Commit Graph

  • 44422853be
    Add package-to-file location evidence relationships (#1698) Alex Goodman 2023-04-14 15:08:46 -04:00
  • cc731c7b19
    Add Linux Kernel cataloger (#1694) Avi Deitcher 2023-04-14 21:33:36 +03:00
  • 5d156b8241
    Add annotations for evidence on package locations (#1723) Alex Goodman 2023-04-13 17:02:29 -04:00
  • 05715489c4
    add format make target (#1733) Alex Goodman 2023-04-12 14:36:38 -04:00
  • 661d256b85
    Update tests to not fail on Mac M1's. (#1730) Shane Dell 2023-04-12 11:11:05 -04:00
  • dd30c99bc2
    chore(deps): update bootstrap tools to latest versions (#1728) v0.77.0 anchore-actions-token-generator[bot] 2023-04-11 10:13:14 -04:00
  • 16ebcb2455
    Add support for nar files. (#1727) Shane Dell 2023-04-11 09:41:49 -04:00
  • 305838582b
    add highlevel details about catalogers (#1726) Alex Goodman 2023-04-10 13:11:22 -04:00
  • a260fb2774
    chore(deps): bump golang.org/x/net from 0.8.0 to 0.9.0 (#1722) dependabot[bot] 2023-04-07 15:58:21 -04:00
  • f83cae35f2
    chore(deps): update stereoscope to e95d60a265e384df29b7a139f5c5402d6ad72e06 (#1721) anchore-actions-token-generator[bot] 2023-04-07 08:48:17 -04:00
  • 0fed17f1c8
    feat: gradle lockfile support (#1719) Henry Sachs 2023-04-06 20:58:28 +02:00
  • da44db92e9
    chore(deps): bump github.com/docker/docker (#1715) dependabot[bot] 2023-04-06 13:44:51 +00:00
  • 4a499c946e
    chore(deps): bump golang.org/x/mod from 0.9.0 to 0.10.0 (#1713) dependabot[bot] 2023-04-06 13:44:41 +00:00
  • 99c28a94a4
    chore(deps): bump golang.org/x/term from 0.6.0 to 0.7.0 (#1714) dependabot[bot] 2023-04-06 13:36:16 +00:00
  • f7ac4e98af
    chore(deps): bump github.com/spf13/cobra from 1.6.1 to 1.7.0 (#1716) dependabot[bot] 2023-04-06 09:34:59 -04:00
  • 394ec8d215
    chore(deps): bump peter-evans/create-pull-request from 4 to 5 (#1712) dependabot[bot] 2023-04-05 19:04:26 -04:00
  • 7845381331
    chore: update tools-golang to v0.5.0 (#1717) v0.76.1 Keith Zantow 2023-04-05 13:59:52 -04:00
  • 7464079a09
    Add Nix cataloger (#1696) Alex Goodman 2023-04-04 10:53:56 -04:00
  • 8a574c9ed9
    refactor spdx tooling test to reduce intermittent failures (#1707) Alex Goodman 2023-04-03 14:43:28 -04:00
  • 681d250fdc
    Capture file ownership relationships from portage ecosystem (#1702) Alex Goodman 2023-04-03 09:46:18 -04:00
  • 2022ffa0e5
    chore: update deprecated set-output calls (#1705) Keith Zantow 2023-04-03 09:36:11 -04:00
  • dfcc07e512
    feat: Add config option to allow user to select the default image source location v0.76.0 Christopher Angelo Phillips 2023-03-31 10:04:10 -04:00
  • 2fa238af7c
    chore(deps): bump github.com/docker/docker (#1699) dependabot[bot] 2023-03-29 10:00:37 -04:00
  • 63bbd1e3ed
    chore(deps): update bootstrap tools to latest versions (#1697) anchore-actions-token-generator[bot] 2023-03-27 09:17:34 -04:00
  • 81b87dd108
    chore(deps): update stereoscope to d7551b7f46f53179922d6229709d3d1602881080 (#1693) anchore-actions-token-generator[bot] 2023-03-23 16:30:08 +00:00
  • f473bb75a8
    1577 spdxlicense generate (#1691) Christopher Angelo Phillips 2023-03-23 11:48:24 -04:00
  • 539bc2afcb
    chore(deps): bump github.com/vbatts/go-mtree from 0.5.2 to 0.5.3 (#1692) dependabot[bot] 2023-03-23 11:09:32 -04:00
  • 9fd532246a
    feat: scan local go mod cache for licenses of golang packages (#1645) Avi Deitcher 2023-03-23 16:38:15 +02:00
  • 11e926ab2f
    chore: fix flaky license sorting (#1690) Keith Zantow 2023-03-22 14:41:49 -04:00
  • 168c5aed51
    chore(deps): bump github.com/gookit/color from 1.5.2 to 1.5.3 (#1689) dependabot[bot] 2023-03-22 14:26:58 -04:00
  • d02c56aa5f
    fix: shell completion by adding missing usage message required by spf13/cobra (#1688) Dan 2023-03-22 17:45:09 +00:00
  • 829a71cd92
    chore(deps): update bootstrap tools to latest versions (#1686) anchore-actions-token-generator[bot] 2023-03-22 09:01:24 -04:00
  • 34ace36a9e
    chore: tweak some workflow text (#1685) Keith Zantow 2023-03-21 11:08:49 -04:00
  • 100cf1003d
    Remove more side effects from application config testing (#1684) Alex Goodman 2023-03-20 16:53:45 -04:00
  • f11a7b5e9f
    Deprecate config.yaml as valid config source; Add unit regression for correct config paths (#1640) Aidan Delaney 2023-03-20 19:13:35 +00:00
  • 434aa7fd46
    chore: Update syft bootstrap tools to latest versions. (#1682) anchore-actions-token-generator[bot] 2023-03-20 13:20:48 -04:00
  • 5fb0423b72
    Update documentation: (#1680) Marc-Etienne Vargenau 2023-03-20 15:10:35 +01:00
  • 7998520848
    chore: Update Stereoscope to 7928713c391e20abaede6a029f4ce37b628a4c8b (#1681) anchore-actions-token-generator[bot] 2023-03-18 10:32:39 -04:00
  • d05000ff21
    fix: reduce logging for bad dpkg lines (#1675) Keith Zantow 2023-03-17 13:08:51 -04:00
  • f66e77e2c6
    fix ruby classifier (#1678) witchcraze 2023-03-17 22:42:20 +09:00
  • 928c4a55ff
    feat: add shared dir for easier cleanup (#1676) Christopher Angelo Phillips 2023-03-16 16:05:34 -04:00
  • 1899eb50d0
    chore(deps): bump github.com/google/go-containerregistry (#1672) dependabot[bot] 2023-03-16 12:07:47 -04:00
  • b5ec4d4f08
    chore(deps): bump actions/setup-go from 3 to 4 (#1671) dependabot[bot] 2023-03-16 12:02:07 -04:00
  • 61362c04fa
    fix: move defer after error to protect panic case (#1670) Christopher Angelo Phillips 2023-03-15 15:29:10 -04:00
  • e3140063d4
    feat: add argocd, helm, kustomize and kubectl binary classifiers (#1663) Joye Lin 2023-03-16 02:53:22 +08:00
  • 1d9ef34ec7
    defer closing file (#1668) razzle 2023-03-15 13:50:42 -05:00
  • 302735097e
    fix: remove author contributing to javascript CPEs (#1669) Keith Zantow 2023-03-14 10:10:24 -04:00
  • cc0a376aba
    fix: more python matching support (#1667) v0.75.0 Keith Zantow 2023-03-13 13:26:43 -04:00
  • b379dd9f27
    Update syft bootstrap tools to latest versions. (#1666) anchore-actions-token-generator[bot] 2023-03-13 10:40:13 -04:00
  • a81e0c8008
    feat: add ruby classifier (#1665) witchcraze 2023-03-10 22:29:40 +09:00
  • 41cbbe09b2
    Update syft bootstrap tools to latest versions. (#1658) v0.74.1 anchore-actions-token-generator[bot] 2023-03-07 12:54:32 -05:00
  • 7714bc0521
    fix: improved Python binary detection (#1648) Keith Zantow 2023-03-07 10:52:29 -05:00
  • 096d2b7bff
    fix: suppress some known incorrect vendor candidates for npm CPEs (#1659) Weston Steimel 2023-03-07 15:18:44 +00:00
  • 7cfdffab5f
    fix: sanitize SPDX LicenseRefs (#1657) Keith Zantow 2023-03-06 10:55:23 -05:00
  • f43953d225
    chore(deps): bump golang.org/x/mod from 0.8.0 to 0.9.0 (#1655) dependabot[bot] 2023-03-06 15:49:34 +00:00
  • eea1b48cbb
    chore(deps): bump golang.org/x/net from 0.7.0 to 0.8.0 (#1653) dependabot[bot] 2023-03-06 15:38:34 +00:00
  • a063cf300b
    chore(deps): bump github.com/spf13/afero from 1.9.4 to 1.9.5 (#1654) dependabot[bot] 2023-03-06 15:21:35 +00:00
  • b73903519c
    chore(deps): bump golang.org/x/term from 0.5.0 to 0.6.0 (#1656) dependabot[bot] 2023-03-06 15:20:43 +00:00
  • 304be4a5a1
    fix: dotnet PURL types are invalid (#1649) Keith Zantow 2023-03-03 16:45:20 -05:00
  • c4cbe211a3
    feat: disable cpe vendor wildcards to reduce false positives (#1647) Weston Steimel 2023-03-03 17:26:46 +00:00
  • 01230aa766
    read relative etc/apk/repositories for alpine version when no OS provided (#1615) Avi Deitcher 2023-03-02 20:04:56 +02:00
  • 5f90d03718
    fix: possible race condition (#1639) v0.74.0 Keith Zantow 2023-03-01 15:35:01 -05:00
  • e2ebc9769f
    fix: remove APK OriginPackage cpe candidates (#1637) Weston Steimel 2023-03-01 17:24:43 +00:00
  • 2e6e3b0c74
    fix: rebar lock file decoding panic (#1628) Keith Zantow 2023-03-01 10:08:29 -05:00
  • 24584a4d27
    fix: handle individual cataloger panics (#1636) Keith Zantow 2023-03-01 10:03:34 -05:00
  • 8e1205f7ab
    fix: apk product/vendor generation for old metadata (#1635) Weston Steimel 2023-03-01 14:58:35 +00:00
  • e92b0fa629
    feat: rust toolchain binary cataloger (#1601) Weston Steimel 2023-03-01 14:53:37 +00:00
  • bcc0751a40
    feat: retain go package info when no module declared (#1632) Weston Steimel 2023-03-01 14:26:44 +00:00
  • f1169e56fc
    fix: improved CPE-generation for several more APK packages (#1631) Weston Steimel 2023-03-01 13:55:40 +00:00
  • 98e737fc27
    chore: update deprecated release flag (#1629) Christopher Angelo Phillips 2023-02-27 15:57:56 -05:00
  • ff34594284
    chore(deps): bump actions/upload-artifact from 2 to 3 (#1627) dependabot[bot] 2023-02-27 14:17:29 -05:00
  • 9e953b1da3
    feat: add support for SUPPORT_END in /etc/os-release (#1612) Benji Visser 2023-02-27 11:43:19 -07:00
  • fbda21f4f4
    fix: further improvements to CPE generation for apk packages (#1623) Weston Steimel 2023-02-27 18:16:04 +00:00
  • d23b4d4cbd
    chore(deps): bump github.com/stretchr/testify from 1.8.1 to 1.8.2 (#1625) dependabot[bot] 2023-02-27 13:14:20 -05:00
  • f3acff81f3
    chore(deps): bump actions/checkout from 2 to 3 (#1626) dependabot[bot] 2023-02-27 13:14:03 -05:00
  • fa0a9fe8f9
    feat: set cosign attest predicate type based on Syft output type (#1598) Nils Hanke 2023-02-24 21:08:40 +01:00
  • 284bae9d5f
    chore(deps): bump github.com/spf13/afero from 1.9.3 to 1.9.4 (#1609) dependabot[bot] 2023-02-24 15:07:52 -05:00
  • 3ee1af0dc6
    fix: correct apk purls for other distros (#1620) Weston Steimel 2023-02-24 20:07:07 +00:00
  • 0c5f03235e
    refactor: move apk upstream logic to apk metadata (#1619) Weston Steimel 2023-02-24 15:59:19 +00:00
  • 5e8aa4da5e
    fix: decoding null apk metadata pullDependencies (#1614) Keith Zantow 2023-02-23 14:55:49 -05:00
  • abfec62219
    feat: haproxy binary matcher (#1591) Benji Visser 2023-02-23 12:39:08 -07:00
  • 0c05855131
    fix: determine upstream for apk version streams (#1610) Weston Steimel 2023-02-23 17:32:34 +00:00
  • 1150772d06
    fix: improve CPE generation for curl APK (#1608) Weston Steimel 2023-02-23 17:32:12 +00:00
  • be71f7c6ae
    disable changelog, version file updates, brew, and some docker tags on release v0.72.1 Alex Goodman 2023-02-22 16:34:11 -05:00
  • 8220a8731a
    Update SPDX license list to 3.20 (#1600) Marc-Etienne Vargenau 2023-02-21 21:12:28 +01:00
  • 56fdb8d2bf
    chore: update SPDX license list (#1599) Keith Zantow 2023-02-21 12:31:24 -05:00
  • 4011928613
    Update Stereoscope to fab1c9638abc2c21cd53dca1f205f37d71148ee0 (#1604) anchore-actions-token-generator[bot] 2023-02-22 19:08:35 +00:00
  • 669fee84d5
    Revert "add workaround for macos github actions cache issue (#1584)" (#1605) Alex Goodman 2023-02-22 15:03:12 -05:00
  • aa151da5fe
    Update Stereoscope to fab1c9638abc2c21cd53dca1f205f37d71148ee0 (#1604) v0.73.0 anchore-actions-token-generator[bot] 2023-02-22 19:08:35 +00:00
  • 4bf677d555
    chore: fix cataloger_test (#1603) Keith Zantow 2023-02-22 12:30:41 -05:00
  • f5e20521e0
    fix: merging of binary packages (#1583) Keith Zantow 2023-02-22 12:03:15 -05:00
  • 8f6a317fef
    fix: issue when matching format versions (#1585) Keith Zantow 2023-02-22 10:32:05 -05:00
  • d339ffdcb5
    chore: update syft bootstrap tools to latest versions. (#1593) anchore-actions-token-generator[bot] 2023-02-22 10:16:14 -05:00
  • e84ffc6003
    feat: add perl binary classifier (#1592) Benji Visser 2023-02-22 07:58:05 -07:00
  • bb52a25c8a
    Update Stereoscope to 529924d6d5aa6c708cceffc651883b6e1e27f5df (#1602) anchore-actions-token-generator[bot] 2023-02-22 08:49:04 +00:00
  • 4b7b709473
    Update SPDX license list to 3.20 (#1600) Marc-Etienne Vargenau 2023-02-21 21:12:28 +01:00
  • 2ef2eed382
    chore: update SPDX license list (#1599) Keith Zantow 2023-02-21 12:31:24 -05:00
  • f6716092af
    fix cataloger selection to be more specific (#1582) Alex Goodman 2023-02-17 10:35:54 -05:00
  • 0076b19893
    add workaround for macos github actions cache issue (#1584) Alex Goodman 2023-02-17 10:29:33 -05:00
  • 2642a36161
    Update Stereoscope to 4b5ebf8c7f4b81ca79c4c3f0af1d0723eab87d42 (#1576) v0.72.0 anchore-actions-token-generator[bot] 2023-02-16 10:22:43 -05:00