Commit Graph

  • 903d29b6f7
    chore(deps): bump modernc.org/sqlite from 1.22.1 to 1.23.0 (#1863) dependabot[bot] 2023-06-05 10:47:59 -04:00
  • 79a955b1a9
    feat: source-version flag (#1859) Keith Zantow 2023-06-05 10:36:34 -04:00
  • 1bd9de9047
    chore(deps): bump github.com/spf13/viper from 1.15.0 to 1.16.0 (#1851) dependabot[bot] 2023-06-01 08:35:14 -04:00
  • 68f8df9594
    accept main.version ldflags even without vcs (#1855) Avi Deitcher 2023-06-01 15:34:46 +03:00
  • c69cdd9f4a
    feat: add scope to pom properties (#1779) James Neate 2023-06-01 13:22:29 +01:00
  • 5842fc2a64
    chore(deps): bump github.com/stretchr/testify from 1.8.3 to 1.8.4 (#1852) dependabot[bot] 2023-05-30 13:48:54 -04:00
  • f0307fdd62
    chore(deps): bump github.com/docker/docker (#1849) dependabot[bot] 2023-05-26 16:08:20 -04:00
  • 74013d7da7
    Add test to ensure package metadata is represented in the JSON schema (#1841) Alex Goodman 2023-05-25 13:26:56 -04:00
  • 6afbffce28
    Fix directory resolver to consider CWD and root path input correctly (#1840) Alex Goodman 2023-05-25 09:41:18 -04:00
  • 07e76907f6
    Migrate location-related structs to the file package (#1751) Alex Goodman 2023-05-24 17:06:38 -04:00
  • 4bf17a94b9
    chore(deps): bump github.com/go-git/go-git/v5 from 5.6.1 to 5.7.0 (#1843) dependabot[bot] 2023-05-24 11:40:11 -04:00
  • 4ac8fdf6df
    fix: add panic recovery for license parse (#1839) v0.82.0 Christopher Angelo Phillips 2023-05-23 12:58:49 -04:00
  • 087a6356b9
    chore: return both failures when failed to retrieve an image with a scheme (#1801) Idan Frimark 2023-05-23 17:32:12 +03:00
  • 26c201f7f7
    Extract go module versions from ldflags for binaries built by go (#1832) Alex Goodman 2023-05-23 10:27:48 -04:00
  • a3c5550217
    fix: duplicate packages, support pnpm lockfile v6 (#1778) Keith Zantow 2023-05-23 10:24:25 -04:00
  • 798af57853
    chore(deps): update stereoscope to e14bc4437b2eac481c5b6f101890b22df4f33596 (#1834) anchore-actions-token-generator[bot] 2023-05-23 10:18:39 -04:00
  • f50302b2ba
    chore(deps): bump github.com/stretchr/testify from 1.8.2 to 1.8.3 (#1829) dependabot[bot] 2023-05-22 14:01:17 -04:00
  • b09cf6c6b5
    chore(deps): bump github.com/docker/docker (#1833) dependabot[bot] 2023-05-22 13:07:24 -04:00
  • 334a775cb9
    Keep original FileInfo persisted on file.Metadata structs (#1794) v0.81.0 Alex Goodman 2023-05-19 10:21:10 -04:00
  • f1b6f38ea8
    chore(deps): bump github.com/sirupsen/logrus from 1.9.1 to 1.9.2 (#1827) dependabot[bot] 2023-05-19 09:01:05 -04:00
  • f6f8332b7f
    chore(deps): bump github.com/google/go-containerregistry (#1823) dependabot[bot] 2023-05-17 14:34:27 -04:00
  • 74351567ab
    chore(deps): bump github.com/sirupsen/logrus from 1.9.0 to 1.9.1 (#1822) dependabot[bot] 2023-05-17 14:33:48 -04:00
  • 51d4c9b4ab
    chore(deps): bump github.com/docker/docker (#1824) dependabot[bot] 2023-05-17 14:33:30 -04:00
  • 4601ca3735
    fix: update field plurality of 8.0.0 schema before release (#1820) Christopher Angelo Phillips 2023-05-16 13:05:48 -04:00
  • 1a2a49840b
    fix: update cataloger to check for expressions before split (#1819) Christopher Angelo Phillips 2023-05-16 12:04:28 -04:00
  • 42fa9e4965
    feat: update syft license concept to complex struct (#1743) Christopher Angelo Phillips 2023-05-15 16:23:39 -04:00
  • 8046f09562
    fix: cyclonedx depends-on relationship inverted (#1816) Shane Alvarez 2023-05-15 07:59:26 -06:00
  • b4ed599481
    fix: retain sbom cataloger relationships (#1509) mikey strauss 2023-05-15 16:57:21 +03:00
  • e925d9d4a5
    feat: warn if parsing newer SBOM (#1810) William Murphy 2023-05-11 08:55:27 -04:00
  • da3624644a
    feat: Add R cataloger (#1790) William Murphy 2023-05-10 12:30:11 -04:00
  • 0580328ad9
    update cosign to v2 release (different go module) (#1805) Bob Callaway 2023-05-10 10:12:37 -05:00
  • 291da8cd12
    fix: Reduce log spam on unknown relationship type (#1797) William Murphy 2023-05-10 09:51:12 -04:00
  • 8a3cbf2fdd
    chore(deps): update bootstrap tools to latest versions (#1807) anchore-actions-token-generator[bot] 2023-05-10 08:25:36 -04:00
  • ef08d0fa39
    chore(deps): bump golang.org/x/net from 0.9.0 to 0.10.0 (#1802) dependabot[bot] 2023-05-09 11:59:39 -04:00
  • 75d625b697
    chore(deps): bump github.com/docker/docker (#1795) dependabot[bot] 2023-05-08 12:45:50 -04:00
  • 88ba8b78fc
    chore(deps): bump github.com/google/go-containerregistry (#1796) dependabot[bot] 2023-05-08 12:45:30 -04:00
  • 3f19aa589c
    chore(deps): update bootstrap tools to latest versions (#1792) anchore-actions-token-generator[bot] 2023-05-07 13:23:41 -04:00
  • 630c18e0d3
    Print package list when extra packages found (#1791) William Murphy 2023-05-05 15:57:13 -04:00
  • 1860bab24b
    chore(deps): update bootstrap tools to latest versions (#1786) anchore-actions-token-generator[bot] 2023-05-05 14:57:02 -04:00
  • e31839a370
    chore(deps): bump golang.org/x/term from 0.7.0 to 0.8.0 (#1787) dependabot[bot] 2023-05-05 18:56:40 +00:00
  • 0f1aed4477
    Update the CPE generation for spring-security-core (#1789) v0.80.0 Josh Bressers 2023-05-05 10:41:41 -05:00
  • ddb338d834
    chore: do not HTML escape PackageURLs (#1782) Keith Zantow 2023-05-05 10:08:04 -04:00
  • 354c72bbf4
    chore: do not include kernel module cataloger by default (#1784) Keith Zantow 2023-05-05 09:54:24 -04:00
  • d63a1f5f80
    chore(docs): Update lists of catalogers (#1780) Jeff Squyres 2023-05-04 15:36:22 -04:00
  • 645206735e
    chore: add more detail on SPDX file IDs (#1769) Keith Zantow 2023-05-02 16:52:18 -04:00
  • 95a04cadea
    Search /usr/share for rpmdb to fix scan on ostree-managed images (#1756) Filip Pytloun 2023-05-02 22:43:52 +02:00
  • dd458a2b33
    chore(deps): bump github.com/docker/docker (#1767) dependabot[bot] 2023-05-02 16:43:16 -04:00
  • 5f3d4d285b
    rename sbom.PackageCatalog to sbom.Packages (#1773) Alex Goodman 2023-05-01 10:19:58 -04:00
  • 10c3cc27e8
    chore(deps): bump modernc.org/sqlite from 1.22.0 to 1.22.1 (#1768) dependabot[bot] 2023-04-27 11:58:59 -04:00
  • a07bfe7dfa
    Create python requirements metadata (#1759) Shane Dell 2023-04-27 09:04:30 -04:00
  • 451cb9d5ca
    chore: update test redactor ordering (#1765) Keith Zantow 2023-04-26 16:42:43 -04:00
  • fd02bef0a3
    rename pkg.Catalog to pkg.Collection (#1764) Alex Goodman 2023-04-26 13:56:33 -04:00
  • 02bd52728e
    chore(deps): bump modernc.org/sqlite from 1.21.2 to 1.22.0 (#1758) dependabot[bot] 2023-04-26 10:37:49 -04:00
  • c038f13d44
    chore: go-rpmdb update (#1757) Christopher Angelo Phillips 2023-04-24 10:34:13 -04:00
  • 8102ad4edc
    chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.7.1-0.20221222100750-41a1ac565cce to 0.7.1 (#1706) dependabot[bot] 2023-04-24 10:20:12 -04:00
  • 13485ca5e7
    fix: Improve pnpm support (#1752) Shane Dell 2023-04-21 13:58:23 -04:00
  • b2b332e8b2
    feat: Add template func hasField (#1754) v0.79.0 Alex Lehman 2023-04-21 09:34:06 -04:00
  • a42bac6fcc
    fix: only cache java packages and not source content (#1750) Christopher Angelo Phillips 2023-04-19 16:07:34 -04:00
  • 98a6c6efbe
    Add sections of interest for Gemfile.lock cataloger (#1749) Shane Dell 2023-04-19 12:18:17 -04:00
  • 55a90a2ee0
    fix: update cache.fingerprint file to java-builds dir (#1748) Christopher Angelo Phillips 2023-04-19 12:17:07 -04:00
  • 6e835fd8fc
    Add ALPM Metadata to CYCLONEDX and SPDX output formats (#1747) Shane Dell 2023-04-18 11:53:02 -04:00
  • ee80349ea0
    chore: bump stereoscope to latest version (#1741) Weston Steimel 2023-04-18 16:44:03 +01:00
  • 52b54bbad9
    chore(deps): update bootstrap tools to latest versions (#1744) anchore-actions-token-generator[bot] 2023-04-18 10:25:02 -04:00
  • 66d9c5637b
    chore(deps): bump github.com/docker/docker (#1746) dependabot[bot] 2023-04-18 10:22:41 -04:00
  • 244b797a19
    Create consul binary classifier (#1738) v0.78.0 Shane Dell 2023-04-17 12:26:07 -04:00
  • 95176d7e0c
    chore(deps): update bootstrap tools to latest versions (#1740) anchore-actions-token-generator[bot] 2023-04-17 12:06:35 -04:00
  • 5a7bab972c
    Fix kernel cataloger test fixtures (#1742) Alex Goodman 2023-04-17 11:44:46 -04:00
  • b69259534d
    feat: Support scanning license files in golang packages over the network (#1630) Avi Deitcher 2023-04-14 22:13:29 +03:00
  • 44422853be
    Add package-to-file location evidence relationships (#1698) Alex Goodman 2023-04-14 15:08:46 -04:00
  • cc731c7b19
    Add Linux Kernel cataloger (#1694) Avi Deitcher 2023-04-14 21:33:36 +03:00
  • 5d156b8241
    Add annotations for evidence on package locations (#1723) Alex Goodman 2023-04-13 17:02:29 -04:00
  • 05715489c4
    add format make target (#1733) Alex Goodman 2023-04-12 14:36:38 -04:00
  • 661d256b85
    Update tests to not fail on Mac M1's. (#1730) Shane Dell 2023-04-12 11:11:05 -04:00
  • dd30c99bc2
    chore(deps): update bootstrap tools to latest versions (#1728) v0.77.0 anchore-actions-token-generator[bot] 2023-04-11 10:13:14 -04:00
  • 16ebcb2455
    Add support for nar files. (#1727) Shane Dell 2023-04-11 09:41:49 -04:00
  • 305838582b
    add highlevel details about catalogers (#1726) Alex Goodman 2023-04-10 13:11:22 -04:00
  • a260fb2774
    chore(deps): bump golang.org/x/net from 0.8.0 to 0.9.0 (#1722) dependabot[bot] 2023-04-07 15:58:21 -04:00
  • f83cae35f2
    chore(deps): update stereoscope to e95d60a265e384df29b7a139f5c5402d6ad72e06 (#1721) anchore-actions-token-generator[bot] 2023-04-07 08:48:17 -04:00
  • 0fed17f1c8
    feat: gradle lockfile support (#1719) Henry Sachs 2023-04-06 20:58:28 +02:00
  • da44db92e9
    chore(deps): bump github.com/docker/docker (#1715) dependabot[bot] 2023-04-06 13:44:51 +00:00
  • 4a499c946e
    chore(deps): bump golang.org/x/mod from 0.9.0 to 0.10.0 (#1713) dependabot[bot] 2023-04-06 13:44:41 +00:00
  • 99c28a94a4
    chore(deps): bump golang.org/x/term from 0.6.0 to 0.7.0 (#1714) dependabot[bot] 2023-04-06 13:36:16 +00:00
  • f7ac4e98af
    chore(deps): bump github.com/spf13/cobra from 1.6.1 to 1.7.0 (#1716) dependabot[bot] 2023-04-06 09:34:59 -04:00
  • 394ec8d215
    chore(deps): bump peter-evans/create-pull-request from 4 to 5 (#1712) dependabot[bot] 2023-04-05 19:04:26 -04:00
  • 7845381331
    chore: update tools-golang to v0.5.0 (#1717) v0.76.1 Keith Zantow 2023-04-05 13:59:52 -04:00
  • 7464079a09
    Add Nix cataloger (#1696) Alex Goodman 2023-04-04 10:53:56 -04:00
  • 8a574c9ed9
    refactor spdx tooling test to reduce intermittent failures (#1707) Alex Goodman 2023-04-03 14:43:28 -04:00
  • 681d250fdc
    Capture file ownership relationships from portage ecosystem (#1702) Alex Goodman 2023-04-03 09:46:18 -04:00
  • 2022ffa0e5
    chore: update deprecated set-output calls (#1705) Keith Zantow 2023-04-03 09:36:11 -04:00
  • dfcc07e512
    feat: Add config option to allow user to select the default image source location v0.76.0 Christopher Angelo Phillips 2023-03-31 10:04:10 -04:00
  • 2fa238af7c
    chore(deps): bump github.com/docker/docker (#1699) dependabot[bot] 2023-03-29 10:00:37 -04:00
  • 63bbd1e3ed
    chore(deps): update bootstrap tools to latest versions (#1697) anchore-actions-token-generator[bot] 2023-03-27 09:17:34 -04:00
  • 81b87dd108
    chore(deps): update stereoscope to d7551b7f46f53179922d6229709d3d1602881080 (#1693) anchore-actions-token-generator[bot] 2023-03-23 16:30:08 +00:00
  • f473bb75a8
    1577 spdxlicense generate (#1691) Christopher Angelo Phillips 2023-03-23 11:48:24 -04:00
  • 539bc2afcb
    chore(deps): bump github.com/vbatts/go-mtree from 0.5.2 to 0.5.3 (#1692) dependabot[bot] 2023-03-23 11:09:32 -04:00
  • 9fd532246a
    feat: scan local go mod cache for licenses of golang packages (#1645) Avi Deitcher 2023-03-23 16:38:15 +02:00
  • 11e926ab2f
    chore: fix flaky license sorting (#1690) Keith Zantow 2023-03-22 14:41:49 -04:00
  • 168c5aed51
    chore(deps): bump github.com/gookit/color from 1.5.2 to 1.5.3 (#1689) dependabot[bot] 2023-03-22 14:26:58 -04:00
  • d02c56aa5f
    fix: shell completion by adding missing usage message required by spf13/cobra (#1688) Dan 2023-03-22 17:45:09 +00:00
  • 829a71cd92
    chore(deps): update bootstrap tools to latest versions (#1686) anchore-actions-token-generator[bot] 2023-03-22 09:01:24 -04:00