Commit Graph

  • 2c97ff1b24
    chore(deps): bump actions/cache from 5.0.0 to 5.0.1 (#4476) dependabot[bot] 2025-12-16 08:28:51 -05:00
  • e760a7cad4
    chore(deps): bump actions/cache in /.github/actions/bootstrap (#4477) dependabot[bot] 2025-12-16 08:28:48 -05:00
  • e1ae4e1112
    chore(deps): update tools to latest versions (#4473) anchore-actions-token-generator[bot] 2025-12-16 08:28:44 -05:00
  • beb70891e5
    unapply base path for resolver inbound requests (#4478) Alex Goodman 2025-12-16 08:28:12 -05:00
  • e0b61a3ae3
    fix: golang PURL should include full module (#4395) Rez Moss 2025-12-12 14:19:26 -05:00
  • 4c38ee1932
    fix:best effort to get the os info of an ELF binary (#4438) VictorHuu 2025-12-13 03:13:59 +08:00
  • 6be0a9abc4
    Improve PR template (#4472) Alex Goodman 2025-12-12 10:45:29 -05:00
  • ea1f4cba38
    feat: add support for Gemfile.next.lock (#4457) Alexandre Steppé 2025-12-12 16:20:53 +01:00
  • c8982b887d
    chore:cancel in-progress workflows for new commits on same PR (#4465) VictorHuu 2025-12-12 23:20:20 +08:00
  • 6ad4873a33
    chore(deps): update tools to latest versions (#4466) anchore-actions-token-generator[bot] 2025-12-12 08:49:02 -05:00
  • 052e4ca9a3
    chore(deps): bump github/codeql-action from 4.31.7 to 4.31.8 (#4468) dependabot[bot] 2025-12-12 08:48:36 -05:00
  • 41e133e2cf
    chore(deps): bump actions/cache from 4.3.0 to 5.0.0 (#4469) dependabot[bot] 2025-12-12 08:48:32 -05:00
  • a85e034afc
    chore(deps): bump github.com/anchore/stereoscope from 0.1.14 to 0.1.16 (#4470) dependabot[bot] 2025-12-12 08:48:28 -05:00
  • d5380013ae
    chore(deps): bump actions/cache in /.github/actions/bootstrap (#4471) dependabot[bot] 2025-12-12 08:48:22 -05:00
  • 281a9b87de keep both local and global symbols Alex Goodman 2025-12-11 14:20:44 -05:00
  • 5ea3387cbc
    chore(deps): update tools to latest versions (#4462) anchore-actions-token-generator[bot] 2025-12-11 09:55:34 -05:00
  • bf1f0ceea3 add support for PE binaries Alex Goodman 2025-12-10 13:53:00 -05:00
  • 568b7601bb
    fix(javascript): remove debug print statement in dependency parser (#4412) Chris Greeno 2025-12-10 18:42:09 +00:00
  • 7fdb08c0b6
    Validating download_url for github repositories, and updating if necessary (#4390) Kendrick 2025-12-10 10:41:00 -08:00
  • 47e1cee5a5
    chore(deps): update tools to latest versions (#4456) anchore-actions-token-generator[bot] 2025-12-10 13:34:42 -05:00
  • a0c5b8aa8d
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.5 to 6.7.7 (#4460) dependabot[bot] 2025-12-10 13:32:56 -05:00
  • ab5fa0a664
    chore(deps): bump peter-evans/create-pull-request from 7.0.11 to 8.0.0 (#4459) dependabot[bot] 2025-12-10 13:32:51 -05:00
  • 07ad8a5573
    chore(deps): bump anchore/sbom-action from 0.20.10 to 0.20.11 (#4458) dependabot[bot] 2025-12-10 13:32:47 -05:00
  • 703edff876 call file config validate in cli post load Alex Goodman 2025-12-10 13:22:45 -05:00
  • a05608a4c8 wire up cli config Alex Goodman 2025-12-10 12:53:41 -05:00
  • 41aa6f6753 fix test fixture Alex Goodman 2025-12-10 09:08:31 -05:00
  • 1a70ffe2fa bump json schema Alex Goodman 2025-12-10 09:08:17 -05:00
  • 33c5e40431 remove dead code Alex Goodman 2025-12-09 17:46:30 -05:00
  • 32946ec41f add gcc and clang toolchains Alex Goodman 2025-12-09 17:43:38 -05:00
  • bfe63f83db
    chore(deps): update anchore dependencies (#4440) v1.38.2 v1.38.1 anchore-actions-token-generator[bot] 2025-12-09 20:56:03 +00:00
  • 9bf4c5bdf9 initial prototype Alex Goodman 2025-12-09 11:31:48 -05:00
  • f01056d111
    chore(deps): update tools to latest versions (#4442) anchore-actions-token-generator[bot] 2025-12-09 11:00:08 -05:00
  • 09b24bdb47
    chore(deps): bump peter-evans/create-pull-request from 7.0.8 to 7.0.11 (#4447) dependabot[bot] 2025-12-09 09:59:32 -05:00
  • ae1fa09e02
    chore(deps): bump actions/create-github-app-token from 2.1.4 to 2.2.1 (#4445) dependabot[bot] 2025-12-09 09:57:48 -05:00
  • 6b0f924426
    chore(deps): bump github.com/go-git/go-billy/v5 from 5.6.2 to 5.7.0 (#4448) dependabot[bot] 2025-12-09 09:56:00 -05:00
  • 6d56087289
    chore(deps): bump github/codeql-action from 4.31.6 to 4.31.7 (#4446) dependabot[bot] 2025-12-09 09:47:52 -05:00
  • 1d718f3311
    chore(deps): bump golang.org/x/tools from 0.39.0 to 0.40.0 (#4453) dependabot[bot] 2025-12-09 09:46:52 -05:00
  • 9e3150b7ee
    fix: java archives excluded due to incorrect license glob results (#4449) Keith Zantow 2025-12-08 15:58:13 -05:00
  • d950ac1fae
    fix: use vercel for vendor in nextjs CPE (#4450) Will Murphy 2025-12-08 15:23:36 -05:00
  • baca32f04a
    fix:after compliance applied,the relationship concerning the original one should be omitted (#4419) VictorHuu 2025-12-05 04:30:16 +08:00
  • 155738aba7
    chore(deps): bump github.com/github/go-spdx/v2 from 2.3.4 to 2.3.5 (#4434) dependabot[bot] 2025-12-04 13:42:59 -05:00
  • 2b72158b0b
    chore(deps): bump github.com/spf13/cobra from 1.10.1 to 1.10.2 (#4435) dependabot[bot] 2025-12-04 13:42:50 -05:00
  • a80679beba
    chore(deps): bump actions/checkout from 6.0.0 to 6.0.1 (#4431) dependabot[bot] 2025-12-03 20:18:45 -05:00
  • b0c74d4104
    chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.17 to 0.5.18 (#4432) dependabot[bot] 2025-12-03 13:20:11 -05:00
  • afe28a2fc0
    fix:handle compound aliases like ``.tgz`` when cataloging archives (#4421) VictorHuu 2025-12-03 05:55:32 +08:00
  • 5b42bfe017
    fix: update identify to steam based detections archiver-compound-aliases Christopher Phillips 2025-12-02 11:46:14 -05:00
  • d37ed567a8
    chore: use git ls-files instead of find to list files (#4425) Will Murphy 2025-12-01 16:46:42 -05:00
  • e556ceb4a8
    chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.15 to 0.5.17 (#4413) dependabot[bot] 2025-12-01 16:34:38 -05:00
  • d8538e7d8b
    chore(deps): update tools to latest versions (#4420) anchore-actions-token-generator[bot] 2025-12-01 16:34:18 -05:00
  • cd19ac956c
    chore(deps): bump github.com/olekukonko/tablewriter from 1.1.1 to 1.1.2 (#4427) dependabot[bot] 2025-12-01 16:34:07 -05:00
  • d1a523fef5
    chore(deps): bump github/codeql-action from 4.31.4 to 4.31.6 (#4424) dependabot[bot] 2025-12-01 16:34:03 -05:00
  • e1e3d002bc
    chore(deps): bump github.com/goccy/go-yaml from 1.18.0 to 1.19.0 (#4426) dependabot[bot] 2025-12-01 16:33:48 -05:00
  • 57ec3a6561
    feat: apply HandleCompundArchiveAliases across syft Christopher Phillips 2025-12-01 11:05:59 -05:00
  • a0f7148608
    chore: ignore .DS_Store in test fixtures (#4422) Will Murphy 2025-12-01 10:15:35 -05:00
  • 4bbceb09c1 handle compound aliases like tar.gz when cataloging archives Yuntao Hu 2025-12-01 21:44:30 +08:00
  • 5b96d1d69d
    chore: rename test func for CPE decoder (#4379) Adam Chovanec 2025-11-26 05:05:31 +01:00
  • 6c666383e7
    chore(deps): bump anchore/sbom-action from 0.20.9 to 0.20.10 (#4381) dependabot[bot] 2025-11-25 23:05:05 -05:00
  • b9710a1e79
    chore(deps): bump modernc.org/sqlite from 1.40.0 to 1.40.1 (#4382) dependabot[bot] 2025-11-25 23:04:56 -05:00
  • 023a14f869
    chore(deps): bump actions/checkout from 5.0.0 to 6.0.0 (#4396) dependabot[bot] 2025-11-25 23:03:02 -05:00
  • 439a063d08
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.3 to 6.7.5 (#4397) dependabot[bot] 2025-11-25 10:20:59 -05:00
  • c95893209d
    fix: normalize python package names from dependency lists (#4408) Will Murphy 2025-11-25 10:20:21 -05:00
  • 7e02bdfe45
    chore(deps): update tools to latest versions (#4398) anchore-actions-token-generator[bot] 2025-11-25 10:17:33 -05:00
  • 479cf5aff2
    chore(deps): bump github.com/google/go-containerregistry (#4409) dependabot[bot] 2025-11-25 10:16:54 -05:00
  • 65e58ba33d feat: add support for detecting packages in JARs Patrick Pichler 2025-09-04 15:36:05 +02:00
  • f12788da78
    chore(deps): bump github/codeql-action from 4.31.3 to 4.31.4 (#4386) dependabot[bot] 2025-11-20 12:40:21 -05:00
  • 67709362b6
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.2 to 6.7.3 (#4387) dependabot[bot] 2025-11-20 12:01:21 -05:00
  • 55526dbde0
    chore(deps): bump golang.org/x/crypto from 0.44.0 to 0.45.0 (#4391) dependabot[bot] 2025-11-20 12:01:05 -05:00
  • af167ba0c1
    chore(deps): bump actions/setup-go from 6.0.0 to 6.1.0 (#4392) dependabot[bot] 2025-11-20 12:00:56 -05:00
  • 00e1329bd1
    chore(deps): bump actions/setup-go in /.github/actions/bootstrap (#4393) dependabot[bot] 2025-11-20 12:00:44 -05:00
  • 9aca8167b8
    chore: drop cpe from gguf (#4383) Christopher Angelo Phillips 2025-11-19 05:37:40 -05:00
  • 759909f611
    fix: emit lua rockspec dependencies in metadata (#4376) Will Murphy 2025-11-18 09:19:41 -05:00
  • 7014cb023f
    chore: options to run release-install-script without release (#4377) Keith Zantow 2025-11-17 17:12:04 -05:00
  • a033ae525f
    chore(deps): update anchore dependencies (#4374) v1.38.0 anchore-actions-token-generator[bot] 2025-11-17 12:17:15 -05:00
  • 1c22325385
    ci: output oras path (#4373) Will Murphy 2025-11-17 10:36:45 -05:00
  • 75ad5c6c74
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.1 to 6.7.2 (#4372) dependabot[bot] 2025-11-17 08:47:47 -05:00
  • d2641dfa39
    chore(deps): bump golang.org/x/tools from 0.38.0 to 0.39.0 (#4364) dependabot[bot] 2025-11-17 13:41:45 +00:00
  • 365325376a
    chore(deps): update tools to latest versions (#4370) anchore-actions-token-generator[bot] 2025-11-15 06:47:23 -05:00
  • 153f2321ce
    Fix test-fixture publish (#4369) Alex Goodman 2025-11-14 15:41:23 -05:00
  • 7bf7bcc461
    Support extras statements in Python PDM cataloger (#4352) Alex Goodman 2025-11-14 15:13:10 -05:00
  • 6a21b5e5e2
    chore(deps): update tools to latest versions (#4365) anchore-actions-token-generator[bot] 2025-11-14 09:25:27 -05:00
  • 6480c8a425
    chore(deps): bump github/codeql-action from 4.31.2 to 4.31.3 (#4366) dependabot[bot] 2025-11-14 09:25:08 -05:00
  • 89842bd2f6
    chore: migrate syft to use mholt/archives instead of anchore fork (#4029) Kudryavcev Nikolay 2025-11-14 02:04:43 +03:00
  • 4a60c41f38
    feat: 4184 gguf parser (ai artifact cataloger) part 1 (#4279) Christopher Angelo Phillips 2025-11-13 17:43:48 -05:00
  • 2e100f33f3
    chore(deps): update tools to latest versions (#4358) anchore-actions-token-generator[bot] 2025-11-12 13:27:47 -05:00
  • b444f0c2ed
    chore(deps): bump golang.org/x/mod from 0.29.0 to 0.30.0 (#4359) dependabot[bot] 2025-11-12 13:27:33 -05:00
  • 102d362daf
    feat: CPEs format decoder (#4207) Adam Chovanec 2025-11-12 16:45:09 +01:00
  • 66c78d44af
    Document additional json schema fields (#4356) Alex Goodman 2025-11-10 16:29:06 -05:00
  • 78a4ab8ced
    chore(deps): bump github.com/olekukonko/tablewriter from 1.0.9 to 1.1.1 (#4354) dependabot[bot] 2025-11-10 13:31:15 -05:00
  • 25ca33d20e
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.0 to 6.7.1 (#4355) dependabot[bot] 2025-11-10 13:30:56 -05:00
  • 60ca241593
    chore(deps): update tools to latest versions (#4347) anchore-actions-token-generator[bot] 2025-11-07 20:56:44 +00:00
  • 0f475c8bcd
    chore(deps): bump github.com/opencontainers/selinux (#4349) dependabot[bot] 2025-11-07 15:21:35 -05:00
  • 199394934d
    preserve --from order (#4350) Alex Goodman 2025-11-07 10:17:10 -05:00
  • 8a22d394ed
    chore(deps): bump golang.org/x/time from 0.12.0 to 0.14.0 (#4348) dependabot[bot] 2025-11-07 08:48:20 -05:00
  • bbef262b8f
    feat: Add license enrichment from pypi to python packages (#4295) Tim Olshansky 2025-11-06 13:05:08 -08:00
  • 4e06a7ab32
    feat(javascript): Add dependency parsing (#4304) Tim Olshansky 2025-11-06 13:03:43 -08:00
  • e5711e9b42
    Update CPE processing to use NVD API (#4332) Alex Goodman 2025-11-06 16:02:26 -05:00
  • f69b1db099
    feat: detect elixir bin (#4334) Rez Moss 2025-11-06 16:02:02 -05:00
  • efe8905d3e
    chore: move syft forward to latest golang golang-version-bump Christopher Phillips 2025-11-06 15:56:10 -05:00
  • fe1ea443c2
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.9 to 6.7.0 (#4337) dependabot[bot] 2025-11-06 15:47:49 -05:00
  • bfcbf266df
    chore(deps): bump github.com/containerd/containerd from 1.7.28 to 1.7.29 (#4340) dependabot[bot] 2025-11-06 15:46:32 -05:00