[bot] 2026-01-05 09:19:40 -05:00
  • d1adfdc3a6
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.7 to 6.7.8 (#4502) dependabot[bot] 2026-01-05 09:19:34 -05:00
  • 0028165062
    chore(deps): bump github.com/spdx/tools-golang from 0.5.5 to 0.5.6 (#4503) dependabot[bot] 2026-01-05 09:19:29 -05:00
  • 997a76712f
    chore(deps): update tools to latest versions (#4504) anchore-actions-token-generator[bot] 2026-01-05 09:19:24 -05:00
  • e44ef53489
    chore(deps): bump github.com/hashicorp/go-getter from 1.8.3 to 1.8.4 (#4518) dependabot[bot] 2026-01-05 09:17:46 -05:00
  • e0708e725f
    chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.18 to 0.5.19 (#4520) dependabot[bot] 2026-01-05 09:17:39 -05:00
  • e9e3494853
    remove debug output (#4496) v1.39.0 Alex Goodman 2025-12-22 14:51:39 -05:00
  • b3c70da3ea
    Add experimental cataloger capabilities command (#4317) Alex Goodman 2025-12-22 14:34:10 -05:00
  • ae1a247f3d
    Unpin fixture dependencies that will always float (#4495) Alex Goodman 2025-12-22 14:17:58 -05:00
  • 0ea920ba6d
    Decompress UPX packed binaries to extract golang build info (ELF formatted binaries with lzma method only) (#4480) Alex Goodman 2025-12-22 09:17:38 -05:00
  • 7ef4703454
    chore(deps): update tools to latest versions (#4491) anchore-actions-token-generator[bot] 2025-12-22 09:15:51 -05:00
  • 8334fb04ec
    chore(deps): bump modernc.org/sqlite from 1.40.1 to 1.41.0 (#4489) dependabot[bot] 2025-12-19 11:00:31 -05:00
  • 3549b04e18 Merge remote-tracking branch 'origin/main' into add-go-symbol-extract add-go-symbol-extract Alex Goodman 2025-12-19 10:02:13 -05:00
  • c9760d2341
    feat: snap can be queried by revision and ``track/risk/branch`` (#4439) VictorHuu 2025-12-19 04:41:36 +08:00
  • 74c9380248
    fix: 4423 dotnet-deps cataloger skips project type by def Rez Moss 2025-12-18 13:38:47 -05:00
  • 7ed733c3fb
    signpost to docs site (#4483) Alex Goodman 2025-12-17 13:00:38 -05:00
  • a39c600913
    chore(deps): bump github/codeql-action from 4.31.8 to 4.31.9 (#4481) dependabot[bot] 2025-12-17 10:20:52 -05:00
  • a2020fe1c7
    chore(deps): bump github.com/goccy/go-yaml from 1.19.0 to 1.19.1 (#4482) dependabot[bot] 2025-12-17 10:20:43 -05:00
  • 89824f0ae7 Merge remote-tracking branch 'origin/main' into add-go-symbol-extract Alex Goodman 2025-12-16 13:53:31 -05:00
  • b361427043 add test coverage for cgo Alex Goodman 2025-12-16 13:47:55 -05:00
  • c79a57b6a1
    Detect embedded deps.json in .NET binaries (#4375) Rez Moss 2025-12-16 08:35:19 -05:00
  • 2c97ff1b24
    chore(deps): bump actions/cache from 5.0.0 to 5.0.1 (#4476) dependabot[bot] 2025-12-16 08:28:51 -05:00
  • e760a7cad4
    chore(deps): bump actions/cache in /.github/actions/bootstrap (#4477) dependabot[bot] 2025-12-16 08:28:48 -05:00
  • e1ae4e1112
    chore(deps): update tools to latest versions (#4473) anchore-actions-token-generator[bot] 2025-12-16 08:28:44 -05:00
  • beb70891e5
    unapply base path for resolver inbound requests (#4478) Alex Goodman 2025-12-16 08:28:12 -05:00
  • e0b61a3ae3
    fix: golang PURL should include full module (#4395) Rez Moss 2025-12-12 14:19:26 -05:00
  • 4c38ee1932
    fix:best effort to get the os info of an ELF binary (#4438) VictorHuu 2025-12-13 03:13:59 +08:00
  • 6be0a9abc4
    Improve PR template (#4472) Alex Goodman 2025-12-12 10:45:29 -05:00
  • ea1f4cba38
    feat: add support for Gemfile.next.lock (#4457) Alexandre Steppé 2025-12-12 16:20:53 +01:00
  • c8982b887d
    chore:cancel in-progress workflows for new commits on same PR (#4465) VictorHuu 2025-12-12 23:20:20 +08:00
  • 6ad4873a33
    chore(deps): update tools to latest versions (#4466) anchore-actions-token-generator[bot] 2025-12-12 08:49:02 -05:00
  • 052e4ca9a3
    chore(deps): bump github/codeql-action from 4.31.7 to 4.31.8 (#4468) dependabot[bot] 2025-12-12 08:48:36 -05:00
  • 41e133e2cf
    chore(deps): bump actions/cache from 4.3.0 to 5.0.0 (#4469) dependabot[bot] 2025-12-12 08:48:32 -05:00
  • a85e034afc
    chore(deps): bump github.com/anchore/stereoscope from 0.1.14 to 0.1.16 (#4470) dependabot[bot] 2025-12-12 08:48:28 -05:00
  • d5380013ae
    chore(deps): bump actions/cache in /.github/actions/bootstrap (#4471) dependabot[bot] 2025-12-12 08:48:22 -05:00
  • 281a9b87de keep both local and global symbols Alex Goodman 2025-12-11 14:20:44 -05:00
  • 5ea3387cbc
    chore(deps): update tools to latest versions (#4462) anchore-actions-token-generator[bot] 2025-12-11 09:55:34 -05:00
  • bf1f0ceea3 add support for PE binaries Alex Goodman 2025-12-10 13:53:00 -05:00
  • 568b7601bb
    fix(javascript): remove debug print statement in dependency parser (#4412) Chris Greeno 2025-12-10 18:42:09 +00:00
  • 7fdb08c0b6
    Validating download_url for github repositories, and updating if necessary (#4390) Kendrick 2025-12-10 10:41:00 -08:00
  • 47e1cee5a5
    chore(deps): update tools to latest versions (#4456) anchore-actions-token-generator[bot] 2025-12-10 13:34:42 -05:00
  • a0c5b8aa8d
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.5 to 6.7.7 (#4460) dependabot[bot] 2025-12-10 13:32:56 -05:00
  • ab5fa0a664
    chore(deps): bump peter-evans/create-pull-request from 7.0.11 to 8.0.0 (#4459) dependabot[bot] 2025-12-10 13:32:51 -05:00
  • 07ad8a5573
    chore(deps): bump anchore/sbom-action from 0.20.10 to 0.20.11 (#4458) dependabot[bot] 2025-12-10 13:32:47 -05:00
  • 703edff876 call file config validate in cli post load Alex Goodman 2025-12-10 13:22:45 -05:00
  • a05608a4c8 wire up cli config Alex Goodman 2025-12-10 12:53:41 -05:00
  • 41aa6f6753 fix test fixture Alex Goodman 2025-12-10 09:08:31 -05:00
  • 1a70ffe2fa bump json schema Alex Goodman 2025-12-10 09:08:17 -05:00
  • 33c5e40431 remove dead code Alex Goodman 2025-12-09 17:46:30 -05:00
  • 32946ec41f add gcc and clang toolchains Alex Goodman 2025-12-09 17:43:38 -05:00
  • bfe63f83db
    chore(deps): update anchore dependencies (#4440) v1.38.2 v1.38.1 anchore-actions-token-generator[bot] 2025-12-09 20:56:03 +00:00
  • 9bf4c5bdf9 initial prototype Alex Goodman 2025-12-09 11:31:48 -05:00
  • f01056d111
    chore(deps): update tools to latest versions (#4442) anchore-actions-token-generator[bot] 2025-12-09 11:00:08 -05:00
  • 09b24bdb47
    chore(deps): bump peter-evans/create-pull-request from 7.0.8 to 7.0.11 (#4447) dependabot[bot] 2025-12-09 09:59:32 -05:00
  • ae1fa09e02
    chore(deps): bump actions/create-github-app-token from 2.1.4 to 2.2.1 (#4445) dependabot[bot] 2025-12-09 09:57:48 -05:00
  • 6b0f924426
    chore(deps): bump github.com/go-git/go-billy/v5 from 5.6.2 to 5.7.0 (#4448) dependabot[bot] 2025-12-09 09:56:00 -05:00
  • 6d56087289
    chore(deps): bump github/codeql-action from 4.31.6 to 4.31.7 (#4446) dependabot[bot] 2025-12-09 09:47:52 -05:00
  • 1d718f3311
    chore(deps): bump golang.org/x/tools from 0.39.0 to 0.40.0 (#4453) dependabot[bot] 2025-12-09 09:46:52 -05:00
  • 9e3150b7ee
    fix: java archives excluded due to incorrect license glob results (#4449) Keith Zantow 2025-12-08 15:58:13 -05:00
  • d950ac1fae
    fix: use vercel for vendor in nextjs CPE (#4450) Will Murphy 2025-12-08 15:23:36 -05:00
  • baca32f04a
    fix:after compliance applied,the relationship concerning the original one should be omitted (#4419) VictorHuu 2025-12-05 04:30:16 +08:00
  • 155738aba7
    chore(deps): bump github.com/github/go-spdx/v2 from 2.3.4 to 2.3.5 (#4434) dependabot[bot] 2025-12-04 13:42:59 -05:00
  • 2b72158b0b
    chore(deps): bump github.com/spf13/cobra from 1.10.1 to 1.10.2 (#4435) dependabot[bot] 2025-12-04 13:42:50 -05:00
  • a80679beba
    chore(deps): bump actions/checkout from 6.0.0 to 6.0.1 (#4431) dependabot[bot] 2025-12-03 20:18:45 -05:00
  • b0c74d4104
    chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.17 to 0.5.18 (#4432) dependabot[bot] 2025-12-03 13:20:11 -05:00
  • afe28a2fc0
    fix:handle compound aliases like ``.tgz`` when cataloging archives (#4421) VictorHuu 2025-12-03 05:55:32 +08:00
  • 5b42bfe017
    fix: update identify to steam based detections archiver-compound-aliases Christopher Phillips 2025-12-02 11:46:14 -05:00
  • d37ed567a8
    chore: use git ls-files instead of find to list files (#4425) Will Murphy 2025-12-01 16:46:42 -05:00
  • e556ceb4a8
    chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.15 to 0.5.17 (#4413) dependabot[bot] 2025-12-01 16:34:38 -05:00