Commit Graph

  • 7f5dbf9872
    chore: bump stereoscope to v0.0.13 (#3601) Christopher Angelo Phillips 2025-01-21 15:50:42 -05:00
  • c10e904c28
    feat(cataloger): add a terraform provider cataloger (#3378) Thomas Gosteli 2025-01-21 20:44:54 +01:00
  • 1906c179d0
    chore(deps): update tools to latest versions (#3597) anchore-actions-token-generator[bot] 2025-01-21 11:44:27 -05:00
  • 4edfa4d138
    chore(deps): update CPE dictionary index (#3599) anchore-actions-token-generator[bot] 2025-01-21 11:43:59 -05:00
  • a6557d7cec
    chore(deps): bump actions/setup-go from 5.2.0 to 5.3.0 (#3600) dependabot[bot] 2025-01-21 11:41:53 -05:00
  • bd131d78f1 [wip] add elf note dependencies add-elf-note-dependencies Alex Goodman 2025-01-17 22:16:32 -05:00
  • 19a75fe504
    feat(golang): add license parsing from vendor dirs (#3522) Dominik Schmidt 2025-01-18 02:25:05 +01:00
  • 8198a706d6
    chore: bump packageurl-go with new parsing rules (#3596) Christopher Angelo Phillips 2025-01-17 16:20:14 -05:00
  • 254a915592
    chore(deps): bump marocchino/sticky-pull-request-comment (#3595) dependabot[bot] 2025-01-17 13:57:21 -05:00
  • 512319337f
    feat: add cataloger for NuGet packages (#3484) Bert Coppens 2025-01-16 20:57:17 +01:00
  • 6b2d73d4b7
    allow disabling all package catalogers (#3468) GGMU 2025-01-16 20:03:54 +02:00
  • c359c76934
    chore(deps): bump github.com/google/go-containerregistry (#3592) dependabot[bot] 2025-01-16 12:19:26 -05:00
  • 06a22dd4dc
    chore(deps): bump modernc.org/sqlite from 1.34.4 to 1.34.5 (#3593) dependabot[bot] 2025-01-16 12:19:19 -05:00
  • 63a026eb8f
    chore(deps): update tools to latest versions (#3582) anchore-actions-token-generator[bot] 2025-01-15 17:13:17 -05:00
  • 436b36916d
    chore: update README.md's link to Nixpkgs (#3578) Alex Mason 2025-01-16 04:56:11 +11:00
  • 453b187ca1
    chore(deps): bump github.com/sanity-io/litter from 1.5.5 to 1.5.6 (#3579) dependabot[bot] 2025-01-15 12:42:13 -05:00
  • 86ad570f8d
    chore(deps): bump github.com/spf13/afero from 1.11.0 to 1.12.0 (#3580) dependabot[bot] 2025-01-15 12:41:59 -05:00
  • 2f08d60ba3
    chore(deps): bump actions/upload-artifact from 4.5.0 to 4.6.0 (#3581) dependabot[bot] 2025-01-15 12:41:07 -05:00
  • da62caee3d
    chore(deps): update CPE dictionary index (#3583) anchore-actions-token-generator[bot] 2025-01-15 12:11:46 -05:00
  • 2220d708a5
    chore(deps): bump github/codeql-action from 3.28.0 to 3.28.1 (#3584) dependabot[bot] 2025-01-15 12:05:19 -05:00
  • 1a9af0db96
    chore(deps): bump github.com/go-git/go-billy/v5 from 5.6.1 to 5.6.2 (#3585) dependabot[bot] 2025-01-14 10:57:33 -05:00
  • b79f9330fc
    chore(deps): bump github.com/bmatcuk/doublestar/v4 from 4.7.1 to 4.8.0 (#3586) dependabot[bot] 2025-01-14 10:55:48 -05:00
  • fbfad5ef35
    chore(deps): bump github.com/docker/docker (#3587) dependabot[bot] 2025-01-14 10:55:38 -05:00
  • b4e7b64d5c
    chore(deps): update anchore dependencies (#3571) anchore-actions-token-generator[bot] 2025-01-08 17:51:48 +00:00
  • b3fc7b3b0a
    chore(deps): update tools to latest versions (#3567) anchore-actions-token-generator[bot] 2025-01-07 11:30:26 -05:00
  • df36303df0
    chore(deps): bump golang.org/x/net from 0.33.0 to 0.34.0 (#3568) dependabot[bot] 2025-01-07 11:29:58 -05:00
  • a2a56dd3e9
    fix: golang remote license search not executing when error reading local mod dir (#3549) Keith Zantow 2025-01-06 11:47:55 -05:00
  • 2a8c8ac832
    chore(deps): update tools to latest versions (#3564) anchore-actions-token-generator[bot] 2025-01-06 11:15:36 -05:00
  • dc01c5d052
    chore(deps): update CPE dictionary index (#3565) anchore-actions-token-generator[bot] 2025-01-06 11:15:13 -05:00
  • a95244aace
    chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.7 to 0.5.8 (#3548) dependabot[bot] 2025-01-03 15:23:57 +00:00
  • 5c429ae834
    chore(deps): update tools to latest versions (#3560) anchore-actions-token-generator[bot] 2025-01-03 10:12:02 -05:00
  • 463a8f3661
    chore(deps): bump github.com/go-git/go-git/v5 from 5.13.0 to 5.13.1 (#3561) dependabot[bot] 2025-01-03 10:11:30 -05:00
  • cbce129bb9
    Use reader when scanning for package versions over reading entire binary into memory (#3558) Alex Goodman 2025-01-02 17:12:37 -05:00
  • 470c2ff04c
    chore(deps): bump github.com/go-git/go-billy/v5 from 5.6.0 to 5.6.1 (#3551) dependabot[bot] 2025-01-02 21:52:01 +00:00
  • 1f4a48c3c1
    chore(deps): update tools to latest versions (#3556) anchore-actions-token-generator[bot] 2025-01-02 16:18:47 -05:00
  • f9ffe7252e
    test: removes latest license list test (#3559) Christopher Angelo Phillips 2025-01-02 15:56:44 -05:00
  • 286182a66f
    chore(deps): bump peter-evans/create-pull-request from 7.0.5 to 7.0.6 (#3547) dependabot[bot] 2025-01-02 12:26:49 -05:00
  • 5c47568362
    chore(deps): update CPE dictionary index (#3550) anchore-actions-token-generator[bot] 2025-01-02 09:25:13 -05:00
  • 52d904363c
    chore(deps): bump github.com/go-git/go-git/v5 from 5.12.0 to 5.13.0 (#3552) dependabot[bot] 2025-01-02 09:24:40 -05:00
  • 25792160fb
    chore(deps): update tools to latest versions (#3543) anchore-actions-token-generator[bot] 2024-12-23 11:32:17 -05:00
  • 453c429c5c
    chore(deps): update CPE dictionary index (#3544) anchore-actions-token-generator[bot] 2024-12-23 09:37:58 -05:00
  • 13e32d3a49
    chore(deps): bump modernc.org/sqlite from 1.34.3 to 1.34.4 (#3545) dependabot[bot] 2024-12-23 09:36:57 -05:00
  • 03dbd38d88
    chore(deps): bump github/codeql-action from 3.27.9 to 3.28.0 (#3546) dependabot[bot] 2024-12-23 09:36:46 -05:00
  • a185acdc43
    chore(deps): bump golang.org/x/net from 0.32.0 to 0.33.0 (#3541) dependabot[bot] 2024-12-19 11:15:20 -05:00
  • 4822950b06
    chore(deps): bump modernc.org/sqlite from 1.34.2 to 1.34.3 (#3542) dependabot[bot] 2024-12-19 11:15:10 -05:00
  • 2c10b602f0
    chore(deps): bump actions/upload-artifact from 4.4.3 to 4.5.0 (#3537) dependabot[bot] 2024-12-18 13:34:38 -05:00
  • 5120651285
    chore(deps): bump github.com/docker/docker (#3538) dependabot[bot] 2024-12-18 13:34:24 -05:00
  • 397eb9c10a
    chore(deps): update CPE dictionary index (#3526) anchore-actions-token-generator[bot] 2024-12-16 10:37:35 -05:00
  • adfb6656fd
    chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.9.1 to 0.9.2 (#3530) dependabot[bot] 2024-12-16 10:37:19 -05:00
  • 952837dd25
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.4 to 6.6.5 (#3531) dependabot[bot] 2024-12-16 09:29:51 -05:00
  • 4ac8439115
    chore(deps): bump anchore/sbom-action from 0.17.8 to 0.17.9 (#3532) dependabot[bot] 2024-12-16 09:29:08 -05:00
  • 5e16e5031a
    chore(deps): update anchore dependencies (#3525) v1.18.1 anchore-actions-token-generator[bot] 2024-12-13 13:30:11 -05:00
  • 36016a0c5f
    chore(deps): bump github/codeql-action from 3.27.7 to 3.27.9 (#3524) dependabot[bot] 2024-12-13 10:38:58 -05:00
  • 8dcb495312
    chore(deps): bump golang.org/x/crypto from 0.30.0 to 0.31.0 (#3523) dependabot[bot] 2024-12-12 15:43:40 -05:00
  • 02f9350fa5
    chore(deps): bump actions/setup-go from 5.1.0 to 5.2.0 (#3519) dependabot[bot] 2024-12-11 13:14:55 -05:00
  • 20fb9cc00c
    chore(deps): bump actions/checkout from 4.2.1 to 4.2.2 (#3518) dependabot[bot] 2024-12-11 13:14:25 -05:00
  • 6deb41c458
    chore: make fixes field in PR template match auto-close regex (#3520) William Murphy 2024-12-11 12:37:55 -05:00
  • 445142886e
    fix: stop omitting redundantly parenthesized licenses in CDX formatter (#3517) William Murphy 2024-12-11 10:06:08 -05:00
  • 561ed50c2d
    chore: migrate syft to use the anchore fork of archiver without replace (#3516) Christopher Angelo Phillips 2024-12-10 13:33:24 -05:00
  • d77e78ea9d
    Make pre-release integration PRs (#3370) Alex Goodman 2024-12-10 12:14:11 -05:00
  • 0f9d2e5311
    chore(deps): bump github.com/docker/docker (#3512) dependabot[bot] 2024-12-10 10:49:17 -05:00
  • 0dc74a3c37
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.3 to 6.6.4 (#3513) dependabot[bot] 2024-12-10 10:49:05 -05:00
  • 37957b895e
    chore(deps): bump github/codeql-action from 3.27.6 to 3.27.7 (#3514) dependabot[bot] 2024-12-10 10:48:52 -05:00
  • d38efb0b7f
    chore(deps): update anchore dependencies (#3510) v1.18.0 Alex Goodman 2024-12-09 15:51:16 -05:00
  • f9e320c5b7
    fix: convert file paths for spdx formats from absolute to relative (#3509) Christopher Angelo Phillips 2024-12-09 13:02:54 -05:00
  • cd0900e758
    chore(deps): update CPE dictionary index (#3507) anchore-actions-token-generator[bot] 2024-12-09 09:54:52 -05:00
  • 064a9712ac
    chore(deps): update tools to latest versions (#3506) anchore-actions-token-generator[bot] 2024-12-09 09:54:48 -05:00
  • c43c9df1ba
    chore(deps): bump github.com/magiconair/properties from 1.8.7 to 1.8.9 (#3508) dependabot[bot] 2024-12-09 09:54:12 -05:00
  • 4015f40982
    chore(deps): bump actions/cache from 4.1.2 to 4.2.0 (#3503) dependabot[bot] 2024-12-06 15:29:44 -05:00
  • 340b5e17f0
    Add relationships for rust audit binary packages (#3500) Alex Goodman 2024-12-06 09:23:18 -05:00
  • 4adb56d2fe
    fix order of rust dependencies and support git sources in Cargo.lock dependencies (#3502) William Murphy 2024-12-06 08:38:36 -05:00
  • d3c9ce532d
    chore(deps): update tools to latest versions (#3501) anchore-actions-token-generator[bot] 2024-12-06 08:36:54 -05:00
  • 5e22251c86
    chore(deps): bump golang.org/x/net from 0.31.0 to 0.32.0 (#3499) dependabot[bot] 2024-12-05 11:36:33 -05:00
  • 02b7c959c7 redefine unknown dependency completeness enum note-dep-quality Alex Goodman 2024-12-05 09:47:02 -05:00
  • 25e5d555ef
    chore: add and document target for updating unit snapshots (#3498) William Murphy 2024-12-04 15:21:07 -05:00
  • 48190233f4
    fix: emit NOASSERTION for copyright text to fix SPDX 2.2 validation failure (#3495) Christopher Angelo Phillips 2024-12-04 14:58:36 -05:00
  • 3508e648af
    chore(deps): update tools to latest versions (#3496) anchore-actions-token-generator[bot] 2024-12-04 10:01:21 -05:00
  • 1af70d766d
    chore(deps): update tools to latest versions (#3487) anchore-actions-token-generator[bot] 2024-12-03 11:04:44 -05:00
  • 0c3fa82952
    chore(deps): bump github/codeql-action from 3.27.5 to 3.27.6 (#3494) dependabot[bot] 2024-12-03 11:04:28 -05:00
  • c3619422bb
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.2 to 6.6.3 (#3489) dependabot[bot] 2024-12-02 16:30:09 +00:00
  • 59e943385d
    feat: set max layer size (#3464) GGMU 2024-12-02 18:29:42 +02:00
  • 0e880e83e6
    chore(deps): update CPE dictionary index (#3491) anchore-actions-token-generator[bot] 2024-12-02 11:14:28 -05:00
  • 74d58024f6
    chore(deps): bump modernc.org/sqlite from 1.34.1 to 1.34.2 (#3492) dependabot[bot] 2024-12-02 10:47:33 -05:00
  • a0a62931c8
    chore(deps): bump github.com/saferwall/pe from 1.5.5 to 1.5.6 (#3493) dependabot[bot] 2024-12-02 10:47:21 -05:00
  • a320cf76a4
    chore(deps): update tools to latest versions (#3478) anchore-actions-token-generator[bot] 2024-11-27 10:17:54 -05:00
  • ec5f3169db
    chore(deps): update CPE dictionary index (#3479) anchore-actions-token-generator[bot] 2024-11-27 10:17:34 -05:00
  • bbc292ecc0
    chore(deps): bump github.com/stretchr/testify from 1.9.0 to 1.10.0 (#3480) dependabot[bot] 2024-11-27 10:17:19 -05:00
  • b8d3dd3039
    chore(deps): bump github.com/charmbracelet/bubbletea from 1.2.3 to 1.2.4 (#3482) dependabot[bot] 2024-11-27 10:17:10 -05:00
  • 9f1e91e72e
    chore(deps): update stereoscope to be5deed44b7c03fcbfa6f1f42fb67202d31636a9 (#3483) anchore-actions-token-generator[bot] 2024-11-27 10:17:00 -05:00
  • b64213109a rename mixed enum and fix golang Alex Goodman 2024-11-22 17:25:29 -05:00
  • 2118295f19
    fix: dart classifier for 2.x and ARM (#3475) witchcraze 2024-11-23 03:05:09 +09:00
  • 21df38798e
    Use file indexer directly when scanning with file source (#3333) Adam McClenaghan 2024-11-22 16:53:53 +00:00
  • 8abd97a5bf
    chore(deps): bump anchore/sbom-action from 0.17.7 to 0.17.8 (#3476) dependabot[bot] 2024-11-22 11:18:05 -05:00
  • 05c09fd73d
    chore(deps): bump github/codeql-action from 3.27.4 to 3.27.5 (#3473) dependabot[bot] 2024-11-21 15:14:27 -05:00
  • a8d4202d77
    chore(deps): update stereoscope to aa3a3ef4efe8d8759c9aa87261b405cc003bfc9a (#3472) v1.17.0 anchore-actions-token-generator[bot] 2024-11-21 14:28:51 +00:00
  • 19a30b9fd2
    chore(deps): bump github.com/charmbracelet/bubbletea from 1.2.2 to 1.2.3 (#3467) dependabot[bot] 2024-11-20 08:32:30 -05:00
  • e65fe243bf
    fix: bump clio to pull in logging fix (#3466) William Murphy 2024-11-19 14:56:53 -05:00
  • f4cad63da1
    3122 valid license url characters (#3449) Christopher Angelo Phillips 2024-11-19 10:34:58 -05:00
  • e7b65c2c58
    3030 license declared spdx correction (#3461) Christopher Angelo Phillips 2024-11-19 10:00:59 -05:00
  • 8aef0c908a
    chore(deps): update tools to latest versions (#3463) anchore-actions-token-generator[bot] 2024-11-19 09:36:46 -05:00