Commit Graph

  • 98e737fc27
    chore: update deprecated release flag (#1629) Christopher Angelo Phillips 2023-02-27 15:57:56 -05:00
  • ff34594284
    chore(deps): bump actions/upload-artifact from 2 to 3 (#1627) dependabot[bot] 2023-02-27 14:17:29 -05:00
  • 9e953b1da3
    feat: add support for SUPPORT_END in /etc/os-release (#1612) Benji Visser 2023-02-27 11:43:19 -07:00
  • fbda21f4f4
    fix: further improvements to CPE generation for apk packages (#1623) Weston Steimel 2023-02-27 18:16:04 +00:00
  • d23b4d4cbd
    chore(deps): bump github.com/stretchr/testify from 1.8.1 to 1.8.2 (#1625) dependabot[bot] 2023-02-27 13:14:20 -05:00
  • f3acff81f3
    chore(deps): bump actions/checkout from 2 to 3 (#1626) dependabot[bot] 2023-02-27 13:14:03 -05:00
  • fa0a9fe8f9
    feat: set cosign attest predicate type based on Syft output type (#1598) Nils Hanke 2023-02-24 21:08:40 +01:00
  • 284bae9d5f
    chore(deps): bump github.com/spf13/afero from 1.9.3 to 1.9.4 (#1609) dependabot[bot] 2023-02-24 15:07:52 -05:00
  • 3ee1af0dc6
    fix: correct apk purls for other distros (#1620) Weston Steimel 2023-02-24 20:07:07 +00:00
  • 0c5f03235e
    refactor: move apk upstream logic to apk metadata (#1619) Weston Steimel 2023-02-24 15:59:19 +00:00
  • 5e8aa4da5e
    fix: decoding null apk metadata pullDependencies (#1614) Keith Zantow 2023-02-23 14:55:49 -05:00
  • abfec62219
    feat: haproxy binary matcher (#1591) Benji Visser 2023-02-23 12:39:08 -07:00
  • 0c05855131
    fix: determine upstream for apk version streams (#1610) Weston Steimel 2023-02-23 17:32:34 +00:00
  • 1150772d06
    fix: improve CPE generation for curl APK (#1608) Weston Steimel 2023-02-23 17:32:12 +00:00
  • be71f7c6ae
    disable changelog, version file updates, brew, and some docker tags on release v0.72.1 Alex Goodman 2023-02-22 16:34:11 -05:00
  • 8220a8731a
    Update SPDX license list to 3.20 (#1600) Marc-Etienne Vargenau 2023-02-21 21:12:28 +01:00
  • 56fdb8d2bf
    chore: update SPDX license list (#1599) Keith Zantow 2023-02-21 12:31:24 -05:00
  • 4011928613
    Update Stereoscope to fab1c9638abc2c21cd53dca1f205f37d71148ee0 (#1604) anchore-actions-token-generator[bot] 2023-02-22 19:08:35 +00:00
  • 669fee84d5
    Revert "add workaround for macos github actions cache issue (#1584)" (#1605) Alex Goodman 2023-02-22 15:03:12 -05:00
  • aa151da5fe
    Update Stereoscope to fab1c9638abc2c21cd53dca1f205f37d71148ee0 (#1604) v0.73.0 anchore-actions-token-generator[bot] 2023-02-22 19:08:35 +00:00
  • 4bf677d555
    chore: fix cataloger_test (#1603) Keith Zantow 2023-02-22 12:30:41 -05:00
  • f5e20521e0
    fix: merging of binary packages (#1583) Keith Zantow 2023-02-22 12:03:15 -05:00
  • 8f6a317fef
    fix: issue when matching format versions (#1585) Keith Zantow 2023-02-22 10:32:05 -05:00
  • d339ffdcb5
    chore: update syft bootstrap tools to latest versions. (#1593) anchore-actions-token-generator[bot] 2023-02-22 10:16:14 -05:00
  • e84ffc6003
    feat: add perl binary classifier (#1592) Benji Visser 2023-02-22 07:58:05 -07:00
  • bb52a25c8a
    Update Stereoscope to 529924d6d5aa6c708cceffc651883b6e1e27f5df (#1602) anchore-actions-token-generator[bot] 2023-02-22 08:49:04 +00:00
  • 4b7b709473
    Update SPDX license list to 3.20 (#1600) Marc-Etienne Vargenau 2023-02-21 21:12:28 +01:00
  • 2ef2eed382
    chore: update SPDX license list (#1599) Keith Zantow 2023-02-21 12:31:24 -05:00
  • f6716092af
    fix cataloger selection to be more specific (#1582) Alex Goodman 2023-02-17 10:35:54 -05:00
  • 0076b19893
    add workaround for macos github actions cache issue (#1584) Alex Goodman 2023-02-17 10:29:33 -05:00
  • 2642a36161
    Update Stereoscope to 4b5ebf8c7f4b81ca79c4c3f0af1d0723eab87d42 (#1576) v0.72.0 anchore-actions-token-generator[bot] 2023-02-16 10:22:43 -05:00
  • 1981b249f1
    chore(deps): bump golang.org/x/net from 0.6.0 to 0.7.0 (#1574) dependabot[bot] 2023-02-15 12:54:55 -05:00
  • a3ebb31e3c
    chore: update bug issue template (#1571) Keith Zantow 2023-02-14 12:58:44 -05:00
  • 9b9a7d6c98
    allow convert to take stdin (#1570) Alex Goodman 2023-02-14 10:03:47 -05:00
  • 57a13ae355
    fix: improve CPE and upstream generation logic for Alpine packages (#1567) Weston Steimel 2023-02-13 17:23:13 +00:00
  • 890fb3f0e8
    fix: missing APK node vulnerabilities (#1565) Keith Zantow 2023-02-10 15:52:13 -05:00
  • e236054668
    fix: python CPE generation for alpine (#1564) Weston Steimel 2023-02-10 18:04:16 +00:00
  • 3013c8b691
    chore(deps): bump github.com/docker/docker (#1563) dependabot[bot] 2023-02-10 10:43:19 -05:00
  • 88c81d33ed
    switch from trigger-release target to release target (#1560) v0.71.0 Alex Goodman 2023-02-09 11:35:11 -05:00
  • 988041ba6d
    Speed up cataloging by replacing globs searching with index lookups (#1510) Alex Goodman 2023-02-09 11:19:47 -05:00
  • 550e2fc7c3
    Update syft bootstrap tools to latest versions. (#1549) anchore-actions-token-generator[bot] 2023-02-09 10:10:35 -05:00
  • 43b53ac173
    Fix installed versions (#1556) witchcraze 2023-02-09 23:03:40 +09:00
  • 08804842fa
    chore(deps): bump golang.org/x/net from 0.5.0 to 0.6.0 (#1558) dependabot[bot] 2023-02-09 09:01:56 -05:00
  • 284814153d
    feat: add postgresql classifier (#1536) witchcraze 2023-02-09 04:31:17 +09:00
  • 8847ba5d0b
    Add release trigger (#1501) Alex Goodman 2023-02-08 11:38:27 -05:00
  • 48528efff3
    chore(deps): bump golang.org/x/mod from 0.7.0 to 0.8.0 (#1552) dependabot[bot] 2023-02-08 10:07:37 -05:00
  • 8d856a7c7b
    chore(deps): bump golang.org/x/term from 0.4.0 to 0.5.0 (#1551) dependabot[bot] 2023-02-08 09:23:31 -05:00
  • 38a090c218
    fix: add support for licenses not found on list (#1540) Avi Deitcher 2023-02-07 18:47:04 +02:00
  • deb7052f41
    Update syft bootstrap tools to latest versions. (#1541) anchore-actions-token-generator[bot] 2023-02-07 15:41:14 +00:00
  • 9650473298
    feat: Allow specific versions of formats to be specified (#1543) Keith Zantow 2023-02-07 10:40:43 -05:00
  • 95201840d2
    Update Stereoscope to c49244e4d66f1ee789027ea23acc746968799c3b (#1539) anchore-actions-token-generator[bot] 2023-02-07 10:05:18 -05:00
  • 6ba595344a
    source: when base is set, responsePath should be absolute (#1542) Justin Chadwell 2023-02-06 17:06:04 +00:00
  • 9995950c70
    fix: update config struct to not decode password/key (#1538) v0.70.0 Christopher Angelo Phillips 2023-02-03 13:06:14 -05:00
  • b6a496f18c
    Update syft bootstrap tools to latest versions. (#1537) anchore-actions-token-generator[bot] 2023-02-03 12:35:33 -05:00
  • 0853a50f4d
    feat: add traefik classifier (#1504) witchcraze 2023-02-03 03:59:26 +09:00
  • a1b82c9664
    fix: don't hardcode Cosign attest type (#1533) Nils Hanke 2023-02-02 18:47:12 +01:00
  • ad8604c223
    chore(deps): bump github.com/docker/docker (#1531) dependabot[bot] 2023-02-02 10:53:22 -05:00
  • d80ee966dc
    Update syft bootstrap tools to latest versions. (#1530) anchore-actions-token-generator[bot] 2023-02-02 08:47:29 -05:00
  • 1530ef354f
    chore: update spdx/tools-golang to v0.5.0-rc1 (#1503) v0.69.1 Keith Zantow 2023-01-31 11:53:16 -05:00
  • cdac2245b5
    feat: update golang to 1.19 (#1526) Bradley Jones 2023-01-31 16:39:57 +00:00
  • 8dba4c33dd
    Update syft bootstrap tools to latest versions. (#1525) anchore-actions-token-generator[bot] 2023-01-31 09:27:38 -05:00
  • b81c9805dc
    Allow scanning unpacked container filesystems (#1485) v0.69.0 Justin Chadwell 2023-01-30 18:47:24 +00:00
  • ba55963104
    fix: allow template for syft convert (#1521) Keith Zantow 2023-01-26 12:07:36 -05:00
  • 8c91605541
    1465 attestation with private key (#1502) Christopher Angelo Phillips 2023-01-26 11:19:13 -05:00
  • 4c0aef09b8
    fix: add relevant CPEs to python and busybox classifiers (#1517) v0.68.1 Weston Steimel 2023-01-25 17:18:24 +00:00
  • 02fb757c21
    Update syft bootstrap tools to latest versions. (#1515) anchore-actions-token-generator[bot] 2023-01-25 10:31:53 -05:00
  • 674a54512c
    chore: correct bootstrap tool script (#1514) Keith Zantow 2023-01-25 10:22:28 -05:00
  • 21ba5d0806
    chore(deps): bump github.com/google/go-containerregistry (#1513) dependabot[bot] 2023-01-25 13:41:43 +00:00
  • 0ba57a5936
    Fix AssertEncoderAgainstGoldenSnapshot calls to conditionally update (#1511) Alex Goodman 2023-01-24 16:41:57 -05:00
  • 3269bc98d4
    chore(deps): bump golang.org/x/mod from 0.6.0 to 0.7.0 (#1505) dependabot[bot] 2023-01-23 15:01:25 -05:00
  • 7f3382f7eb
    chore(deps): bump github.com/docker/docker (#1506) dependabot[bot] 2023-01-23 14:58:39 -05:00
  • 65e5ff63f0
    chore(deps): bump github.com/Masterminds/sprig/v3 from 3.2.2 to 3.2.3 (#1507) dependabot[bot] 2023-01-23 14:48:22 -05:00
  • d287c22b69
    chore(deps): bump github.com/dustin/go-humanize from 1.0.0 to 1.0.1 (#1508) dependabot[bot] 2023-01-23 14:48:00 -05:00
  • e8be93a8eb
    Bump github.com/spdx/tools-golang to v0.4.0 (#1450) Luca Comellini 2023-01-20 14:00:21 -08:00
  • e58050bac0
    Fix panic in apkdb parsing on empty "provides" values (#1494) v0.68.0 Dan Luhring 2023-01-20 09:49:44 -05:00
  • 36a0945c95
    push detailed log statements to trace-level (#1500) Alex Goodman 2023-01-20 09:33:23 -05:00
  • 396441e921
    npm: package-lock license decoding to accept string or array (#1482) mikcl 2023-01-20 14:28:51 +00:00
  • 972e4cdaeb
    always set the package ID for java packages (#1493) Alex Goodman 2023-01-20 09:18:00 -05:00
  • 99f55f6a81
    fix: skip filling in empty fields in APK metadata (#1484) Nils Hanke 2023-01-20 15:03:30 +01:00
  • 285112fe29
    chore(deps): bump github.com/facebookincubator/nvdtools (#1499) dependabot[bot] 2023-01-20 14:02:47 +00:00
  • f29bea5921
    chore(deps): bump github.com/jinzhu/copier from 0.3.2 to 0.3.5 (#1498) dependabot[bot] 2023-01-20 08:51:20 -05:00
  • 39cdbc42aa
    chore(deps): bump github.com/vbatts/go-mtree from 0.5.0 to 0.5.2 (#1497) dependabot[bot] 2023-01-20 08:50:59 -05:00
  • 27b62ce833
    chore(deps): bump github.com/gookit/color from 1.4.2 to 1.5.2 (#1496) dependabot[bot] 2023-01-20 08:50:37 -05:00
  • 499e7c4e16
    chore(deps): bump github.com/spf13/viper from 1.14.0 to 1.15.0 (#1495) dependabot[bot] 2023-01-20 08:50:19 -05:00
  • 0f75f975c8
    Relax error conditions for catalogers (#1492) Alex Goodman 2023-01-19 19:28:42 -05:00
  • 7427445fe9
    feat: add memcached classifier (#1486) witchcraze 2023-01-20 01:22:11 +09:00
  • 09a5baf523
    chore(deps): bump github.com/spf13/viper from 1.13.0 to 1.14.0 (#1488) dependabot[bot] 2023-01-19 10:39:04 -05:00
  • 33c08c8545
    chore(deps): bump github.com/bmatcuk/doublestar/v4 from 4.0.2 to 4.6.0 (#1489) dependabot[bot] 2023-01-19 10:38:50 -05:00
  • fd002db802
    chore(deps): bump github.com/spf13/cobra from 1.6.0 to 1.6.1 (#1490) dependabot[bot] 2023-01-19 14:16:50 +00:00
  • cb3e4b8e49
    chore(deps): bump github.com/go-test/deep from 1.0.8 to 1.1.0 (#1491) dependabot[bot] 2023-01-19 14:01:33 +00:00
  • 5917f8d8f9
    chore(deps): bump github.com/google/go-containerregistry (#1487) dependabot[bot] 2023-01-19 13:47:36 +00:00
  • 70e6d0f2e3
    chore(deps): bump golang.org/x/net from 0.4.0 to 0.5.0 (#1475) dependabot[bot] 2023-01-18 14:39:50 +00:00
  • 31a763c46d
    chore(deps): bump github.com/adrg/xdg from 0.3.3 to 0.4.0 (#1477) dependabot[bot] 2023-01-18 09:39:35 -05:00
  • ae6c9c2e97
    chore(deps): bump github.com/sergi/go-diff from 1.2.0 to 1.3.1 (#1476) dependabot[bot] 2023-01-18 09:39:15 -05:00
  • f6a0dd33d1
    chore(deps): bump github.com/vifraa/gopom from 0.1.0 to 0.2.1 (#1474) dependabot[bot] 2023-01-18 09:38:30 -05:00
  • b77c104aa6
    chore(deps): bump github/codeql-action from 1 to 2 (#1473) dependabot[bot] 2023-01-18 09:38:06 -05:00
  • 10ca7f56ab
    chore(deps): bump actions/setup-go from 2 to 3 (#1472) dependabot[bot] 2023-01-18 09:37:45 -05:00
  • 6b2dc08ffb
    Add dependabot (#1451) Luca Comellini 2023-01-18 06:29:24 -08:00
  • 03971ace43
    chore: use checkout v3 with new depth (#1471) v0.66.2 Christopher Angelo Phillips 2023-01-17 16:26:39 -05:00
  • 07aee798b0
    chore: use checkout v2 for tag depth (#1470) Christopher Angelo Phillips 2023-01-17 16:03:29 -05:00