Commit Graph

  • 0b78186a97
    chore(deps): update tools to latest versions (#3871) anchore-actions-token-generator[bot] 2025-05-09 08:29:20 +00:00
  • 99ef5accc7
    chore(deps): bump actions/setup-go from 5.4.0 to 5.5.0 (#3867) dependabot[bot] 2025-05-08 14:27:08 -04:00
  • d634f1438b
    chore(deps): bump actions/setup-go in /.github/actions/bootstrap (#3868) dependabot[bot] 2025-05-08 14:26:57 -04:00
  • 1574fb20ae
    merge multiple targets for the same dotnet package (#3869) Alex Goodman 2025-05-08 11:28:08 -04:00
  • 00c4a4e72a
    Use package ID from decoded SBOMs when provided (#1872) James Neate 2025-05-08 16:25:30 +01:00
  • 47cc8b58a7 persist artifact ID as supplemental package data preserve-format-object Alex Goodman 2025-05-07 21:51:58 -04:00
  • 39396cfff9
    feat: upgrade base docker image (#3862) bgoareguer 2025-05-07 16:29:48 +02:00
  • 8aaf36b1ad
    chore(deps): bump github.com/github/go-spdx/v2 from 2.3.2 to 2.3.3 (#3863) dependabot[bot] 2025-05-07 10:00:05 -04:00
  • af273002b8
    chore(deps): bump golang.org/x/net from 0.39.0 to 0.40.0 (#3859) dependabot[bot] 2025-05-06 12:12:58 -04:00
  • 6eff158ad3
    chore: update license sort to be stable with contents field (#3860) Christopher Angelo Phillips 2025-05-06 11:45:47 -04:00
  • 7b25ea5eda
    annotate hidden paths in all-layers scope (#3855) Alex Goodman 2025-05-06 09:50:04 -04:00
  • 1ba1186410
    fix: use "contents" field and remove "fullText" license field (#3857) Christopher Angelo Phillips 2025-05-05 17:40:09 -04:00
  • 6db60c5975
    Add deep-squashed scope to annotate all layers where a package exists (#3138) GGMU 2025-05-05 21:35:57 +03:00
  • e13c9e7813
    fix: propagate unarchive error of file source (#3845) Kudryavcev Nikolay 2025-05-05 18:37:47 +03:00
  • d47a6c3a6d
    Improve support for cataloging nix package relationships (#3837) Alex Goodman 2025-05-05 11:35:13 -04:00
  • 7505a04aad
    chore(deps): update tools to latest versions (#3848) anchore-actions-token-generator[bot] 2025-05-05 15:26:14 +00:00
  • f1620b120a
    chore(deps): update CPE dictionary index (#3851) anchore-actions-token-generator[bot] 2025-05-05 15:14:28 +00:00
  • 00f53b1777
    chore: upgrade fixtures to use version 4 lockfile (#3852) Christopher Angelo Phillips 2025-05-05 10:38:23 -04:00
  • 3faf43d592
    chore(deps): bump github/codeql-action from 3.28.16 to 3.28.17 (#3846) dependabot[bot] 2025-05-05 10:23:08 -04:00
  • 6ba087c72c
    fix: Do not use hashes for SPDX license names/expressions (#3844) Christopher Angelo Phillips 2025-05-02 09:34:08 -04:00
  • 94e63eb367
    feat: detect when full license text has been provided and preserve as separate field (#3450) Christopher Angelo Phillips 2025-05-01 15:00:46 -04:00
  • 4999de4114
    chore(deps): bump github.com/Masterminds/semver/v3 from 3.3.0 to 3.3.1 (#3843) dependabot[bot] 2025-05-01 10:06:11 -04:00
  • 9ecfe9a53c
    chore(deps): update tools to latest versions (#3841) anchore-actions-token-generator[bot] 2025-05-01 09:29:19 -04:00
  • baa1080ef6
    Update github.com/Masterminds/semver to v3 (#3836) Alan Pope 2025-04-30 21:38:12 +01:00
  • 529840bfc0
    Add support for PHP Pear (#2775) Laurent Goderre 2025-04-30 16:16:58 -04:00
  • 78ef2cf53b
    fix: Improve detection of erlang binary in alpine Linux (#3839) Oleksandr Vodotiiets 2025-04-30 21:50:12 +03:00
  • 09c3b7cbea
    fix:Resolve ancestral symlinks correctly (#3783) VictorHuu 2025-05-01 02:47:32 +08:00
  • 6dca10fe1f
    chore(deps): update CPE dictionary index (#3834) anchore-actions-token-generator[bot] 2025-04-30 14:40:52 -04:00
  • 1ecf1ce7bf
    chore(deps): update tools to latest versions (#3835) anchore-actions-token-generator[bot] 2025-04-30 14:40:37 -04:00
  • 20ca60de8b
    chore(deps): bump github.com/charmbracelet/bubbletea from 1.3.4 to 1.3.5 (#3838) dependabot[bot] 2025-04-30 14:40:00 -04:00
  • fa599547a3
    fix the fluent-bit regex detection pattern (#3817) VictorHuu 2025-04-25 23:50:45 +08:00
  • 22d8b30813
    chore(deps): bump anchore/sbom-action from 0.18.0 to 0.19.0 (#3832) dependabot[bot] 2025-04-25 11:29:24 -04:00
  • a714fb8391
    chore(deps): update tools to latest versions (#3830) v1.23.1 anchore-actions-token-generator[bot] 2025-04-25 09:59:29 -04:00
  • 03fa142de9
    Resolve owned file paths when searching for overlaps (#3828) Alex Goodman 2025-04-24 17:59:45 -04:00
  • 4211d79667
    chore(deps): update anchore dependencies (#3827) v1.23.0 anchore-actions-token-generator[bot] 2025-04-24 16:03:09 -04:00
  • 9af087d213
    fix: Make the fileresolver Support Prefix Match of Files (#3820) VictorHuu 2025-04-25 01:38:05 +08:00
  • 5c6c6aa123
    Add support for detecting javascript assets in .NET projects using libman (#3825) Alex Goodman 2025-04-24 13:11:01 -04:00
  • 43a85dfb85
    chore(deps): update tools to latest versions (#3823) anchore-actions-token-generator[bot] 2025-04-24 13:08:32 -04:00
  • 61a3d1784a
    (feat): support skipping archive extraction with file source (#3795) Adam McClenaghan 2025-04-24 17:22:36 +01:00
  • df18edf905
    Consider DLL claims for dependencies of .NET packages from deps.json (#3822) Alex Goodman 2025-04-24 11:59:16 -04:00
  • 2dd9d583af
    PE cataloger should consider compile target paths from deps.json (#3821) Alex Goodman 2025-04-24 09:01:53 -04:00
  • f6d4a7d27a
    Perf: skip license scanner injection (#3796) Adam McClenaghan 2025-04-23 21:01:10 +01:00
  • 273d414b6b
    chore(deps): bump sigstore/cosign-installer from 3.8.1 to 3.8.2 (#3818) dependabot[bot] 2025-04-23 11:27:08 -04:00
  • 0a0c2963f4
    chore(deps): bump github/codeql-action from 3.28.15 to 3.28.16 (#3819) dependabot[bot] 2025-04-23 11:25:42 -04:00
  • 1d7529d01f
    chore(deps): update tools to latest versions (#3815) anchore-actions-token-generator[bot] 2025-04-22 13:10:35 -04:00
  • a69f6aec90
    docs: document test commands (#3816) Will Murphy 2025-04-22 10:23:52 -04:00
  • df11561929
    Support detection of Chrome binaries (#3136) Stijn Taelemans 2025-04-21 22:37:15 +02:00
  • ab570497b0
    fix:allow golang tip image detection regex pattern (#3757) VictorHuu 2025-04-22 02:06:52 +08:00
  • ea7e9e696b
    fix:Make the parse of the replace part in ``go.mod`` more compliant and traceable (#3812) VictorHuu 2025-04-22 01:58:54 +08:00
  • 1f15361ecf
    (fix): delete collection name/type key entries when empty (#3797) Adam McClenaghan 2025-04-21 18:41:39 +01:00
  • 0bcf2881c4
    chore(deps): update CPE dictionary index (#3813) anchore-actions-token-generator[bot] 2025-04-21 09:59:06 -04:00
  • b9ae936731
    chore(deps): update tools to latest versions (#3806) anchore-actions-token-generator[bot] 2025-04-17 12:26:29 -04:00
  • e452cc7623
    chore(deps): bump github.com/go-git/go-git/v5 from 5.15.0 to 5.16.0 (#3807) dependabot[bot] 2025-04-17 12:26:18 -04:00
  • b13ffdd304
    fix: comma separated selectors in cataloger list command (#3804) Keith Zantow 2025-04-16 10:41:48 -04:00
  • a5da154327
    chore(deps): bump github.com/anchore/stereoscope from 0.1.2 to 0.1.3 (#3803) dependabot[bot] 2025-04-15 19:31:45 +00:00
  • 1866e25f9a
    chore: fix conan parser typos (#3802) Musang Kim 2025-04-15 23:51:02 +09:00
  • 1e336e3f07
    chore(deps): update tools to latest versions (#3798) anchore-actions-token-generator[bot] 2025-04-14 14:43:53 -04:00
  • eee9d0a41e
    chore(deps): update CPE dictionary index (#3799) anchore-actions-token-generator[bot] 2025-04-14 14:43:25 -04:00
  • a5632c0044
    chore(deps): bump github.com/mholt/archives from 0.1.0 to 0.1.1 (#3778) dependabot[bot] 2025-04-11 14:50:51 -04:00
  • 2a409488a0
    chore(deps): bump marocchino/sticky-pull-request-comment (#3788) dependabot[bot] 2025-04-11 12:43:11 -04:00
  • d145e80c20
    chore(deps): bump github.com/magiconair/properties from 1.8.9 to 1.8.10 (#3789) dependabot[bot] 2025-04-11 12:42:57 -04:00
  • 05de0d2a1b
    chore(deps): bump github.com/charmbracelet/bubbles from 0.20.0 to 0.21.0 (#3790) dependabot[bot] 2025-04-11 12:42:46 -04:00
  • 24df095a5e
    empty source during decoding should not be fatal (#3791) Alex Goodman 2025-04-11 10:12:29 -04:00
  • e7f0a602c2
    chore(deps): bump github.com/go-git/go-git/v5 from 5.14.0 to 5.15.0 (#3792) dependabot[bot] 2025-04-11 10:12:05 -04:00
  • 7c8aad9e1b testing improve-nix-support Alan Pope 2025-04-09 14:54:35 +01:00
  • e73293cd45
    chore(deps): update tools to latest versions (#3785) anchore-actions-token-generator[bot] 2025-04-08 14:03:29 -04:00
  • 3b3943d2d6
    chore(deps): bump github/codeql-action from 3.28.13 to 3.28.15 (#3786) dependabot[bot] 2025-04-08 14:03:06 -04:00
  • 97228af539
    chore(deps): bump golang.org/x/net from 0.38.0 to 0.39.0 (#3787) dependabot[bot] 2025-04-08 14:02:48 -04:00
  • 987ba83674
    chore(deps): update CPE dictionary index (#3782) anchore-actions-token-generator[bot] 2025-04-07 10:01:11 -04:00
  • f11377fe30
    chore(deps): update tools to latest versions (#3775) anchore-actions-token-generator[bot] 2025-04-03 17:35:26 +00:00
  • 12f36420dd
    Parse GitHub actions comments (#3776) Alex Goodman 2025-04-03 10:46:27 -04:00
  • f851085668
    Expand python license scanning to cover unclaimed files (#3779) Alex Goodman 2025-04-03 10:31:02 -04:00
  • da62a82413
    feat: adds the DirectoryTag to the r cataloger (#3774) Christopher Angelo Phillips 2025-04-01 11:46:51 -04:00
  • 9ab83874ed
    chore(deps): update anchore dependencies (#3772) v1.22.0 anchore-actions-token-generator[bot] 2025-04-01 14:09:34 +00:00
  • d033ad7de6
    unpin go version in ci (#3773) Alex Goodman 2025-04-01 09:27:15 -04:00
  • b948f2e254
    chore(deps): bump golang.org/x/net from 0.37.0 to 0.38.0 (#3766) dependabot[bot] 2025-03-31 15:02:30 +00:00
  • 6d792aa9dd
    chore(deps): bump 8398a7/action-slack from 3.16.2 to 3.18.0 (#3767) dependabot[bot] 2025-03-31 10:43:47 -04:00
  • 72a0fa4aa3
    chore(deps): bump modernc.org/sqlite from 1.36.1 to 1.37.0 (#3771) dependabot[bot] 2025-03-31 10:41:53 -04:00
  • ec130b977e
    chore(deps): update CPE dictionary index (#3769) anchore-actions-token-generator[bot] 2025-03-31 11:51:04 +01:00
  • c53f2fbad3
    Better represent .NET runtime packages (#3768) Alex Goodman 2025-03-28 13:36:27 -04:00
  • 40dd5d0bbd
    better .NET cpe generation (#3764) Alex Goodman 2025-03-28 10:58:59 -04:00
  • ad9928cb2a
    Merge the .NET deps.json and PE binary catalogers (#3563) Alex Goodman 2025-03-27 14:38:16 -04:00
  • 4a9437808e
    feat: parallelize catalogers per-file and hash contents in parallel (#3636) Keith Zantow 2025-03-26 11:10:08 -04:00
  • dbe29ed4ab
    chore(deps): bump github/codeql-action from 3.28.12 to 3.28.13 (#3758) dependabot[bot] 2025-03-24 14:28:25 -04:00
  • d0018c921e
    chore(deps): update CPE dictionary index (#3756) anchore-actions-token-generator[bot] 2025-03-24 10:02:21 -04:00
  • 7ac4d91f43
    chore: reformat (#3754) Keith Zantow 2025-03-21 06:13:35 -04:00
  • 410b85e1c9
    chore(deps): update tools to latest versions (#3747) anchore-actions-token-generator[bot] 2025-03-20 10:19:45 -04:00
  • e9b24a29d7
    Remove mitchellh dependencies (#3748) Alex Goodman 2025-03-20 10:19:19 -04:00
  • 35d666b27d
    chore(deps): bump actions/upload-artifact from 4.6.1 to 4.6.2 (#3750) dependabot[bot] 2025-03-20 10:02:50 -04:00
  • b036d75e8a
    chore(deps): bump github.com/docker/docker (#3749) dependabot[bot] 2025-03-20 10:02:35 -04:00
  • f1bc8f8a2a
    chore(deps): bump actions/cache from 4.2.2 to 4.2.3 (#3751) dependabot[bot] 2025-03-20 10:02:21 -04:00
  • e986750cbc
    chore(deps): bump actions/cache in /.github/actions/bootstrap (#3752) dependabot[bot] 2025-03-20 10:02:05 -04:00
  • 5fa8e9c6e9
    feat: add Debian archive (.deb) file cataloger (#3704) Alan Pope 2025-03-19 20:03:21 +00:00
  • be0959cabf
    chore(deps): bump actions/setup-go in /.github/actions/bootstrap (#3742) dependabot[bot] 2025-03-19 13:46:54 -04:00
  • 78dc6f7546
    chore(deps): bump actions/setup-go from 5.3.0 to 5.4.0 (#3743) dependabot[bot] 2025-03-19 13:46:51 -04:00
  • 071948f58e
    chore(deps): bump github/codeql-action from 3.28.11 to 3.28.12 (#3744) dependabot[bot] 2025-03-19 13:46:47 -04:00
  • 710f876d86
    chore(deps): bump github.com/BurntSushi/toml from 1.4.0 to 1.5.0 (#3740) dependabot[bot] 2025-03-19 09:29:47 -04:00
  • 8d798134c2
    chore(deps): bump github.com/containerd/containerd from 1.7.26 to 1.7.27 (#3738) dependabot[bot] 2025-03-19 09:29:36 -04:00
  • 8fb32dfc13
    chore(deps): update tools to latest versions (#3739) anchore-actions-token-generator[bot] 2025-03-19 08:32:30 -04:00
  • 2738291a96
    swap centos images for rocky (#3741) Alex Goodman 2025-03-18 10:25:03 -04:00