Commit Graph

  • 8c91605541
    1465 attestation with private key (#1502) Christopher Angelo Phillips 2023-01-26 11:19:13 -05:00
  • 4c0aef09b8
    fix: add relevant CPEs to python and busybox classifiers (#1517) v0.68.1 Weston Steimel 2023-01-25 17:18:24 +00:00
  • 02fb757c21
    Update syft bootstrap tools to latest versions. (#1515) anchore-actions-token-generator[bot] 2023-01-25 10:31:53 -05:00
  • 674a54512c
    chore: correct bootstrap tool script (#1514) Keith Zantow 2023-01-25 10:22:28 -05:00
  • 21ba5d0806
    chore(deps): bump github.com/google/go-containerregistry (#1513) dependabot[bot] 2023-01-25 13:41:43 +00:00
  • 0ba57a5936
    Fix AssertEncoderAgainstGoldenSnapshot calls to conditionally update (#1511) Alex Goodman 2023-01-24 16:41:57 -05:00
  • 3269bc98d4
    chore(deps): bump golang.org/x/mod from 0.6.0 to 0.7.0 (#1505) dependabot[bot] 2023-01-23 15:01:25 -05:00
  • 7f3382f7eb
    chore(deps): bump github.com/docker/docker (#1506) dependabot[bot] 2023-01-23 14:58:39 -05:00
  • 65e5ff63f0
    chore(deps): bump github.com/Masterminds/sprig/v3 from 3.2.2 to 3.2.3 (#1507) dependabot[bot] 2023-01-23 14:48:22 -05:00
  • d287c22b69
    chore(deps): bump github.com/dustin/go-humanize from 1.0.0 to 1.0.1 (#1508) dependabot[bot] 2023-01-23 14:48:00 -05:00
  • e8be93a8eb
    Bump github.com/spdx/tools-golang to v0.4.0 (#1450) Luca Comellini 2023-01-20 14:00:21 -08:00
  • e58050bac0
    Fix panic in apkdb parsing on empty "provides" values (#1494) v0.68.0 Dan Luhring 2023-01-20 09:49:44 -05:00
  • 36a0945c95
    push detailed log statements to trace-level (#1500) Alex Goodman 2023-01-20 09:33:23 -05:00
  • 396441e921
    npm: package-lock license decoding to accept string or array (#1482) mikcl 2023-01-20 14:28:51 +00:00
  • 972e4cdaeb
    always set the package ID for java packages (#1493) Alex Goodman 2023-01-20 09:18:00 -05:00
  • 99f55f6a81
    fix: skip filling in empty fields in APK metadata (#1484) Nils Hanke 2023-01-20 15:03:30 +01:00
  • 285112fe29
    chore(deps): bump github.com/facebookincubator/nvdtools (#1499) dependabot[bot] 2023-01-20 14:02:47 +00:00
  • f29bea5921
    chore(deps): bump github.com/jinzhu/copier from 0.3.2 to 0.3.5 (#1498) dependabot[bot] 2023-01-20 08:51:20 -05:00
  • 39cdbc42aa
    chore(deps): bump github.com/vbatts/go-mtree from 0.5.0 to 0.5.2 (#1497) dependabot[bot] 2023-01-20 08:50:59 -05:00
  • 27b62ce833
    chore(deps): bump github.com/gookit/color from 1.4.2 to 1.5.2 (#1496) dependabot[bot] 2023-01-20 08:50:37 -05:00
  • 499e7c4e16
    chore(deps): bump github.com/spf13/viper from 1.14.0 to 1.15.0 (#1495) dependabot[bot] 2023-01-20 08:50:19 -05:00
  • 0f75f975c8
    Relax error conditions for catalogers (#1492) Alex Goodman 2023-01-19 19:28:42 -05:00
  • 7427445fe9
    feat: add memcached classifier (#1486) witchcraze 2023-01-20 01:22:11 +09:00
  • 09a5baf523
    chore(deps): bump github.com/spf13/viper from 1.13.0 to 1.14.0 (#1488) dependabot[bot] 2023-01-19 10:39:04 -05:00
  • 33c08c8545
    chore(deps): bump github.com/bmatcuk/doublestar/v4 from 4.0.2 to 4.6.0 (#1489) dependabot[bot] 2023-01-19 10:38:50 -05:00
  • fd002db802
    chore(deps): bump github.com/spf13/cobra from 1.6.0 to 1.6.1 (#1490) dependabot[bot] 2023-01-19 14:16:50 +00:00
  • cb3e4b8e49
    chore(deps): bump github.com/go-test/deep from 1.0.8 to 1.1.0 (#1491) dependabot[bot] 2023-01-19 14:01:33 +00:00
  • 5917f8d8f9
    chore(deps): bump github.com/google/go-containerregistry (#1487) dependabot[bot] 2023-01-19 13:47:36 +00:00
  • 70e6d0f2e3
    chore(deps): bump golang.org/x/net from 0.4.0 to 0.5.0 (#1475) dependabot[bot] 2023-01-18 14:39:50 +00:00
  • 31a763c46d
    chore(deps): bump github.com/adrg/xdg from 0.3.3 to 0.4.0 (#1477) dependabot[bot] 2023-01-18 09:39:35 -05:00
  • ae6c9c2e97
    chore(deps): bump github.com/sergi/go-diff from 1.2.0 to 1.3.1 (#1476) dependabot[bot] 2023-01-18 09:39:15 -05:00
  • f6a0dd33d1
    chore(deps): bump github.com/vifraa/gopom from 0.1.0 to 0.2.1 (#1474) dependabot[bot] 2023-01-18 09:38:30 -05:00
  • b77c104aa6
    chore(deps): bump github/codeql-action from 1 to 2 (#1473) dependabot[bot] 2023-01-18 09:38:06 -05:00
  • 10ca7f56ab
    chore(deps): bump actions/setup-go from 2 to 3 (#1472) dependabot[bot] 2023-01-18 09:37:45 -05:00
  • 6b2dc08ffb
    Add dependabot (#1451) Luca Comellini 2023-01-18 06:29:24 -08:00
  • 03971ace43
    chore: use checkout v3 with new depth (#1471) v0.66.2 Christopher Angelo Phillips 2023-01-17 16:26:39 -05:00
  • 07aee798b0
    chore: use checkout v2 for tag depth (#1470) Christopher Angelo Phillips 2023-01-17 16:03:29 -05:00
  • 6cf668f749
    fix: nil panic in graalvm cataloger (#1468) Keith Zantow 2023-01-17 14:06:24 -05:00
  • 2ec4371c95
    add linter for type assertion checks (#1469) Alex Goodman 2023-01-17 14:00:03 -05:00
  • fc4d28f365
    fix: bump golang.org/x/net to v0.4.0 (#1467) Weston Steimel 2023-01-17 17:02:34 +00:00
  • 5290dfb9c2
    fix: bump golang.org/x/text to v0.3.8 (#1466) Weston Steimel 2023-01-17 15:50:02 +00:00
  • 05611c283d
    bootstrap within composite action (#1461) Alex Goodman 2023-01-17 10:04:22 -05:00
  • 934644232a
    chore: revert GolangBinMetadata name and make analogous GolangModMetadata (#1458) Keith Zantow 2023-01-13 16:46:12 -05:00
  • 641bccc79b
    README: update Nix installation instructions (#1455) Florian Klink 2023-01-13 15:43:25 +00:00
  • ac94bf530c
    fix: update graalvm cataloger to fix panic (#1454) v0.66.1 Keith Zantow 2023-01-12 17:42:13 -05:00
  • e87cfe7319
    chore: remove bumping cosign in go.mod when updating bootstrap tools (#1452) Weston Steimel 2023-01-12 21:21:01 +00:00
  • 260cb4c72d
    feat: Add the origin field to the output format of syftjson (#1327) v0.66.0 Asi Greenholts 2023-01-12 22:03:05 +02:00
  • 85bddaa43d
    chore: update schema (#1449) Keith Zantow 2023-01-12 14:25:47 -05:00
  • a864dc9505
    feat: prefer known CPE vendors over other candidates (#1294) Arnout Engelen 2023-01-12 20:16:53 +01:00
  • 44e8ae2577
    fix: update attestation code to remove library dependencies and shellout for keyless flow (#1442) Christopher Angelo Phillips 2023-01-12 12:22:05 -05:00
  • ac8f72fdd1
    feat: add BeamVM Hex support (#1073) Chapman Pendery 2023-01-12 12:10:46 -05:00
  • e063471c66
    feat: add apache httpd binary classifier (#1448) witchcraze 2023-01-13 00:50:01 +09:00
  • 645debe7a4
    chore: claim artifacthub package ownership from developer-guy (#881) Batuhan Apaydın 2023-01-11 23:25:42 +03:00
  • 4bfb849310
    Parallel package catalog processing (#1355) mikcl 2023-01-11 20:18:02 +00:00
  • d524bd5fc3
    feat: Add php binary catalogers (#1444) witchcraze 2023-01-12 03:46:20 +09:00
  • a8416d674b
    Update syft bootstrap tools to latest versions. (#1443) anchore-actions-token-generator[bot] 2023-01-11 12:50:40 -05:00
  • 725529f43f
    fix: duplicate file in tar archive causes read to fail (#1445) Keith Zantow 2023-01-10 14:55:02 -05:00
  • e480443c8c
    Add support for GraalVM Native Image executables. (#1276) William Blair 2023-01-06 18:31:22 -05:00
  • db386baf81
    Add redis binary classifier (#1438) Benji Visser 2023-01-06 10:50:48 -07:00
  • 795a63f1c9
    docs: add cataloger construction summary (#1434) Christopher Angelo Phillips 2023-01-05 12:03:00 -05:00
  • d4f9993b8d
    chore: update bootstrap tools to latest versions. (#1428) anchore-actions-token-generator[bot] 2023-01-05 10:20:58 -05:00
  • bb6fc6525c
    Add alpine type to purl (#1431) Benji Visser 2023-01-04 17:35:46 -05:00
  • bc1edb9c8a
    adding purl types for binary classifiers (#1435) v0.65.0 Benji Visser 2023-01-04 09:34:37 -07:00
  • 64be0a1072
    chore: refactor basic CPE functionality to its own package (#1436) Keith Zantow 2023-01-04 11:26:28 -05:00
  • e3d6ffd30e
    fix: typo in os.Getwd error message (#1433) Justin Chadwell 2023-01-03 14:56:20 +00:00
  • 8d36b21237
    fix: additional excessive go binary warnings (#1432) Justin Chadwell 2023-01-03 14:54:08 +00:00
  • 6a7d6e6071
    docs: migrate to homebrew-core (#1427) Rui Chen 2023-01-02 08:16:32 -05:00
  • e1e489a284
    fix: unicode output in cyclonedx-json format (#1420) v0.64.0 Keith Zantow 2022-12-23 08:37:47 -05:00
  • b125ea83ba
    fix: excessive go binary warnings (#1424) Keith Zantow 2022-12-23 08:36:49 -05:00
  • 3690f979b3
    feat: update spdx format model to produce valid spdx json documents (#1418) Christopher Angelo Phillips 2022-12-21 15:56:03 -05:00
  • 5dd726fc86
    clean package names in python parsers (#1417) Alex Goodman 2022-12-21 13:31:49 -05:00
  • c8b8b1ca11
    docs: update schema name to 2.3 (#1416) Christopher Angelo Phillips 2022-12-19 21:57:19 -05:00
  • 7b08608adb
    feat: add h1digest when scanning go.mod (#1405) Keith Zantow 2022-12-19 21:18:35 -05:00
  • 82f32c7301
    feat: Add license parsing for java (#1385) dja-fr 2022-12-20 02:10:15 +01:00
  • 4ffbeeeea5
    fix: cyclonedx component type for binaries (#1406) Keith Zantow 2022-12-19 19:49:27 -05:00
  • b1d6dae203
    fix: openjdk detection pattern (#1415) Keith Zantow 2022-12-19 19:49:04 -05:00
  • 0f1e8fca14
    bug: spdx checksum empty array; allow syft to generate SHA1 for spdx-tag-value documents (#1404) Christopher Angelo Phillips 2022-12-19 19:10:35 -05:00
  • 8b38549b79
    Add NetBSD support. (#1412) Thomas Klausner 2022-12-19 21:59:50 +00:00
  • 23a3173c9f
    feat: add catalog delete (#1377) v0.63.0 Christopher Angelo Phillips 2022-12-12 12:55:12 -05:00
  • 17aa8287e6
    docs: remove file classifier (#1397) Keith Zantow 2022-12-08 11:50:29 -05:00
  • 730d3e3187
    chore: update latest cyclonedx library (#1390) Christopher Angelo Phillips 2022-12-08 11:36:08 -05:00
  • 997fbdfcf3
    feat: Add Java binary catalogers (#1392) Keith Zantow 2022-12-08 10:50:28 -05:00
  • 13ceed9336
    chore: Update SPDX license list to 3.19 (#1389) Marc-Etienne Vargenau 2022-12-08 16:29:27 +01:00
  • 668f102340
    fix: add manual vendor/product removal to fix false flags (#1070) Chapman Pendery 2022-12-08 09:57:42 -05:00
  • f1a124209a
    Update Stereoscope to c5ff155d72f166e2332e160a75c3ff2b8e9c7e2e (#1395) anchore-actions-token-generator[bot] 2022-12-08 08:32:49 +00:00
  • 5dbb3fc41d
    chore: fix test busybox image sha (#1393) Keith Zantow 2022-12-07 20:15:39 -05:00
  • 614ea00905
    fix: go version not properly identified in binary (#1384) Keith Zantow 2022-12-02 13:24:36 -05:00
  • 247b054ab5
    Update Stereoscope to 3b80d983223f6e6fc2d33b0ffa003d30268418e9 (#1376) v0.62.3 anchore-actions-token-generator[bot] 2022-11-30 16:11:57 +00:00
  • 9e43725951
    fix: Update node binary package name (#1375) Keith Zantow 2022-11-30 10:30:57 -05:00
  • 4f39287216
    feat: Generic Binary Cataloger (#1336) Keith Zantow 2022-11-29 18:28:10 -05:00
  • 7a69e2129b
    recover from bad parsing of golang binary (#1371) Alex Goodman 2022-11-29 10:56:46 -05:00
  • f6996f7b9a
    Fix parsing of apk databases with large entries (#1365) Dan Luhring 2022-11-29 10:16:36 -05:00
  • bd523bdb5d
    Update syft bootstrap tools to latest versions. (#1369) anchore-actions-token-generator[bot] 2022-11-29 10:13:00 -05:00
  • 0cbd0cc703
    fix: guard for locations < 1 in alpmdb parse (#1366) v0.62.2 Christopher Angelo Phillips 2022-11-28 10:43:18 -05:00
  • b290a445ca
    fix: remove cabal.project.freeze panic on last pkg (#1363) Christopher Angelo Phillips 2022-11-23 17:33:18 -05:00
  • bcfe38c009
    fix: requirements.txt - return unicode only letter/num for version (#1361) Christopher Angelo Phillips 2022-11-22 10:43:05 -05:00
  • 74967a28ea
    Update syft bootstrap tools to latest versions. (#1356) anchore-actions-token-generator[bot] 2022-11-21 09:57:49 -05:00
  • 098e61dcc8
    fix: sort relationships in SPDX output (#1350) v0.62.1 Keith Zantow 2022-11-21 09:26:24 -05:00
  • 0dddf51fd5
    chore: add debug logging for decode errors (#1352) Keith Zantow 2022-11-21 09:26:11 -05:00
  • 04880c06ce
    feat(npm): handle aliases in package-lock.json (#1349) mikcl 2022-11-20 16:32:10 +00:00