Commit graph

  • c2c8c793d2
    chore(deps): bump actions/upload-artifact from 4.4.1 to 4.4.3 (#3314) dependabot[bot] 2024-10-11 05:17:35 -0400
  • fbff87fc6d
    shorten release docs (#3318) Alex Goodman 2024-10-11 05:17:01 -0400
  • 6f6edb36df chore(deps): update stereoscope to c04af061af62ab3ba6ab6760613526eaa7fcb163 #3319 kzantow 2024-10-11 08:09:50 +0000
  • 729512eab2 shorten release docs #3318 Alex Goodman 2024-10-10 16:31:48 -0400
  • 0c71bf23c5
    docs: clearer deprecation message for --file (#3310) William Murphy 2024-10-10 13:11:45 -0400
  • b62b0cb800
    [docs] Add mastodon link to README.md (#3306) Alan Pope 2024-10-10 15:28:55 +0100
  • 223a52d07e
    chore(deps): update stereoscope to 5bc91bf166769e43d8d0f86c02e877c55eb04aed (#3313) anchore-actions-token-generator[bot] 2024-10-10 06:03:55 -0400
  • 32a64140b4
    chore(deps): bump actions/upload-artifact from 4.4.1 to 4.4.3 #3314 dependabot[bot] 2024-10-10 10:01:55 +0000
  • 5d068f30c0
    chore(deps): bump actions/cache from 4.1.0 to 4.1.1 (#3312) dependabot[bot] 2024-10-10 06:01:06 -0400
  • 138622d9c9 chore(deps): update stereoscope to 5bc91bf166769e43d8d0f86c02e877c55eb04aed #3313 kzantow 2024-10-10 08:09:38 +0000
  • 3fe5184feb
    chore(deps): bump actions/cache from 4.1.0 to 4.1.1 #3312 dependabot[bot] 2024-10-09 13:54:19 +0000
  • 8e322425d2
    chore(deps): bump actions/upload-artifact from 4.4.1 to 4.4.2 #3311 dependabot[bot] 2024-10-09 13:54:12 +0000
  • dca2913b1e docs: clearer deprecation message for --file #3310 Will Murphy 2024-10-09 08:55:48 -0400
  • 5d165e0230
    chore(deps): bump github/codeql-action from 3.26.11 to 3.26.12 (#3307) dependabot[bot] 2024-10-09 08:07:36 -0400
  • 56ed131247
    chore(deps): bump actions/checkout from 4.2.0 to 4.2.1 (#3308) dependabot[bot] 2024-10-09 08:07:14 -0400
  • 37c179b530
    chore(deps): bump actions/upload-artifact from 4.4.0 to 4.4.1 (#3309) dependabot[bot] 2024-10-09 08:06:49 -0400
  • a3bd5145d2 wire up bitnami cataloger to run on images by default spike-bitnami-cataloger Will Murphy 2024-10-08 14:14:23 -0400
  • f9eb2ee609
    chore(deps): bump actions/upload-artifact from 4.4.0 to 4.4.1 #3309 dependabot[bot] 2024-10-08 13:59:47 +0000
  • 378448d4fe
    chore(deps): bump actions/checkout from 4.2.0 to 4.2.1 #3308 dependabot[bot] 2024-10-08 13:59:42 +0000
  • b2fbb57679
    chore(deps): bump github/codeql-action from 3.26.11 to 3.26.12 #3307 dependabot[bot] 2024-10-08 13:59:33 +0000
  • 6a33b80048 prototype: start bitnami cataloger Will Murphy 2024-10-08 09:31:33 -0400
  • bc33107852
    [docs] Add mastodon link to README.md #3306 Alan Pope 2024-10-08 11:59:05 +0100
  • ccbee94b87
    feat: report unknowns in sbom (#2998) v1.14.0 Keith Zantow 2024-10-07 16:11:37 -0400
  • e9f506026d remove unknown usage from elf security feature cataloger #2998 Alex Goodman 2024-10-07 15:32:53 -0400
  • 4d7ed9f749
    chore(deps): bump sigstore/cosign-installer from 3.6.0 to 3.7.0 (#3299) dependabot[bot] 2024-10-07 15:21:34 -0400
  • 4c4e5cb06c
    chore(deps): update stereoscope to efa76446cc1c7e6c4117350943a2754b2453aec4 (#3301) anchore-actions-token-generator[bot] 2024-10-07 15:21:26 -0400
  • 8b6159dbd8
    chore(deps): bump golang.org/x/net from 0.29.0 to 0.30.0 (#3304) dependabot[bot] 2024-10-07 15:20:38 -0400
  • 7b30ce15d7
    chore(deps): bump actions/cache from 4.0.2 to 4.1.0 (#3305) dependabot[bot] 2024-10-07 15:20:29 -0400
  • 27ee203495
    chore(deps): update CPE dictionary index (#3302) anchore-actions-token-generator[bot] 2024-10-07 15:20:12 -0400
  • 3b9c55d28b
    Fix: Parse package.json with non-standard fields in 'author' section (#3300) Piotr Radkowski 2024-10-07 16:26:04 +0200
  • f2ebc6f755
    chore(deps): bump actions/cache from 4.0.2 to 4.1.0 #3305 dependabot[bot] 2024-10-07 13:50:03 +0000
  • 81e67ff68e
    chore(deps): bump golang.org/x/net from 0.29.0 to 0.30.0 #3304 dependabot[bot] 2024-10-07 13:49:57 +0000
  • fe03de984d
    Merge 8e0f6934c8 into 25f5c6729f #2948 C0D3 M4513R 2024-10-07 15:30:00 +0200
  • 092259e8fc
    Merge edd910f88f into 25f5c6729f #3266 Alex Goodman 2024-10-07 15:29:11 +0200
  • b713c5ba12 test: parse 'package.json' files with non-standard fields in author section #3300 Piotr Radkowski 2024-10-07 14:12:45 +0200
  • 28ba7a3c0a Improved parsing of package.json 'author' section Piotr Radkowski 2024-10-04 17:47:26 +0200
  • b01c61679d chore(deps): update CPE dictionary index #3302 wagoodman 2024-10-07 01:30:12 +0000
  • 7128c21e57 chore(deps): update stereoscope to efa76446cc1c7e6c4117350943a2754b2453aec4 #3301 kzantow 2024-10-06 08:08:27 +0000
  • 8af704dcb4
    Merge 13fa727841 into 25f5c6729f #3292 Laurent Goderre 2024-10-05 13:22:45 -0400
  • 25f5c6729f
    chore(deps): bump github/codeql-action from 3.26.10 to 3.26.11 (#3298) dependabot[bot] 2024-10-05 09:25:01 -0400
  • 0d457142cc
    chore: add pull request template (#3294) William Murphy 2024-10-05 09:05:11 -0400
  • fc8457418a
    chore(deps): update tools to latest versions (#3296) anchore-actions-token-generator[bot] 2024-10-05 07:32:32 -0400
  • 1634789f35 chore(deps): update tools to latest versions #3296 spiffcs 2024-10-05 08:07:47 +0000
  • cd73516780
    chore: surface package.json files with no name or version Keith Zantow 2024-10-04 16:21:11 -0400
  • 9112f71db9
    Merge remote-tracking branch 'upstream/main' into feat/known-unknowns Keith Zantow 2024-10-04 15:46:08 -0400
  • bc5ea249f7
    Merge 9166df5e6b into 13c6876906 #3132 GGMU 2024-10-04 17:31:42 +0200
  • 13c6876906
    Track supporting DPKG evidence (#3228) Alex Goodman 2024-10-04 11:07:29 -0400
  • 29fa195110 use path over filepath #3228 Alex Goodman 2024-10-04 10:57:52 -0400
  • 7cdf30b2fe
    chore(deps): bump sigstore/cosign-installer from 3.6.0 to 3.7.0 #3299 dependabot[bot] 2024-10-04 13:44:03 +0000
  • 6872874a39
    chore(deps): bump github/codeql-action from 3.26.10 to 3.26.11 #3298 dependabot[bot] 2024-10-04 13:44:00 +0000
  • 770fdc53ea
    Fix: make failed CPE validation correctly return error (#2762) William Murphy 2024-10-03 16:42:57 -0400
  • 62e974b623 chore: add pull request template #3294 Will Murphy 2024-10-03 14:30:25 -0400
  • 32c0d1e673
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.5.9 to 6.6.0 (#3293) dependabot[bot] 2024-10-03 10:14:13 -0400
  • 1cea756ce7
    chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.5.9 to 6.6.0 #3293 dependabot[bot] 2024-10-03 13:19:11 +0000
  • 13fa727841 Add cataloger for Dart pubspec #3292 Laurent Goderre 2024-09-30 11:28:26 -0400
  • 1c1b3af16c
    test: add test to cover new OSCPE err pattern #2762 Christopher Phillips 2024-10-02 16:22:38 -0400
  • cd04a00776
    chore: merge with main and refactor call that relied on old nil behavior Christopher Phillips 2024-10-02 16:15:27 -0400
  • 7a6ea44fe9
    Merge branch 'main' into fix-cpe-validation Christopher Phillips 2024-10-02 16:06:12 -0400
  • 263ea6b1bb
    feat: update haproxy classifier (#3277) witchcraze 2024-10-03 04:10:39 +0900
  • cc4f62b3d4
    chore(deps): update tools to latest versions (#3291) anchore-actions-token-generator[bot] 2024-10-02 09:07:25 -0400
  • f64835c1dc chore(deps): update tools to latest versions #3291 spiffcs 2024-10-02 08:08:42 +0000
  • dbad17de9e
    fix: don't use builtin scanner in licensecheck (#3290) Niv Govrin 2024-10-01 20:53:54 +0300
  • 6f401891e7
    test: update tests to match new SPDXLicense structure #3244 3088-full-license-description Christopher Phillips 2024-10-01 11:52:48 -0400
  • 93beceb4a2
    chore(deps): update CPE dictionary index (#3288) anchore-actions-token-generator[bot] 2024-10-01 10:50:15 -0400
  • 9b242b0309
    chore(deps): bump github/codeql-action from 3.26.9 to 3.26.10 (#3289) dependabot[bot] 2024-10-01 10:48:46 -0400
  • edd910f88f [wip] more concurrent catalogers #3266 more-concurrent-catalogers Alex Goodman 2024-10-01 10:18:44 -0400
  • aaef307d15 fix: don't use builtin scanner in licensecheck #3290 Niv Govrin 2024-10-01 09:09:00 +0000
  • f5f8005fe0
    update redis classifier (#3281) witchcraze 2024-10-01 04:37:47 +0900
  • 53e4a0a851
    chore(deps): bump github/codeql-action from 3.26.9 to 3.26.10 #3289 dependabot[bot] 2024-09-30 14:02:39 +0000
  • 9d0c9bf97d chore(deps): update CPE dictionary index #3288 wagoodman 2024-09-30 01:30:06 +0000
  • 8a722d0ffe
    feat: refactor license constructor and break all tests Christopher Phillips 2024-09-27 15:36:30 -0400
  • e9add57a3c
    chore: bump JSON schema Christopher Phillips 2024-09-27 11:43:43 -0400
  • 18e5807bb1
    Merge 30d6eb53ac into 2a3d171c10 #3244 Christopher Angelo Phillips 2024-09-27 11:34:30 -0400
  • 2a3d171c10
    fix: improve node classifier version matching (#3284) witchcraze 2024-09-27 21:53:35 +0900
  • 1a746b2c05
    fix: update ruby classifier for -rc, -dev, etc. versions (#3285) witchcraze 2024-09-27 21:51:50 +0900
  • d37b5cb1b0 update ruby classifier Signed-off-by: witchcraze <witchcraze@gmail.com> #3285 witchcraze 2024-09-27 16:06:16 +0900
  • f12ce2bf32 update node classifier Signed-off-by: witchcraze <witchcraze@gmail.com> #3284 witchcraze 2024-09-27 14:40:56 +0900
  • e37c4686c2
    chore(deps): update CPE dictionary index (#3262) anchore-actions-token-generator[bot] 2024-09-26 13:49:18 -0400
  • 5393cd5dec
    chore(deps): bump github.com/docker/docker (#3264) dependabot[bot] 2024-09-26 13:49:02 -0400
  • f9ef9cf1dc
    chore(deps): bump github/codeql-action from 3.26.8 to 3.26.9 (#3275) dependabot[bot] 2024-09-26 13:48:45 -0400
  • 16122eb32d
    chore(deps): update stereoscope to dc10ea61fd18efa45b516eda4de8bc19d8322429 (#3280) anchore-actions-token-generator[bot] 2024-09-26 13:48:33 -0400
  • 39b2bf5518
    chore(deps): bump actions/checkout from 4.1.7 to 4.2.0 (#3283) dependabot[bot] 2024-09-26 13:48:12 -0400
  • 9177d93825
    chore(deps): bump actions/checkout from 4.1.7 to 4.2.0 #3283 dependabot[bot] 2024-09-26 14:00:41 +0000
  • f2d79b12b2 Remove snippets to pass Validation. In this case, 9000 byte was required... Signed-off-by: witchcraze <witchcraze@gmail.com> #3281 witchcraze 2024-09-26 17:37:18 +0900
  • ffd95970c8 update redis classifier Signed-off-by: witchcraze <witchcraze@gmail.com> witchcraze 2024-09-26 17:31:16 +0900
  • c2d3092301 chore(deps): update stereoscope to dc10ea61fd18efa45b516eda4de8bc19d8322429 #3280 kzantow 2024-09-26 08:10:16 +0000
  • b046926396 update haproxy classifier Signed-off-by: witchcraze <witchcraze@gmail.com> #3277 witchcraze 2024-09-26 13:09:06 +0900
  • c142f96db5
    chore(deps): bump github/codeql-action from 3.26.8 to 3.26.9 #3275 dependabot[bot] 2024-09-25 13:49:57 +0000
  • d7005d7d8c
    add awaiting response management (#3272) Alex Goodman 2024-09-25 08:56:21 -0400
  • 5963cf815b
    Merge remote-tracking branch 'upstream/main' into chore/refactor-maven-resolver #3273 Keith Zantow 2024-09-24 17:50:54 -0400
  • f0475b5579
    fix: archive parser dependency graph for nested jars, source poms Keith Zantow 2024-09-24 17:50:30 -0400
  • 92c1ddec5a
    fix: correct excluded mount point comparison to file paths (#3269) Christian Dupuis 2024-09-24 23:05:16 +0200
  • 6f426a1c70 add awaiting response management #3272 Alex Goodman 2024-09-24 16:33:16 -0400
  • cbba9274e1
    Improve subpath to mount matching #3269 Christian Dupuis 2024-09-24 13:44:53 +0200
  • e5ac697c3c feat: add binary classifier for avahi #3270 Krystian Gorny 2024-09-24 13:34:45 +0200
  • 2d5fd47ea7 feat: add binary classifier for syslog-ng Krystian Gorny 2024-09-24 13:33:56 +0200
  • 36022ca596 feat: add binary classifier for openssh Krystian Gorny 2024-09-24 12:40:37 +0200
  • 43901bcd43 Add binary cataloger curl test Krystian Gorny 2024-09-24 12:36:50 +0200
  • f28929b643 Remove duplicate binary cataloger zstd test Krystian Gorny 2024-09-24 12:26:56 +0200
  • 01de99b253
    Add JVM cataloger (#3217) v1.13.0 1.13.x Alex Goodman 2024-09-23 17:21:38 -0400