Commit Graph

  • 9480f10ccd
    feat: support top-level SPDX package and graph (#1934) Keith Zantow 2023-07-26 13:54:32 -04:00
  • 1e4d26f526
    chore(deps): bump github.com/go-git/go-git/v5 from 5.8.0 to 5.8.1 (#1959) dependabot[bot] 2023-07-26 13:34:03 +00:00
  • e1c1832f84
    Add cataloger for Swift Package Manager. (#1919) Tristan Farkas 2023-07-25 20:35:21 +02:00
  • 9a73380f29
    chore(deps): update stereoscope to d515761c6ca2743a67d7d08053db69235ae76d1d (#1953) anchore-actions-token-generator[bot] 2023-07-25 10:49:21 -04:00
  • 2e718cf865
    chore(deps): bump github.com/docker/docker (#1955) dependabot[bot] 2023-07-25 10:37:16 -04:00
  • 4000a84624
    chore(deps): bump github.com/go-git/go-git/v5 from 5.7.0 to 5.8.0 (#1951) dependabot[bot] 2023-07-24 11:28:54 -04:00
  • 99d172f0d1
    Introduce indexed embedded CPE dictionary (#1897) Dan Luhring 2023-07-21 09:54:19 -04:00
  • 3f5c601620
    chore(deps): bump github.com/gookit/color from 1.5.3 to 1.5.4 (#1949) dependabot[bot] 2023-07-21 08:50:47 -04:00
  • 8478e0bef7
    Add support for parsing .NET assemblies (#1943) Dan Luhring 2023-07-19 15:34:07 -04:00
  • 0327fdc88a
    docs: capture artifactory dev settings from 1895 (#1947) Christopher Angelo Phillips 2023-07-19 12:54:18 -04:00
  • 88b3d1e9bb remove build binary and add explicit git ignore Alex Goodman 2023-07-18 14:06:34 -04:00
  • 204b790012 docs: update docs with new docker specific instructions (#1941) Christopher Angelo Phillips 2023-07-17 14:19:21 -04:00
  • 35699f6fdc
    remove jotframe UI (#1932) Alex Goodman 2023-07-13 13:21:52 -04:00
  • 2e7fd031d4
    fix: remove indirect dependency of circl v1.1.0 (#1940) Christopher Angelo Phillips 2023-07-13 12:30:37 -04:00
  • 32296f5943
    chore: move wait before iteration to guarantee read before tea (#1931) Christopher Angelo Phillips 2023-07-12 13:59:31 -04:00
  • 4fc17edd14
    implement ui handle waiter (#1930) v0.85.0 Alex Goodman 2023-07-12 13:14:54 -04:00
  • 38efe4ec5f
    fix: background reader apart from global handler for testing (#1929) Christopher Angelo Phillips 2023-07-12 12:37:19 -04:00
  • 05a61897f2
    chore(deps): bump modernc.org/sqlite from 1.23.1 to 1.24.0 (#1928) dependabot[bot] 2023-07-11 14:01:48 -04:00
  • 5a7c200911
    fix: allow valid cyclonedx input with no components (#1873) James Neate 2023-07-11 18:56:36 +01:00
  • 72616db81f
    fix: "or-later" suffix updated to consider deprecated "+" operator (#1907) Christopher Angelo Phillips 2023-07-11 12:21:29 -04:00
  • 4ab9f393fc
    feat: CLI flag for directory base (#1867) Avi Deitcher 2023-07-10 20:36:41 +03:00
  • 9744f4c009
    Fix CPE gen for k8s python client (#1921) Dan Luhring 2023-07-10 11:54:19 -04:00
  • d21fa84335
    chore: update iterations to protect against race (#1927) Christopher Angelo Phillips 2023-07-10 11:44:54 -04:00
  • d5d95da3b6
    chore(deps): update bootstrap tools to latest versions (#1922) anchore-actions-token-generator[bot] 2023-07-10 11:03:09 -04:00
  • c0c089ffd5
    fix: Don't use the actual redis or grpc CPEs for gems (#1926) Dan Luhring 2023-07-10 10:24:42 -04:00
  • 376c42893b
    fix(install): return with right error code (#1915) Lorenzo Orsatti 2023-07-06 22:56:07 +02:00
  • 81d8019207
    Remove erroneous Java CPEs from generation (#1918) Dan Luhring 2023-07-06 16:12:55 -04:00
  • 8ce88e11fd
    chore(deps): bump golang.org/x/net from 0.11.0 to 0.12.0 (#1916) dependabot[bot] 2023-07-06 16:02:44 -04:00
  • f8b832e6c3
    Switch UI to bubbletea (#1888) Alex Goodman 2023-07-06 09:00:46 -04:00
  • a00a3df10c
    fix: use filepath.EvalSymlinks if os.Readlink fails to evaluate the link (#1884) DD (Devdatta) Deshpande 2023-07-06 00:19:22 +05:30
  • cfbb9f703b
    add file source digest support (#1914) Alex Goodman 2023-07-05 13:47:13 -04:00
  • 6280146c81
    chore(deps): update bootstrap tools to latest versions (#1908) anchore-actions-token-generator[bot] 2023-07-05 11:06:22 -04:00
  • e8f7108e6e
    chore(deps): bump golang.org/x/mod from 0.11.0 to 0.12.0 (#1912) dependabot[bot] 2023-07-05 11:06:05 -04:00
  • 023ca1be32
    chore(deps): bump golang.org/x/term from 0.9.0 to 0.10.0 (#1913) dependabot[bot] 2023-07-05 11:05:46 -04:00
  • 2e3c7fa158
    doc(readme): add installation section with scoop (#1909) Marco Damiani 2023-07-03 19:50:01 +02:00
  • 4da3be864f
    Refactor source API (#1846) Alex Goodman 2023-06-30 10:19:16 -04:00
  • 608dbded06
    chore(deps): update bootstrap tools to latest versions (#1905) anchore-actions-token-generator[bot] 2023-06-29 14:10:30 -04:00
  • 791d1f9552
    chore(deps): update stereoscope to cd49355d934e9e09339e0b690398afe7bd9f63f1 (#1903) v0.84.1 anchore-actions-token-generator[bot] 2023-06-28 12:05:12 -04:00
  • e5e97b5c4e
    chore(deps): update bootstrap tools to latest versions (#1902) anchore-actions-token-generator[bot] 2023-06-28 12:04:39 -04:00
  • 8219f8d55b
    fix: discover deb file relationships in distroless images (#1901) Weston Steimel 2023-06-28 13:28:20 +01:00
  • 026be3c0f1
    add oss community board auto-add workflow (#1898) Alex Goodman 2023-06-27 15:53:59 -04:00
  • 0d4f19043e
    chore(deps): update stereoscope to 8c7173ebcf69187d480d4d8b0c6cafaa7aef7024 (#1890) anchore-actions-token-generator[bot] 2023-06-26 13:58:44 -04:00
  • 38b47e484c
    chore(deps): update bootstrap tools to latest versions (#1894) anchore-actions-token-generator[bot] 2023-06-26 13:58:17 -04:00
  • 7943c73d3f
    fix: add support for Dart SDK package dependencies (#1891) Stephane Rufer 2023-06-23 09:40:46 -07:00
  • 25ce245c03
    Simplify the SBOM writer interface (#1892) Alex Goodman 2023-06-23 11:21:22 -04:00
  • 7de7a7990a
    fix: improve version detection in Java archive name parsing (#1889) Dan Luhring 2023-06-22 14:42:10 -04:00
  • f79cb9587f
    fix: only output valid cyclonedx license choices (#1879) Keith Zantow 2023-06-22 12:05:38 -04:00
  • c27d5b11d4
    docs: clarify reasoning of default catalogers for images or directories (#1887) Tim Gerla 2023-06-20 15:47:50 -04:00
  • 5d54e6e847
    Configure chronicle to pre-1.0 mode (#1886) v0.84.0 William Murphy 2023-06-20 12:08:35 -04:00
  • 631d50d038
    chore: update SPDX license list to 3.21 (#1885) Keith Zantow 2023-06-20 11:47:02 -04:00
  • 269006bf04
    chore(deps): update bootstrap tools to latest versions (#1880) anchore-actions-token-generator[bot] 2023-06-20 10:22:18 -04:00
  • e2ed89f700
    Pad artifact IDs (#1882) William Murphy 2023-06-16 13:26:18 -04:00
  • badb957888
    chore(deps): bump golang.org/x/mod from 0.10.0 to 0.11.0 (#1878) dependabot[bot] 2023-06-15 14:10:11 -04:00
  • a1bba36d51
    chore(deps): bump modernc.org/sqlite from 1.23.0 to 1.23.1 (#1874) v0.83.1 dependabot[bot] 2023-06-14 11:45:39 -04:00
  • c019cd51da
    chore(deps): update stereoscope to 5b5049bf4d3a99df9a2b1c31d5d52ddff7b5cec2 (#1871) anchore-actions-token-generator[bot] 2023-06-14 11:29:39 -04:00
  • 5406d8a366
    chore(deps): bump golang.org/x/net from 0.10.0 to 0.11.0 (#1876) dependabot[bot] 2023-06-14 10:30:19 -04:00
  • 098c255a2d
    fix: pom properties not setting artifact id (#1870) James Neate 2023-06-12 14:59:14 +01:00
  • 2c5d64ac9e
    chore(deps): bump github.com/spdx/tools-golang from 0.5.1 to 0.5.2 (#1868) dependabot[bot] 2023-06-08 17:01:19 -04:00
  • 1764e1c3f6
    fix: handle invalid symlinks (#1861) v0.83.0 Avi Deitcher 2023-06-05 22:04:14 +03:00
  • c560ffd811
    chore(deps): bump github.com/spdx/tools-golang from 0.5.0 to 0.5.1 (#1850) dependabot[bot] 2023-06-05 15:01:06 -04:00
  • 7d1b292ad0
    chore(deps): update bootstrap tools to latest versions (#1857) anchore-actions-token-generator[bot] 2023-06-05 18:56:04 +00:00
  • f07581f504
    Pr 1825 (#1865) Christopher Angelo Phillips 2023-06-05 13:01:00 -04:00
  • d676e5e781
    chore(deps): bump github.com/sirupsen/logrus from 1.9.2 to 1.9.3 (#1862) dependabot[bot] 2023-06-05 10:48:18 -04:00
  • 903d29b6f7
    chore(deps): bump modernc.org/sqlite from 1.22.1 to 1.23.0 (#1863) dependabot[bot] 2023-06-05 10:47:59 -04:00
  • 79a955b1a9
    feat: source-version flag (#1859) Keith Zantow 2023-06-05 10:36:34 -04:00
  • 1bd9de9047
    chore(deps): bump github.com/spf13/viper from 1.15.0 to 1.16.0 (#1851) dependabot[bot] 2023-06-01 08:35:14 -04:00
  • 68f8df9594
    accept main.version ldflags even without vcs (#1855) Avi Deitcher 2023-06-01 15:34:46 +03:00
  • c69cdd9f4a
    feat: add scope to pom properties (#1779) James Neate 2023-06-01 13:22:29 +01:00
  • 5842fc2a64
    chore(deps): bump github.com/stretchr/testify from 1.8.3 to 1.8.4 (#1852) dependabot[bot] 2023-05-30 13:48:54 -04:00
  • f0307fdd62
    chore(deps): bump github.com/docker/docker (#1849) dependabot[bot] 2023-05-26 16:08:20 -04:00
  • 74013d7da7
    Add test to ensure package metadata is represented in the JSON schema (#1841) Alex Goodman 2023-05-25 13:26:56 -04:00
  • 6afbffce28
    Fix directory resolver to consider CWD and root path input correctly (#1840) Alex Goodman 2023-05-25 09:41:18 -04:00
  • 07e76907f6
    Migrate location-related structs to the file package (#1751) Alex Goodman 2023-05-24 17:06:38 -04:00
  • 4bf17a94b9
    chore(deps): bump github.com/go-git/go-git/v5 from 5.6.1 to 5.7.0 (#1843) dependabot[bot] 2023-05-24 11:40:11 -04:00
  • 4ac8fdf6df
    fix: add panic recovery for license parse (#1839) v0.82.0 Christopher Angelo Phillips 2023-05-23 12:58:49 -04:00
  • 087a6356b9
    chore: return both failures when failed to retrieve an image with a scheme (#1801) Idan Frimark 2023-05-23 17:32:12 +03:00
  • 26c201f7f7
    Extract go module versions from ldflags for binaries built by go (#1832) Alex Goodman 2023-05-23 10:27:48 -04:00
  • a3c5550217
    fix: duplicate packages, support pnpm lockfile v6 (#1778) Keith Zantow 2023-05-23 10:24:25 -04:00
  • 798af57853
    chore(deps): update stereoscope to e14bc4437b2eac481c5b6f101890b22df4f33596 (#1834) anchore-actions-token-generator[bot] 2023-05-23 10:18:39 -04:00
  • f50302b2ba
    chore(deps): bump github.com/stretchr/testify from 1.8.2 to 1.8.3 (#1829) dependabot[bot] 2023-05-22 14:01:17 -04:00
  • b09cf6c6b5
    chore(deps): bump github.com/docker/docker (#1833) dependabot[bot] 2023-05-22 13:07:24 -04:00
  • 334a775cb9
    Keep original FileInfo persisted on file.Metadata structs (#1794) v0.81.0 Alex Goodman 2023-05-19 10:21:10 -04:00
  • f1b6f38ea8
    chore(deps): bump github.com/sirupsen/logrus from 1.9.1 to 1.9.2 (#1827) dependabot[bot] 2023-05-19 09:01:05 -04:00
  • f6f8332b7f
    chore(deps): bump github.com/google/go-containerregistry (#1823) dependabot[bot] 2023-05-17 14:34:27 -04:00
  • 74351567ab
    chore(deps): bump github.com/sirupsen/logrus from 1.9.0 to 1.9.1 (#1822) dependabot[bot] 2023-05-17 14:33:48 -04:00
  • 51d4c9b4ab
    chore(deps): bump github.com/docker/docker (#1824) dependabot[bot] 2023-05-17 14:33:30 -04:00
  • 4601ca3735
    fix: update field plurality of 8.0.0 schema before release (#1820) Christopher Angelo Phillips 2023-05-16 13:05:48 -04:00
  • 1a2a49840b
    fix: update cataloger to check for expressions before split (#1819) Christopher Angelo Phillips 2023-05-16 12:04:28 -04:00
  • 42fa9e4965
    feat: update syft license concept to complex struct (#1743) Christopher Angelo Phillips 2023-05-15 16:23:39 -04:00
  • 8046f09562
    fix: cyclonedx depends-on relationship inverted (#1816) Shane Alvarez 2023-05-15 07:59:26 -06:00
  • b4ed599481
    fix: retain sbom cataloger relationships (#1509) mikey strauss 2023-05-15 16:57:21 +03:00
  • e925d9d4a5
    feat: warn if parsing newer SBOM (#1810) William Murphy 2023-05-11 08:55:27 -04:00
  • da3624644a
    feat: Add R cataloger (#1790) William Murphy 2023-05-10 12:30:11 -04:00
  • 0580328ad9
    update cosign to v2 release (different go module) (#1805) Bob Callaway 2023-05-10 10:12:37 -05:00
  • 291da8cd12
    fix: Reduce log spam on unknown relationship type (#1797) William Murphy 2023-05-10 09:51:12 -04:00
  • 8a3cbf2fdd
    chore(deps): update bootstrap tools to latest versions (#1807) anchore-actions-token-generator[bot] 2023-05-10 08:25:36 -04:00
  • ef08d0fa39
    chore(deps): bump golang.org/x/net from 0.9.0 to 0.10.0 (#1802) dependabot[bot] 2023-05-09 11:59:39 -04:00
  • 75d625b697
    chore(deps): bump github.com/docker/docker (#1795) dependabot[bot] 2023-05-08 12:45:50 -04:00
  • 88ba8b78fc
    chore(deps): bump github.com/google/go-containerregistry (#1796) dependabot[bot] 2023-05-08 12:45:30 -04:00
  • 3f19aa589c
    chore(deps): update bootstrap tools to latest versions (#1792) anchore-actions-token-generator[bot] 2023-05-07 13:23:41 -04:00