Commit Graph

  • 002ec4510a
    chore(deps): update CPE dictionary index (#3935) anchore-actions-token-generator[bot] 2025-05-28 12:45:42 -04:00
  • 684e1e963d
    fix(terraform): parse provider lock entries without constraints (#3934) Thomas Gosteli 2025-05-27 20:55:19 +02:00
  • bbf3bb5856
    fix(relationship): favor real paths over symlinks for ownership by file (#3923) Dan Luhring 2025-05-23 14:33:19 -04:00
  • 31c1be6d4d
    chore(deps): bump modernc.org/sqlite from 1.37.0 to 1.37.1 (#3926) dependabot[bot] 2025-05-22 10:47:26 -04:00
  • 7bfb4c86a6
    fix(dotnet-deps-cataloger): avoid repeated dependency resolution (#3930) v1.26.1 Keith Zantow 2025-05-21 21:28:40 -04:00
  • 18ed8b60f8
    chore(deps): update tools to latest versions (#3921) anchore-actions-token-generator[bot] 2025-05-21 10:56:17 -04:00
  • b5e9f75ef1
    chore(deps): bump github.com/google/go-containerregistry (#3925) dependabot[bot] 2025-05-21 10:55:48 -04:00
  • ac883f52ed
    add cdx group as purl namespace (#3922) v1.26.0 Alex Goodman 2025-05-20 15:56:08 -04:00
  • e23ca43a83
    add PE binary cataloger (#3911) Alex Goodman 2025-05-19 14:17:09 -04:00
  • e841b03219 [wip] remove sqlite import win-sqless-build Alex Goodman 2025-05-19 11:50:45 -04:00
  • b4ca04001c
    chore: update dockerfile base images to latest rolling tags (#3915) Christopher Angelo Phillips 2025-05-19 09:43:14 -04:00
  • 828645ec27
    chore(deps): update CPE dictionary index (#3913) anchore-actions-token-generator[bot] 2025-05-19 09:16:25 -04:00
  • db77b54c01
    finalize go mod ref (#3908) v1.25.1 Alex Goodman 2025-05-16 13:36:26 -04:00
  • 2d4fe513ec
    remove benchmark workflow (#3906) v1.25.0 Alex Goodman 2025-05-16 11:08:43 -04:00
  • e1374f758e
    fix: update license content filtering default case to be 'none' for no content returned Christopher Angelo Phillips 2025-05-16 10:25:15 -04:00
  • 945893847f
    chore(deps): bump github/codeql-action from 3.28.17 to 3.28.18 (#3905) dependabot[bot] 2025-05-16 14:16:11 +00:00
  • 8cbdd38a63
    fix: Make Native Image contains no embedded SBOM Error Discoverable (#3805) sathiya06 2025-05-16 09:54:40 -04:00
  • 8f02bd85f6
    fix: Distinguish openjdk vs jdk when using file source (#3895) Adam McClenaghan 2025-05-16 14:29:53 +01:00
  • 0480b516f6
    chore: fix publishing test fixture images (#3896) Alex Goodman 2025-05-15 14:35:11 -04:00
  • 2a055690e6
    chore: delete unused fixture (#3901) Christopher Angelo Phillips 2025-05-15 13:30:36 -04:00
  • 4f73d35051
    Include default config licenses (#3900) Christopher Angelo Phillips 2025-05-15 12:48:18 -04:00
  • b369b02f4f
    Expose RPM signature information (for RPM DB and RPM archives) (#3179) Ralph Bean 2025-05-15 12:01:00 -04:00
  • 5effed06a8
    chore(deps): bump github.com/mholt/archives from 0.1.1 to 0.1.2 (#3898) dependabot[bot] 2025-05-15 10:23:30 -04:00
  • 5e25d52845
    chore(deps): bump anchore/sbom-action from 0.19.0 to 0.20.0 (#3899) dependabot[bot] 2025-05-15 10:23:20 -04:00
  • a8e5b25632
    Add PHP interpreter + extensions cataloger (#2585) Laurent Goderre 2025-05-15 08:22:50 -04:00
  • 0521ccaf5e
    chore: update fixtures based on CI builds (#3894) Alex Goodman 2025-05-14 17:30:20 -04:00
  • 3c7018a853
    feat: remove full-text before release (#3889) v1.24.0 Christopher Angelo Phillips 2025-05-14 09:12:05 -04:00
  • e5d7760bb8
    feat: improve dpkg cataloger license recognition for "license agreements" (#3888) Christopher Angelo Phillips 2025-05-14 08:41:48 -04:00
  • 175a6719a9
    Add cataloger for Dart pubspec (#3292) Laurent Goderre 2025-05-13 17:51:49 -04:00
  • f77d503892
    detect license ID from full text when incidentally provided as a value (#3876) Christopher Angelo Phillips 2025-05-13 16:37:18 -04:00
  • b4d717fb30
    chore: update mimetype contact info (#3887) Keith Zantow 2025-05-13 13:47:05 -04:00
  • 12d91f47dc
    Add a homebrew cataloger (#3724) Rez Moss 2025-05-13 13:01:41 -04:00
  • de88b973f8
    chore: fix some logging output (#3884) Weston Steimel 2025-05-13 12:15:19 +00:00
  • 59b880f26a
    order locations by container layer order (#3858) Alex Goodman 2025-05-13 00:02:07 -04:00
  • e3e69596bd
    Translate Portage license strings to SPDX expressions (#1763) Alex Goodman 2025-05-12 21:03:51 -04:00
  • 58392a9717
    fix: stop emitting redis redis CPE for PHP PECL redis (#3881) Will Murphy 2025-05-12 16:17:18 -04:00
  • 621d21eb04
    feat: Add PURL list input/output format (#3853) Keith Zantow 2025-05-12 13:33:24 -04:00
  • bea57a4f7d
    chore(deps): update CPE dictionary index (#3877) anchore-actions-token-generator[bot] 2025-05-12 09:56:30 -04:00
  • ff575b3f4d
    chore(deps): update tools to latest versions (#3878) anchore-actions-token-generator[bot] 2025-05-12 09:56:07 -04:00
  • f9d0fa81ab
    do not search binary contents for version for go package (#3874) Alex Goodman 2025-05-09 13:49:17 -04:00
  • abe5e27b4b
    fix: remove race when writing errors in generic cataloger (#3875) Alex Goodman 2025-05-09 13:46:47 -04:00
  • a7816dc9e7
    clear devel version for go packages (#3873) Alex Goodman 2025-05-09 13:36:52 -04:00
  • 0b78186a97
    chore(deps): update tools to latest versions (#3871) anchore-actions-token-generator[bot] 2025-05-09 08:29:20 +00:00
  • 99ef5accc7
    chore(deps): bump actions/setup-go from 5.4.0 to 5.5.0 (#3867) dependabot[bot] 2025-05-08 14:27:08 -04:00
  • d634f1438b
    chore(deps): bump actions/setup-go in /.github/actions/bootstrap (#3868) dependabot[bot] 2025-05-08 14:26:57 -04:00
  • 1574fb20ae
    merge multiple targets for the same dotnet package (#3869) Alex Goodman 2025-05-08 11:28:08 -04:00
  • 00c4a4e72a
    Use package ID from decoded SBOMs when provided (#1872) James Neate 2025-05-08 16:25:30 +01:00
  • 47cc8b58a7 persist artifact ID as supplemental package data preserve-format-object Alex Goodman 2025-05-07 21:51:58 -04:00
  • 39396cfff9
    feat: upgrade base docker image (#3862) bgoareguer 2025-05-07 16:29:48 +02:00
  • 8aaf36b1ad
    chore(deps): bump github.com/github/go-spdx/v2 from 2.3.2 to 2.3.3 (#3863) dependabot[bot] 2025-05-07 10:00:05 -04:00
  • af273002b8
    chore(deps): bump golang.org/x/net from 0.39.0 to 0.40.0 (#3859) dependabot[bot] 2025-05-06 12:12:58 -04:00
  • 6eff158ad3
    chore: update license sort to be stable with contents field (#3860) Christopher Angelo Phillips 2025-05-06 11:45:47 -04:00
  • 7b25ea5eda
    annotate hidden paths in all-layers scope (#3855) Alex Goodman 2025-05-06 09:50:04 -04:00
  • 1ba1186410
    fix: use "contents" field and remove "fullText" license field (#3857) Christopher Angelo Phillips 2025-05-05 17:40:09 -04:00
  • 6db60c5975
    Add deep-squashed scope to annotate all layers where a package exists (#3138) GGMU 2025-05-05 21:35:57 +03:00
  • e13c9e7813
    fix: propagate unarchive error of file source (#3845) Kudryavcev Nikolay 2025-05-05 18:37:47 +03:00
  • d47a6c3a6d
    Improve support for cataloging nix package relationships (#3837) Alex Goodman 2025-05-05 11:35:13 -04:00
  • 7505a04aad
    chore(deps): update tools to latest versions (#3848) anchore-actions-token-generator[bot] 2025-05-05 15:26:14 +00:00
  • f1620b120a
    chore(deps): update CPE dictionary index (#3851) anchore-actions-token-generator[bot] 2025-05-05 15:14:28 +00:00
  • 00f53b1777
    chore: upgrade fixtures to use version 4 lockfile (#3852) Christopher Angelo Phillips 2025-05-05 10:38:23 -04:00
  • 3faf43d592
    chore(deps): bump github/codeql-action from 3.28.16 to 3.28.17 (#3846) dependabot[bot] 2025-05-05 10:23:08 -04:00
  • 6ba087c72c
    fix: Do not use hashes for SPDX license names/expressions (#3844) Christopher Angelo Phillips 2025-05-02 09:34:08 -04:00
  • 94e63eb367
    feat: detect when full license text has been provided and preserve as separate field (#3450) Christopher Angelo Phillips 2025-05-01 15:00:46 -04:00
  • 4999de4114
    chore(deps): bump github.com/Masterminds/semver/v3 from 3.3.0 to 3.3.1 (#3843) dependabot[bot] 2025-05-01 10:06:11 -04:00
  • 9ecfe9a53c
    chore(deps): update tools to latest versions (#3841) anchore-actions-token-generator[bot] 2025-05-01 09:29:19 -04:00
  • baa1080ef6
    Update github.com/Masterminds/semver to v3 (#3836) Alan Pope 2025-04-30 21:38:12 +01:00
  • 529840bfc0
    Add support for PHP Pear (#2775) Laurent Goderre 2025-04-30 16:16:58 -04:00
  • 78ef2cf53b
    fix: Improve detection of erlang binary in alpine Linux (#3839) Oleksandr Vodotiiets 2025-04-30 21:50:12 +03:00
  • 09c3b7cbea
    fix:Resolve ancestral symlinks correctly (#3783) VictorHuu 2025-05-01 02:47:32 +08:00
  • 6dca10fe1f
    chore(deps): update CPE dictionary index (#3834) anchore-actions-token-generator[bot] 2025-04-30 14:40:52 -04:00
  • 1ecf1ce7bf
    chore(deps): update tools to latest versions (#3835) anchore-actions-token-generator[bot] 2025-04-30 14:40:37 -04:00
  • 20ca60de8b
    chore(deps): bump github.com/charmbracelet/bubbletea from 1.3.4 to 1.3.5 (#3838) dependabot[bot] 2025-04-30 14:40:00 -04:00
  • fa599547a3
    fix the fluent-bit regex detection pattern (#3817) VictorHuu 2025-04-25 23:50:45 +08:00
  • 22d8b30813
    chore(deps): bump anchore/sbom-action from 0.18.0 to 0.19.0 (#3832) dependabot[bot] 2025-04-25 11:29:24 -04:00
  • a714fb8391
    chore(deps): update tools to latest versions (#3830) v1.23.1 anchore-actions-token-generator[bot] 2025-04-25 09:59:29 -04:00
  • 03fa142de9
    Resolve owned file paths when searching for overlaps (#3828) Alex Goodman 2025-04-24 17:59:45 -04:00
  • 4211d79667
    chore(deps): update anchore dependencies (#3827) v1.23.0 anchore-actions-token-generator[bot] 2025-04-24 16:03:09 -04:00
  • 9af087d213
    fix: Make the fileresolver Support Prefix Match of Files (#3820) VictorHuu 2025-04-25 01:38:05 +08:00
  • 5c6c6aa123
    Add support for detecting javascript assets in .NET projects using libman (#3825) Alex Goodman 2025-04-24 13:11:01 -04:00
  • 43a85dfb85
    chore(deps): update tools to latest versions (#3823) anchore-actions-token-generator[bot] 2025-04-24 13:08:32 -04:00
  • 61a3d1784a
    (feat): support skipping archive extraction with file source (#3795) Adam McClenaghan 2025-04-24 17:22:36 +01:00
  • df18edf905
    Consider DLL claims for dependencies of .NET packages from deps.json (#3822) Alex Goodman 2025-04-24 11:59:16 -04:00
  • 2dd9d583af
    PE cataloger should consider compile target paths from deps.json (#3821) Alex Goodman 2025-04-24 09:01:53 -04:00
  • f6d4a7d27a
    Perf: skip license scanner injection (#3796) Adam McClenaghan 2025-04-23 21:01:10 +01:00
  • 273d414b6b
    chore(deps): bump sigstore/cosign-installer from 3.8.1 to 3.8.2 (#3818) dependabot[bot] 2025-04-23 11:27:08 -04:00
  • 0a0c2963f4
    chore(deps): bump github/codeql-action from 3.28.15 to 3.28.16 (#3819) dependabot[bot] 2025-04-23 11:25:42 -04:00
  • 1d7529d01f
    chore(deps): update tools to latest versions (#3815) anchore-actions-token-generator[bot] 2025-04-22 13:10:35 -04:00
  • a69f6aec90
    docs: document test commands (#3816) Will Murphy 2025-04-22 10:23:52 -04:00
  • df11561929
    Support detection of Chrome binaries (#3136) Stijn Taelemans 2025-04-21 22:37:15 +02:00
  • ab570497b0
    fix:allow golang tip image detection regex pattern (#3757) VictorHuu 2025-04-22 02:06:52 +08:00
  • ea7e9e696b
    fix:Make the parse of the replace part in ``go.mod`` more compliant and traceable (#3812) VictorHuu 2025-04-22 01:58:54 +08:00
  • 1f15361ecf
    (fix): delete collection name/type key entries when empty (#3797) Adam McClenaghan 2025-04-21 18:41:39 +01:00
  • 0bcf2881c4
    chore(deps): update CPE dictionary index (#3813) anchore-actions-token-generator[bot] 2025-04-21 09:59:06 -04:00
  • b9ae936731
    chore(deps): update tools to latest versions (#3806) anchore-actions-token-generator[bot] 2025-04-17 12:26:29 -04:00
  • e452cc7623
    chore(deps): bump github.com/go-git/go-git/v5 from 5.15.0 to 5.16.0 (#3807) dependabot[bot] 2025-04-17 12:26:18 -04:00
  • b13ffdd304
    fix: comma separated selectors in cataloger list command (#3804) Keith Zantow 2025-04-16 10:41:48 -04:00
  • a5da154327
    chore(deps): bump github.com/anchore/stereoscope from 0.1.2 to 0.1.3 (#3803) dependabot[bot] 2025-04-15 19:31:45 +00:00
  • 1866e25f9a
    chore: fix conan parser typos (#3802) Musang Kim 2025-04-15 23:51:02 +09:00
  • 1e336e3f07
    chore(deps): update tools to latest versions (#3798) anchore-actions-token-generator[bot] 2025-04-14 14:43:53 -04:00
  • eee9d0a41e
    chore(deps): update CPE dictionary index (#3799) anchore-actions-token-generator[bot] 2025-04-14 14:43:25 -04:00