Commit Graph

  • e962c10da7
    fix: improve go binary semver extraction for traefik (#3325) Weston Steimel 2024-10-14 13:41:34 +00:00
  • 8095f7b8c1
    chore(deps): update stereoscope to 92e97a1cf36d162bad51ccc6aba0cce7a4dcfbf4 (#3322) anchore-actions-token-generator[bot] 2024-10-13 10:53:58 -04:00
  • 84877369e5
    chore(deps): update stereoscope to c04af061af62ab3ba6ab6760613526eaa7fcb163 (#3319) anchore-actions-token-generator[bot] 2024-10-11 12:30:20 -04:00
  • 6124d72a29
    chore(deps): bump github.com/bmatcuk/doublestar/v4 from 4.6.1 to 4.7.0 (#3321) dependabot[bot] 2024-10-11 10:09:14 -04:00
  • c2c8c793d2
    chore(deps): bump actions/upload-artifact from 4.4.1 to 4.4.3 (#3314) dependabot[bot] 2024-10-11 05:17:35 -04:00
  • fbff87fc6d
    shorten release docs (#3318) Alex Goodman 2024-10-11 05:17:01 -04:00
  • 0c71bf23c5
    docs: clearer deprecation message for --file (#3310) William Murphy 2024-10-10 13:11:45 -04:00
  • b62b0cb800
    [docs] Add mastodon link to README.md (#3306) Alan Pope 2024-10-10 15:28:55 +01:00
  • 223a52d07e
    chore(deps): update stereoscope to 5bc91bf166769e43d8d0f86c02e877c55eb04aed (#3313) anchore-actions-token-generator[bot] 2024-10-10 06:03:55 -04:00
  • 5d068f30c0
    chore(deps): bump actions/cache from 4.1.0 to 4.1.1 (#3312) dependabot[bot] 2024-10-10 06:01:06 -04:00
  • 5d165e0230
    chore(deps): bump github/codeql-action from 3.26.11 to 3.26.12 (#3307) dependabot[bot] 2024-10-09 08:07:36 -04:00
  • 56ed131247
    chore(deps): bump actions/checkout from 4.2.0 to 4.2.1 (#3308) dependabot[bot] 2024-10-09 08:07:14 -04:00
  • 37c179b530
    chore(deps): bump actions/upload-artifact from 4.4.0 to 4.4.1 (#3309) dependabot[bot] 2024-10-09 08:06:49 -04:00
  • a3bd5145d2 wire up bitnami cataloger to run on images by default spike-bitnami-cataloger Will Murphy 2024-10-08 14:14:23 -04:00
  • 6a33b80048 prototype: start bitnami cataloger Will Murphy 2024-10-08 09:31:33 -04:00
  • ccbee94b87
    feat: report unknowns in sbom (#2998) v1.14.0 Keith Zantow 2024-10-07 16:11:37 -04:00
  • 4d7ed9f749
    chore(deps): bump sigstore/cosign-installer from 3.6.0 to 3.7.0 (#3299) dependabot[bot] 2024-10-07 15:21:34 -04:00
  • 4c4e5cb06c
    chore(deps): update stereoscope to efa76446cc1c7e6c4117350943a2754b2453aec4 (#3301) anchore-actions-token-generator[bot] 2024-10-07 15:21:26 -04:00
  • 8b6159dbd8
    chore(deps): bump golang.org/x/net from 0.29.0 to 0.30.0 (#3304) dependabot[bot] 2024-10-07 15:20:38 -04:00
  • 7b30ce15d7
    chore(deps): bump actions/cache from 4.0.2 to 4.1.0 (#3305) dependabot[bot] 2024-10-07 15:20:29 -04:00
  • 27ee203495
    chore(deps): update CPE dictionary index (#3302) anchore-actions-token-generator[bot] 2024-10-07 15:20:12 -04:00
  • 3b9c55d28b
    Fix: Parse package.json with non-standard fields in 'author' section (#3300) Piotr Radkowski 2024-10-07 16:26:04 +02:00
  • 25f5c6729f
    chore(deps): bump github/codeql-action from 3.26.10 to 3.26.11 (#3298) dependabot[bot] 2024-10-05 09:25:01 -04:00
  • 0d457142cc
    chore: add pull request template (#3294) William Murphy 2024-10-05 09:05:11 -04:00
  • fc8457418a
    chore(deps): update tools to latest versions (#3296) anchore-actions-token-generator[bot] 2024-10-05 07:32:32 -04:00
  • 13c6876906
    Track supporting DPKG evidence (#3228) Alex Goodman 2024-10-04 11:07:29 -04:00
  • 770fdc53ea
    Fix: make failed CPE validation correctly return error (#2762) William Murphy 2024-10-03 16:42:57 -04:00
  • 32c0d1e673
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.5.9 to 6.6.0 (#3293) dependabot[bot] 2024-10-03 10:14:13 -04:00
  • 263ea6b1bb
    feat: update haproxy classifier (#3277) witchcraze 2024-10-03 04:10:39 +09:00
  • cc4f62b3d4
    chore(deps): update tools to latest versions (#3291) anchore-actions-token-generator[bot] 2024-10-02 09:07:25 -04:00
  • dbad17de9e
    fix: don't use builtin scanner in licensecheck (#3290) Niv Govrin 2024-10-01 20:53:54 +03:00
  • 93beceb4a2
    chore(deps): update CPE dictionary index (#3288) anchore-actions-token-generator[bot] 2024-10-01 10:50:15 -04:00
  • 9b242b0309
    chore(deps): bump github/codeql-action from 3.26.9 to 3.26.10 (#3289) dependabot[bot] 2024-10-01 10:48:46 -04:00
  • edd910f88f [wip] more concurrent catalogers more-concurrent-catalogers Alex Goodman 2024-10-01 10:18:44 -04:00
  • f5f8005fe0
    update redis classifier (#3281) witchcraze 2024-10-01 04:37:47 +09:00
  • 2a3d171c10
    fix: improve node classifier version matching (#3284) witchcraze 2024-09-27 21:53:35 +09:00
  • 1a746b2c05
    fix: update ruby classifier for -rc, -dev, etc. versions (#3285) witchcraze 2024-09-27 21:51:50 +09:00
  • e37c4686c2
    chore(deps): update CPE dictionary index (#3262) anchore-actions-token-generator[bot] 2024-09-26 13:49:18 -04:00
  • 5393cd5dec
    chore(deps): bump github.com/docker/docker (#3264) dependabot[bot] 2024-09-26 13:49:02 -04:00
  • f9ef9cf1dc
    chore(deps): bump github/codeql-action from 3.26.8 to 3.26.9 (#3275) dependabot[bot] 2024-09-26 13:48:45 -04:00
  • 16122eb32d
    chore(deps): update stereoscope to dc10ea61fd18efa45b516eda4de8bc19d8322429 (#3280) anchore-actions-token-generator[bot] 2024-09-26 13:48:33 -04:00
  • 39b2bf5518
    chore(deps): bump actions/checkout from 4.1.7 to 4.2.0 (#3283) dependabot[bot] 2024-09-26 13:48:12 -04:00
  • d7005d7d8c
    add awaiting response management (#3272) Alex Goodman 2024-09-25 08:56:21 -04:00
  • 92c1ddec5a
    fix: correct excluded mount point comparison to file paths (#3269) Christian Dupuis 2024-09-24 23:05:16 +02:00
  • 01de99b253
    Add JVM cataloger (#3217) v1.13.0 1.13.x Alex Goodman 2024-09-23 17:21:38 -04:00
  • 7815d8e4d9
    feat: classifier for Dart lang binaries (#3265) Laurent Goderre 2024-09-23 14:21:31 -04:00
  • 963ea594c8
    Add compliance policy for empty name and version (#3257) Alex Goodman 2024-09-20 12:50:47 -04:00
  • 60bbd24031
    chore(deps): bump github.com/github/go-spdx/v2 from 2.3.1 to 2.3.2 (#3254) dependabot[bot] 2024-09-20 10:50:16 -04:00
  • 7c12e3f3b3
    chore(deps): bump peter-evans/create-pull-request from 7.0.3 to 7.0.5 (#3255) dependabot[bot] 2024-09-20 10:50:03 -04:00
  • 9b5cf1db51
    chore(deps): bump github/codeql-action from 3.26.7 to 3.26.8 (#3256) dependabot[bot] 2024-09-20 10:49:55 -04:00
  • a08ea86aa6
    chore(deps): update tools to latest versions (#3259) anchore-actions-token-generator[bot] 2024-09-20 10:49:37 -04:00
  • 98c96ce361
    chore(deps): bump github.com/docker/docker (#3260) dependabot[bot] 2024-09-20 10:49:22 -04:00
  • 6a95a5f2ed
    feat: add binary classifiers for lighttp, proftpd, zstd, xz, gzip, jq, and sqlcipher (#3252) Krystian G. 2024-09-19 15:21:02 +02:00
  • cb0de97bc3
    fix: capture-snippet.sh can handle leading whitespaces now (#3249) (#3250) Krystian G. 2024-09-19 15:15:54 +02:00
  • 50016c3172
    chore(deps): update tools to latest versions (#3251) anchore-actions-token-generator[bot] 2024-09-19 09:15:12 -04:00
  • a2f12fef0c
    chore(deps): update tools to latest versions (#3247) anchore-actions-token-generator[bot] 2024-09-18 13:13:24 -04:00
  • 7934696463
    chore(deps): update tools to latest versions (#3243) anchore-actions-token-generator[bot] 2024-09-17 12:30:07 -04:00
  • b9efac4d78
    chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.9.0 to 0.9.1 (#3242) dependabot[bot] 2024-09-16 11:54:12 -04:00
  • 48c1c45d12
    chore(deps): bump github/codeql-action from 3.26.6 to 3.26.7 (#3241) dependabot[bot] 2024-09-16 11:54:01 -04:00
  • 9cc3641ac6
    chore(deps): bump peter-evans/create-pull-request from 7.0.2 to 7.0.3 (#3240) dependabot[bot] 2024-09-16 11:53:51 -04:00
  • 7b4feb7c16
    chore(deps): update tools to latest versions (#3231) anchore-actions-token-generator[bot] 2024-09-16 09:09:11 -04:00
  • 41e9630409
    chore(deps): update CPE dictionary index (#3232) anchore-actions-token-generator[bot] 2024-09-16 09:08:50 -04:00
  • 58100fec9f
    chore(deps): update tools to latest versions (#3205) anchore-actions-token-generator[bot] 2024-09-13 15:05:50 -04:00
  • 834027e32d
    chore(deps): bump github.com/charmbracelet/bubbletea from 1.1.0 to 1.1.1 (#3225) dependabot[bot] 2024-09-13 13:51:17 -04:00
  • 2b4d5c275f
    chore(deps): bump peter-evans/create-pull-request from 7.0.1 to 7.0.2 (#3226) dependabot[bot] 2024-09-13 11:31:09 -04:00
  • 38e51f16ec
    chore(deps): bump modernc.org/sqlite from 1.33.0 to 1.33.1 (#3229) dependabot[bot] 2024-09-13 11:30:58 -04:00
  • 1b863268df
    feat: --enrich flag for data enrichment feature enablement (#3182) Keith Zantow 2024-09-12 10:45:18 -04:00
  • fcd5ec951d
    chore: make ci-check.sh an executable file (#3220) v1.12.2 Ryuichi Okumura 2024-09-11 23:02:37 +09:00
  • 362de2f3b6
    chore: ci-check.sh script +x chore/ci-check-permissions Keith Zantow 2024-09-11 09:59:02 -04:00
  • 61a9fde01c
    chore(deps): bump github.com/opencontainers/runc from 1.1.12 to 1.1.14 (#3219) dependabot[bot] 2024-09-10 21:20:43 +00:00
  • c33a51d3d8
    chore: restore ci-check.sh script (#3218) v1.12.1 Keith Zantow 2024-09-10 15:19:05 -04:00
  • dbc4238f63
    Add haskell binaries cataloger (#3078) v1.12.0 Laurent Goderre 2024-09-10 10:58:20 -04:00
  • fce14fd537
    chore(deps): update CPE dictionary index (#3206) anchore-actions-token-generator[bot] 2024-09-10 10:36:50 -04:00
  • 98bd4e99b6
    chore(deps): bump golang.org/x/net from 0.28.0 to 0.29.0 (#3203) dependabot[bot] 2024-09-10 10:35:43 -04:00
  • 9c2799e379
    Add the Ocaml ecosystem (#3112) Laurent Goderre 2024-09-10 10:35:18 -04:00
  • dafc6ad034
    chore(deps): bump github.com/charmbracelet/bubbles from 0.19.0 to 0.20.0 (#3209) dependabot[bot] 2024-09-09 16:28:01 -04:00
  • 16f89840fd
    chore(deps): bump modernc.org/sqlite from 1.32.0 to 1.33.0 (#3210) dependabot[bot] 2024-09-09 16:27:52 -04:00
  • 2475f7f696
    chore(deps): bump github.com/docker/docker (#3211) dependabot[bot] 2024-09-09 16:27:43 -04:00
  • f735a428eb
    chore(deps): bump github.com/dave/jennifer from 1.7.0 to 1.7.1 (#3212) dependabot[bot] 2024-09-09 16:27:33 -04:00
  • ba7bf6b85e
    dont cleanup cache in forks (#3214) Alex Goodman 2024-09-09 16:27:21 -04:00
  • b153b1d594
    less verbose java logging when non-fatal issues arise (#3208) Alex Goodman 2024-09-09 11:27:59 -04:00
  • 0a3f513f92
    Slim down docker cache size (#3190) Alex Goodman 2024-09-09 11:15:13 -04:00
  • deabd4115a
    chore(deps): bump peter-evans/create-pull-request from 7.0.0 to 7.0.1 (#3196) dependabot[bot] 2024-09-05 15:06:23 -04:00
  • ff0bae67bd
    chore(deps): bump golang.org/x/mod from 0.20.0 to 0.21.0 (#3197) dependabot[bot] 2024-09-05 15:05:15 -04:00
  • a343825685
    fix: haproxy classifier for versions with -dev suffix (#3180) witchcraze 2024-09-06 03:52:19 +09:00
  • 7c96a10cbe
    chore(deps): bump github.com/Masterminds/sprig/v3 from 3.2.3 to 3.3.0 (#3177) dependabot[bot] 2024-09-03 12:22:43 -04:00
  • 8c690d000d
    chore(deps): update CPE dictionary index (#3183) anchore-actions-token-generator[bot] 2024-09-03 12:22:30 -04:00
  • 8ade391658
    chore(deps): bump actions/upload-artifact from 4.3.6 to 4.4.0 (#3184) dependabot[bot] 2024-09-03 12:22:16 -04:00
  • e299a95120
    chore(deps): bump peter-evans/create-pull-request from 6.1.0 to 7.0.0 (#3187) dependabot[bot] 2024-09-03 12:22:07 -04:00
  • f2caf45695
    fix: properly decode SPDX license expressions in CycloneDX format (#3175) Mikail 2024-08-29 17:05:43 +02:00
  • 731fc77641
    chore(deps): bump github.com/docker/docker (#3168) dependabot[bot] 2024-08-29 14:16:50 +00:00
  • 3499d92c6d
    chore(deps): bump github.com/charmbracelet/bubbletea (#3171) dependabot[bot] 2024-08-29 14:16:43 +00:00
  • 19d2735aff
    chore(deps): bump github/codeql-action from 3.26.5 to 3.26.6 (#3173) dependabot[bot] 2024-08-29 14:16:34 +00:00
  • 11d77b4a94
    fix: cycles resolving relative path parent poms with parent-defined variables (#3170) Keith Zantow 2024-08-28 15:12:13 -04:00
  • 2c25f81b68
    fix: improve generated cpes for binaries with existing classifiers (#3169) Weston Steimel 2024-08-28 16:46:35 +01:00
  • 04e3371cce
    fix: add log time of task (#3105) GGMU 2024-08-28 18:04:26 +03:00
  • 5ab43bafec
    fix: improve known CPEs and set NVD as source for all current binary classifiers (#3167) Weston Steimel 2024-08-27 17:36:34 +01:00
  • e9a8c27be1
    respond to authoratative CPEs from catalogers (#3166) Alex Goodman 2024-08-27 10:26:35 -04:00
  • 4ee6c179f8
    set cataloger names within package cataloger task (#3165) Alex Goodman 2024-08-27 09:23:43 -04:00
  • 99be365f62
    fix: use official CPE for curl binary cataloger (#3164) Weston Steimel 2024-08-27 14:03:19 +01:00