From 52068dc533ee95c7a27f45f763dc2660d040cffc Mon Sep 17 00:00:00 2001 From: gitea_admin Date: Sun, 27 Sep 2026 22:15:50 +0000 Subject: [PATCH] chore(deps): update dependency grype to v0.118.0 (#34) MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit This PR contains the following updates: | Package | Update | Change | |---|---|---| | [grype](https://github.com/anchore/grype) | minor | `0.92.2` → `0.118.0` | --- ### Release Notes
anchore/grype (grype) ### [`v0.118.0`](https://github.com/anchore/grype/releases/tag/v0.118.0) ##### Added Features - apk matcher does alias aware aggregation \[PR [#​3634](https://github.com/anchore/grype/pull/3634) [@​crosleyzack](https://github.com/crosleyzack)] ##### Bug Fixes - prevent panic on portage versions without digits \[PR [#​3655](https://github.com/anchore/grype/pull/3655) [@​ashvinctrl](https://github.com/ashvinctrl)] - grype vex does not match oci purl with repository\_url \[Issue [#​3657](https://github.com/anchore/grype/issues/3657)] \[PR [#​3659](https://github.com/anchore/grype/pull/3659) [@​spiffcs](https://github.com/spiffcs)] - Old JVM version comparisons sometimes incorrect \[Issue [#​2701](https://github.com/anchore/grype/issues/2701)] \[PR [#​3583](https://github.com/anchore/grype/pull/3583) [@​Eljees](https://github.com/Eljees)] - CVSSv4 calculation can produce incorrect vulnerability severity \[Issue [#​3656](https://github.com/anchore/grype/issues/3656)] - Grype 0.90.0 DB update failed \[Issue [#​3629](https://github.com/anchore/grype/issues/3629)] ##### Dependencies 72 dependency changes (70 updated, 1 added, 1 removed). 3 vulnerabilities remediated. **🟢 Remediated (3)** - [GO-2026-5158](https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835) (Medium) — go.opentelemetry.io/otel - [GO-2026-6179](https://go.dev/issue/80744) (High) — golang.org/x/mod - [GO-2026-6180](https://go.dev/issue/80745) (High) — golang.org/x/mod
Updated (70 packages) - cel.dev/expr `v0.25.1` → `v0.25.2` - cloud.google.com/go/auth `v0.18.2` → `v0.22.0` - cloud.google.com/go/iam `v1.5.3` → `v1.11.0` - cloud.google.com/go/logging `v1.13.1` → `v1.18.0` - cloud.google.com/go/longrunning `v0.8.0` → `v1.2.0` - cloud.google.com/go/monitoring `v1.24.3` → `v1.29.0` - cloud.google.com/go/storage `v1.61.3` → `v1.64.0` - cloud.google.com/go/trace `v1.11.7` → `v1.16.0` - github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp `v1.32.0` → `v1.33.0` - github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric `v0.55.0` → `v0.57.0` - github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock `v0.55.0` → `v0.57.0` - github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping `v0.55.0` → `v0.57.0` - github.com/anchore/stereoscope `v0.3.0` → `v0.3.1` - github.com/anchore/syft `v1.51.0` → `v1.51.1` - github.com/aws/aws-sdk-go-v2 `v1.41.5` → `v1.43.4` - github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream `v1.7.8` → `v1.7.16` - github.com/aws/aws-sdk-go-v2/config `v1.32.12` → `v1.32.35` - github.com/aws/aws-sdk-go-v2/credentials `v1.19.12` → `v1.19.34` - github.com/aws/aws-sdk-go-v2/feature/ec2/imds `v1.18.20` → `v1.18.35` - github.com/aws/aws-sdk-go-v2/internal/configsources `v1.4.21` → `v1.4.35` - github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 `v2.7.21` → `v2.7.35` - github.com/aws/aws-sdk-go-v2/internal/v4a `v1.4.22` → `v1.4.36` - github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding `v1.13.7` → `v1.13.15` - github.com/aws/aws-sdk-go-v2/service/internal/checksum `v1.9.13` → `v1.9.28` - github.com/aws/aws-sdk-go-v2/service/internal/presigned-url `v1.13.21` → `v1.13.35` - github.com/aws/aws-sdk-go-v2/service/internal/s3shared `v1.19.21` → `v1.19.36` - github.com/aws/aws-sdk-go-v2/service/s3 `v1.97.3` → `v1.106.5` - github.com/aws/aws-sdk-go-v2/service/signin `v1.0.8` → `v1.5.4` - github.com/aws/aws-sdk-go-v2/service/sso `v1.30.13` → `v1.33.4` - github.com/aws/aws-sdk-go-v2/service/ssooidc `v1.35.17` → `v1.38.4` - github.com/aws/aws-sdk-go-v2/service/sts `v1.41.9` → `v1.45.4` - github.com/aws/smithy-go `v1.24.2` → `v1.27.6` - github.com/containerd/containerd/v2 `v2.3.3` → `v2.3.4` - github.com/containerd/platforms `v1.0.0-rc.4` → `v1.0.0-rc.5` - github.com/docker/cli `v29.6.1+incompatible` → `v29.7.2+incompatible` - github.com/docker/go-connections `v0.7.0` → `v0.8.1` - github.com/fatih/color `v1.18.0` → `v1.19.0` - github.com/google/go-containerregistry `v0.21.7` → `v0.21.9` - github.com/google/pprof `v0.0.0-6e76a2b` → `v0.0.0-ef3492d` - github.com/googleapis/enterprise-certificate-proxy `v0.3.14` → `v0.3.19` - github.com/googleapis/gax-go/v2 `v2.17.0` → `v2.23.0` - github.com/hashicorp/aws-sdk-go-base/v2 `v2.0.0-beta.72` → `v2.0.0-beta.74` - github.com/hashicorp/go-getter `v1.8.6` → `v1.8.8` - github.com/hashicorp/go-version `v1.8.0` → `v1.9.0` - github.com/klauspost/compress `v1.19.1` → `v1.19.2` - github.com/mattn/go-isatty `v0.0.20` → `v0.0.24` - github.com/moby/moby/client `v0.5.0` → `v0.5.1` - github.com/spiffe/go-spiffe/v2 `v2.6.0` → `v2.7.0` - github.com/stretchr/objx `v0.5.2` → `v0.5.3` - github.com/stretchr/testify `v1.11.1` → `v1.12.1` - go.opentelemetry.io/contrib/detectors/gcp `v1.43.0` → `v1.44.0` - go.opentelemetry.io/otel `v1.43.0` → `v1.44.0` **(🟢 remediated [GO-2026-5158](https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835))** - go.opentelemetry.io/otel/exporters/stdout/stdoutmetric `v1.40.0` → `v1.44.0` - go.opentelemetry.io/otel/metric `v1.43.0` → `v1.44.0` - go.opentelemetry.io/otel/sdk `v1.43.0` → `v1.44.0` - go.opentelemetry.io/otel/sdk/metric `v1.43.0` → `v1.44.0` - go.opentelemetry.io/otel/trace `v1.43.0` → `v1.44.0` - golang.org/x/crypto `v0.54.0` → `v0.55.0` - golang.org/x/mod `v0.38.0` → `v0.40.0` **(🟢 remediated [GO-2026-6179](https://go.dev/issue/80744), [GO-2026-6180](https://go.dev/issue/80745))** - golang.org/x/net `v0.57.0` → `v0.58.0` - golang.org/x/text `v0.40.0` → `v0.41.0` - golang.org/x/tools `v0.48.0` → `v0.49.0` - google.golang.org/api `v0.271.0` → `v0.292.0` - google.golang.org/genproto `v0.0.0-8636f87` → `v0.0.0-aa98bba` - google.golang.org/genproto/googleapis/api `v0.0.0-afd174a` → `v0.0.0-925bb5d` - google.golang.org/genproto/googleapis/rpc `v0.0.0-afd174a` → `v0.0.0-6ac0973` - google.golang.org/grpc `v1.82.1` → `v1.83.0` - modernc.org/cc/v4 `v4.29.0` → `v4.29.1` - modernc.org/libc `v1.74.1` → `v1.74.4` - modernc.org/sqlite `v1.55.0` → `v1.56.0`
Added (1 package) - go.opentelemetry.io/otel/metric/x `v0.66.0`
Removed (1 package) - github.com/aws/aws-sdk-go-v2/internal/ini `v1.8.6`
**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.117.0...v0.118.0)** ### [`v0.117.0`](https://github.com/anchore/grype/releases/tag/v0.117.0) ##### Added Features - Include vulnerable ranges in CycloneDX output format \[Issue [#​3512](https://github.com/anchore/grype/issues/3512)] \[PR [#​3519](https://github.com/anchore/grype/pull/3519) [@​somaz94](https://github.com/somaz94)] ##### Bug Fixes - honor match.rust.using-cpes configuration \[PR [#​3611](https://github.com/anchore/grype/pull/3611) [@​Dashtid](https://github.com/Dashtid)] ##### Dependencies 11 dependency changes (11 updated). 2 vulnerabilities remediated. **🟢 Remediated (2)** - [GHSA-hc8v-wwc9-vgxm](https://github.com/advisories/GHSA-hc8v-wwc9-vgxm) (High) — github.com/go-git/go-git/v5 - [GHSA-qgq7-7hm3-q39j](https://github.com/advisories/GHSA-qgq7-7hm3-q39j) (Medium) — github.com/go-git/go-git/v5
Updated (11 packages) - github.com/anchore/syft `v1.50.0` → `v1.51.0` - github.com/diskfs/go-diskfs `v1.9.3` → `v1.9.4` - github.com/gabriel-vasile/mimetype `v1.4.13` → `v1.4.15` - github.com/go-git/go-billy/v5 `v5.9.0` → `v5.9.1` - github.com/go-git/go-git/v5 `v5.19.1` → `v5.19.2` **(🟢 remediated [GHSA-hc8v-wwc9-vgxm](https://github.com/advisories/GHSA-hc8v-wwc9-vgxm), [GHSA-qgq7-7hm3-q39j](https://github.com/advisories/GHSA-qgq7-7hm3-q39j))** - github.com/klauspost/compress `v1.19.0` → `v1.19.1` - github.com/magiconair/properties `v1.8.10` → `v1.18.11` - github.com/santhosh-tekuri/jsonschema/v6 `v6.0.2` → `v6.0.3` - github.com/ulikunitz/xz `v0.5.15` → `v0.5.16` - go.yaml.in/yaml/v3 `v3.0.4` → `v3.0.5` - modernc.org/sqlite `v1.54.0` → `v1.55.0`
**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.116.1...v0.117.0)** ### [`v0.116.1`](https://github.com/anchore/grype/releases/tag/v0.116.1) ##### Bug Fixes - Ensure channel parsing is consistent \[PR [#​3603](https://github.com/anchore/grype/pull/3603) [@​wagoodman](https://github.com/wagoodman)] - Scope Go GHSA twins by shared CVE \[PR [#​3592](https://github.com/anchore/grype/pull/3592) [@​wagoodman](https://github.com/wagoodman)] - do not cache a comparator that failed to build \[PR [#​3567](https://github.com/anchore/grype/pull/3567) [@​arpitjain099](https://github.com/arpitjain099)] - Add fix date to rhel minor records created from rhsa \[PR [#​3585](https://github.com/anchore/grype/pull/3585) [@​wagoodman](https://github.com/wagoodman)] - grype reporting CVE-64091 as critical - redhat says it is not affected \[Issue [#​3591](https://github.com/anchore/grype/issues/3591)] - panic: index out of range in distro.parseVersion for VERSION\_ID=v \[Issue [#​3588](https://github.com/anchore/grype/issues/3588)] \[PR [#​3589](https://github.com/anchore/grype/pull/3589) [@​matiasinsaurralde](https://github.com/matiasinsaurralde)] - False Positive: GO-2026-5932 \[Issue [#​3573](https://github.com/anchore/grype/issues/3573)] ##### Dependencies 30 dependency changes (30 updated). 1 vulnerability remediated. **🟢 Remediated (1)** - [GHSA-hrxh-6v49-42gf](https://github.com/advisories/GHSA-hrxh-6v49-42gf) (High) — google.golang.org/grpc
Updated (30 packages) - github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp `v1.31.0` → `v1.32.0` - github.com/anchore/stereoscope `v0.2.2` → `v0.3.0` - github.com/anchore/syft `v1.48.0` → `v1.50.0` - github.com/cncf/xds/go `v0.0.0-ee656c7` → `v0.0.0-dba9d58` - github.com/containerd/containerd/v2 `v2.3.2` → `v2.3.3` - github.com/docker/cli `v29.5.3+incompatible` → `v29.6.1+incompatible` - github.com/envoyproxy/go-control-plane/envoy `v1.36.0` → `v1.37.0` - github.com/envoyproxy/protoc-gen-validate `v1.3.0` → `v1.3.3` - github.com/gkampitakis/go-snaps `v0.5.22` → `v0.5.23` - github.com/gpustack/gguf-parser-go `v0.24.1` → `v0.25.0` - github.com/moby/moby/api `v1.54.2` → `v1.55.0` - github.com/moby/moby/client `v0.4.1` → `v0.5.0` - github.com/pelletier/go-toml/v2 `v2.3.1` → `v2.4.3` - go.opentelemetry.io/contrib/detectors/gcp `v1.39.0` → `v1.43.0` - golang.org/x/crypto `v0.53.0` → `v0.54.0` - golang.org/x/mod `v0.37.0` → `v0.38.0` - golang.org/x/net `v0.56.0` → `v0.57.0` - golang.org/x/sync `v0.21.0` → `v0.22.0` - golang.org/x/sys `v0.46.0` → `v0.47.0` - golang.org/x/term `v0.44.0` → `v0.45.0` - golang.org/x/text `v0.39.0` → `v0.40.0` - golang.org/x/tools `v0.47.0` → `v0.48.0` - google.golang.org/genproto/googleapis/api `v0.0.0-9d38bb4` → `v0.0.0-afd174a` - google.golang.org/genproto/googleapis/rpc `v0.0.0-6f92a3b` → `v0.0.0-afd174a` - google.golang.org/grpc `v1.80.0` → `v1.82.1` **(🟢 remediated [GHSA-hrxh-6v49-42gf](https://github.com/advisories/GHSA-hrxh-6v49-42gf))** - modernc.org/cc/v4 `v4.28.4` → `v4.29.0` - modernc.org/ccgo/v4 `v4.34.4` → `v4.34.6` - modernc.org/gc/v3 `v3.1.3` → `v3.1.4` - modernc.org/libc `v1.73.4` → `v1.74.1` - modernc.org/sqlite `v1.53.0` → `v1.54.0`
**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.116.0...v0.116.1)** ### [`v0.115.0`](https://github.com/anchore/grype/releases/tag/v0.115.0) ##### Added Features - emit golang.org/x/net vulns from govlundb \[PR [#​3534](https://github.com/anchore/grype/pull/3534) [@​willmurphyscode](https://github.com/willmurphyscode)] - Merge Go vuln matches with GHSA matches \[Issue [#​3515](https://github.com/anchore/grype/issues/3515)] ##### Bug Fixes - only emit records for stdlib \[PR [#​3527](https://github.com/anchore/grype/pull/3527) [@​willmurphyscode](https://github.com/willmurphyscode)] - mark hummingbird distro as rolling \[PR [#​3521](https://github.com/anchore/grype/pull/3521) [@​willmurphyscode](https://github.com/willmurphyscode)] - disable go stdlib CPE matching by default \[PR [#​3517](https://github.com/anchore/grype/pull/3517) [@​willmurphyscode](https://github.com/willmurphyscode)] - merge in custom ranges when applicable \[PR [#​3514](https://github.com/anchore/grype/pull/3514) [@​willmurphyscode](https://github.com/willmurphyscode)] - exclude linux-kbuild deb indirect matches by default \[PR [#​3506](https://github.com/anchore/grype/pull/3506) [@​westonsteimel](https://github.com/westonsteimel)] - avoid panic on invalid RHEL version IDs \[PR [#​3490](https://github.com/anchore/grype/pull/3490) [@​jspilman](https://github.com/jspilman)] - Support reading CycloneDX 1.7 SBOMs \[Issue [#​3373](https://github.com/anchore/grype/issues/3373)] - Grype cannot read mariadb version correctly \[Issue [#​3452](https://github.com/anchore/grype/issues/3452)] - grype hangs when downloading certain images using registry client \[Issue [#​3492](https://github.com/anchore/grype/issues/3492)] - Can we get a fix for these Critical findings reported for grype \[Issue [#​3484](https://github.com/anchore/grype/issues/3484)] ##### Additional Changes - Security: bump golang.org/x/crypto to v0.52.0 to resolve multiple CVEs \[Issue [#​3493](https://github.com/anchore/grype/issues/3493)] - Security: bump golang.org/x/net to v0.55.0 to resolve CVEs \[Issue [#​3494](https://github.com/anchore/grype/issues/3494)] ##### Dependencies 35 dependency changes (31 updated, 3 added, 1 removed). 5 vulnerabilities remediated. **🟢 Remediated (5)** - [GHSA-33vj-92qq-66hc](https://github.com/advisories/GHSA-33vj-92qq-66hc) (High) — github.com/containerd/containerd/v2 - [GHSA-cvxm-645q-p574](https://github.com/advisories/GHSA-cvxm-645q-p574) (Medium) — github.com/containerd/containerd/v2 - [GHSA-jpcc-p29g-p8mq](https://github.com/advisories/GHSA-jpcc-p29g-p8mq) (Medium) — github.com/containerd/containerd/v2 - [GHSA-rgh6-rfwx-v388](https://github.com/advisories/GHSA-rgh6-rfwx-v388) (High) — github.com/containerd/containerd/v2 - [GHSA-xhf5-7wjv-pqxp](https://github.com/advisories/GHSA-xhf5-7wjv-pqxp) (High) — github.com/containerd/containerd/v2
Updated (31 packages) - github.com/ProtonMail/go-crypto `v1.4.0` → `v1.4.1` - github.com/anchore/bubbly `v0.2.0` → `v0.2.1` - github.com/anchore/clio `v0.1.0` → `v0.1.1` - github.com/anchore/fangs `v0.1.0` → `v0.1.1` - github.com/anchore/go-collections `v0.1.0` → `v0.1.1` - github.com/anchore/go-homedir `v0.1.0` → `v0.1.1` - github.com/anchore/go-logger `v0.1.0` → `v0.1.1` - github.com/anchore/go-lzo `v0.1.0` → `v0.1.1` - github.com/anchore/go-macholibre `v0.1.0` → `v0.1.1` - github.com/anchore/go-make `v0.5.0` → `v0.8.0` - github.com/anchore/go-struct-converter `v0.1.0` → `v0.2.0-rc2` - github.com/anchore/go-sync `v0.1.0` → `v0.1.1` - github.com/anchore/stereoscope `v0.2.1` → `v0.2.2` - github.com/anchore/syft `v1.45.1` → `v1.46.0` - github.com/charmbracelet/colorprofile `v0.4.1` → `v0.4.3` - github.com/clipperhouse/displaywidth `v0.10.0` → `v0.11.0` - github.com/clipperhouse/uax29/v2 `v2.6.0` → `v2.7.0` - github.com/containerd/containerd/v2 `v2.3.1` → `v2.3.2` **(🟢 remediated [GHSA-33vj-92qq-66hc](https://github.com/advisories/GHSA-33vj-92qq-66hc), [GHSA-cvxm-645q-p574](https://github.com/advisories/GHSA-cvxm-645q-p574), [GHSA-jpcc-p29g-p8mq](https://github.com/advisories/GHSA-jpcc-p29g-p8mq), [GHSA-rgh6-rfwx-v388](https://github.com/advisories/GHSA-rgh6-rfwx-v388), [GHSA-xhf5-7wjv-pqxp](https://github.com/advisories/GHSA-xhf5-7wjv-pqxp))** - github.com/docker/cli `v29.4.3+incompatible` → `v29.5.3+incompatible` - github.com/google/go-containerregistry `v0.21.6` → `v0.21.7` - github.com/mattn/go-runewidth `v0.0.19` → `v0.0.21` - github.com/spdx/tools-golang `v0.5.7` → `v0.6.0-rc4` - github.com/sylabs/sif/v2 `v2.24.0` → `v2.24.1` - golang.org/x/crypto `v0.52.0` → `v0.53.0` - golang.org/x/mod `v0.36.0` → `v0.37.0` - golang.org/x/net `v0.55.0` → `v0.56.0` - golang.org/x/sync `v0.20.0` → `v0.21.0` - golang.org/x/sys `v0.45.0` → `v0.46.0` - golang.org/x/term `v0.43.0` → `v0.44.0` - golang.org/x/text `v0.37.0` → `v0.38.0` - golang.org/x/tools `v0.45.0` → `v0.46.0`
Added (3 packages) - github.com/piprate/json-gold `v0.7.0` - github.com/pquerna/cachecontrol `v0.0.0-1555304` - github.com/tailscale/hujson `v0.0.0-ecc657c`
Removed (1 package) - github.com/google/osv-scanner `v1.9.2`
**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.114.0...v0.115.0)** ### [`v0.114.0`](https://github.com/anchore/grype/releases/tag/v0.114.0) ##### Added Features - Add ability to scan zarf packages \[[#​3329](https://github.com/anchore/grype/issues/3329) [#​3366](https://github.com/anchore/grype/pull/3366) [@​brandtkeller](https://github.com/brandtkeller)] ##### Additional Changes - respect withdrawn status of Go Vuln DB OSV records \[[#​3495](https://github.com/anchore/grype/pull/3495) [@​willmurphyscode](https://github.com/willmurphyscode)] - Govulndb OSV transformer \[[#​3485](https://github.com/anchore/grype/pull/3485) [@​willmurphyscode](https://github.com/willmurphyscode)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.113.0...v0.114.0)** ### [`v0.113.0`](https://github.com/anchore/grype/releases/tag/v0.113.0) ##### Added Features - Include Ubuntu 26.04 "resolute" in distro codenames \[[#​3397](https://github.com/anchore/grype/pull/3397) [@​anchore-oss-update-bot](https://github.com/anchore-oss-update-bot)] - source RPM filtering on Hummingbird \[[#​3410](https://github.com/anchore/grype/pull/3410) [@​willmurphyscode](https://github.com/willmurphyscode)] ##### Bug Fixes - use relatedVulnerabilities description as fallback in SARIF output \[[#​3271](https://github.com/anchore/grype/pull/3271) [@​axidex](https://github.com/axidex)] - improve platform CPE determination logic \[[#​3470](https://github.com/anchore/grype/pull/3470) [@​westonsteimel](https://github.com/westonsteimel)] - normalize uppercase V in semantic version comparison \[[#​3461](https://github.com/anchore/grype/pull/3461) [@​immanuwell](https://github.com/immanuwell)] - purl handling in cgr maven libs \[[#​3420](https://github.com/anchore/grype/pull/3420) [@​willmurphyscode](https://github.com/willmurphyscode)] - Treat uppercase V prefixes the same as lowercase v prefixes in fuzzy version comparison \[[#​3037](https://github.com/anchore/grype/issues/3037) [#​3089](https://github.com/anchore/grype/pull/3089) [@​wasup-yash](https://github.com/wasup-yash)] - Add Runtime Warnings When TLS Verification Is Disabled or HTTP Is Enabled \[[#​3101](https://github.com/anchore/grype/issues/3101) [#​3396](https://github.com/anchore/grype/pull/3396) [@​Dashtid](https://github.com/Dashtid)] - Add support for the aarch64 architecture when parsing the version of Ruby gems in lockfiles \[[#​3442](https://github.com/anchore/grype/issues/3442) [#​3475](https://github.com/anchore/grype/pull/3475) [@​msnandhis](https://github.com/msnandhis)] - zsh completion fails \[[#​2933](https://github.com/anchore/grype/issues/2933) [#​3433](https://github.com/anchore/grype/pull/3433) [@​brandtkeller](https://github.com/brandtkeller)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.112.0...v0.113.0)** ### [`v0.112.0`](https://github.com/anchore/grype/releases/tag/v0.112.0) ##### Added Features - Expand ignore rules to owned sub packages of distro packages \[[#​3368](https://github.com/anchore/grype/issues/3368) [#​3326](https://github.com/anchore/grype/pull/3326) [@​kzantow](https://github.com/kzantow)] ##### Additional Changes - update anchore dependencies \[[#​3391](https://github.com/anchore/grype/pull/3391) [@​anchore-oss-update-bot](https://github.com/anchore-oss-update-bot)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.111.1...v0.112.0)** ### [`v0.111.1`](https://github.com/anchore/grype/releases/tag/v0.111.1) ##### Bug Fixes - apply overlap by ownership removal to dynamically created relationships \[[#​3363](https://github.com/anchore/grype/pull/3363) [@​kzantow](https://github.com/kzantow)] - compare mismatched package / db versions \[[#​3372](https://github.com/anchore/grype/pull/3372) [@​kzantow](https://github.com/kzantow)] - Grype doesn't recognize debian component when `"group" : "debian"` is specified \[[#​2967](https://github.com/anchore/grype/issues/2967)] - HelpURI missing information in SARIF output \[[#​2874](https://github.com/anchore/grype/issues/2874) [#​3351](https://github.com/anchore/grype/pull/3351) [@​will-bates11](https://github.com/will-bates11)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.111.0...v0.111.1)** ### [`v0.108.0`](https://github.com/anchore/grype/releases/tag/v0.108.0) ##### Added Features - enable disabling EOL warnings \[[#​3204](https://github.com/anchore/grype/pull/3204) [@​willmurphyscode](https://github.com/willmurphyscode)] ##### Bug Fixes - fix fallback on major only distro \[[#​3213](https://github.com/anchore/grype/pull/3213) [@​willmurphyscode](https://github.com/willmurphyscode)] - VEX Documents still not working with syft sbom \[[#​3167](https://github.com/anchore/grype/issues/3167)] - VEX: minimal OpenVEX Example not working \[[#​3212](https://github.com/anchore/grype/issues/3212)] ##### Additional Changes - support more accurate scanning for postmarketos \[[#​3182](https://github.com/anchore/grype/pull/3182) [@​westonsteimel](https://github.com/westonsteimel)] - charmbracelet/bubbletea erases grype ui status line \[[#​3214](https://github.com/anchore/grype/pull/3214) [@​spiffcs](https://github.com/spiffcs)] - bump labels and add several test images \[[#​3215](https://github.com/anchore/grype/pull/3215) [@​westonsteimel](https://github.com/westonsteimel)] - improve VEX product and subcomponent matching \[[#​3168](https://github.com/anchore/grype/pull/3168) [@​dariozachow](https://github.com/dariozachow)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.107.1...v0.108.0)** ### [`v0.105.0`](https://github.com/anchore/grype/releases/tag/v0.105.0) ##### Added Features - Add archlinux matcher to grype \[[#​3154](https://github.com/anchore/grype/pull/3154) [@​willmurphyscode](https://github.com/willmurphyscode)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.4...v0.105.0)** ### [`v0.104.4`](https://github.com/anchore/grype/releases/tag/v0.104.4) ##### Bug Fixes - preserve local version segment in constraints for PEP 440 comparison \[[#​3146](https://github.com/anchore/grype/pull/3146) [@​willmurphyscode](https://github.com/willmurphyscode)] ##### Additional Changes - correct help text for return code for fail-on severity option \[[#​3138](https://github.com/anchore/grype/pull/3138) [@​u-ways](https://github.com/u-ways)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.3...v0.104.4)** ### [`v0.104.3`](https://github.com/anchore/grype/releases/tag/v0.104.3) ##### Bug Fixes - Use specifier matching rules when comparing python versions \[[#​3121](https://github.com/anchore/grype/pull/3121) [@​wagoodman](https://github.com/wagoodman)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.2...v0.104.3)** ### [`v0.104.2`](https://github.com/anchore/grype/releases/tag/v0.104.2) ##### Bug Fixes - Since version 0.104.0 shaded jars are not reported \[[#​3098](https://github.com/anchore/grype/issues/3098)] - db search fails with misleading message (out of memory) when no db is present \[[#​3049](https://github.com/anchore/grype/issues/3049) [#​3077](https://github.com/anchore/grype/pull/3077) [@​JvD-Ericsson](https://github.com/JvD-Ericsson)] ##### Additional Changes - replace os.Chdir with t.Chdir in test code \[[#​3067](https://github.com/anchore/grype/pull/3067) [@​joonas](https://github.com/joonas)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.1...v0.104.2)** ### [`v0.104.1`](https://github.com/anchore/grype/releases/tag/v0.104.1) ##### Bug Fixes - Redact during file output \[[#​3068](https://github.com/anchore/grype/pull/3068) [@​kzantow](https://github.com/kzantow)] - Unaffected match table does not filter results if CPE matching is enabled \[[#​3056](https://github.com/anchore/grype/issues/3056) [#​3066](https://github.com/anchore/grype/pull/3066) [@​kzantow](https://github.com/kzantow)] ##### Additional Changes - Migrate grype to use `mholt/archives` instead of anchore fork \[[#​3036](https://github.com/anchore/grype/pull/3036) [@​joonas](https://github.com/joonas)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.0...v0.104.1)** ### [`v0.104.0`](https://github.com/anchore/grype/releases/tag/v0.104.0) ##### Added Features - Add `--from` flag \[[#​3035](https://github.com/anchore/grype/pull/3035) [@​wagoodman](https://github.com/wagoodman)] - Let a suppression expire to prevent that one will forget to resolve a vulnerability \[[#​3031](https://github.com/anchore/grype/issues/3031)] ##### Bug Fixes - Unnormalized fix version triggers false-positive in mssql-jdbc \[[#​3042](https://github.com/anchore/grype/issues/3042) [#​3034](https://github.com/anchore/grype/pull/3034) [@​jamestexas](https://github.com/jamestexas)] ##### Additional Changes - junit template use CDATA block to prevent XML parse errors \[[#​3019](https://github.com/anchore/grype/pull/3019) [@​nvtkaszpir](https://github.com/nvtkaszpir)] - Keep nested loggers labeled \[[#​3040](https://github.com/anchore/grype/pull/3040) [@​wagoodman](https://github.com/wagoodman)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.103.0...v0.104.0)** ### [`v0.103.0`](https://github.com/anchore/grype/releases/tag/v0.103.0) ##### Added Features - Allow hyphen in version string \[[#​3021](https://github.com/anchore/grype/pull/3021) [@​willmurphyscode](https://github.com/willmurphyscode)] - Respect rpmmod PURL qualifier \[[#​3020](https://github.com/anchore/grype/pull/3020) [@​willmurphyscode](https://github.com/willmurphyscode)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.102.0...v0.103.0)** ### [`v0.102.0`](https://github.com/anchore/grype/releases/tag/v0.102.0) ##### Added Features - Use Alma Linux specific advisories for Alma Linux scans \[[#​2745](https://github.com/anchore/grype/issues/2745) [#​2939](https://github.com/anchore/grype/pull/2939) [@​willmurphyscode](https://github.com/willmurphyscode)] ##### Bug Fixes - Bitnami packages with CPEs are not matched against CPE-based vulnerabilities \[[#​2997](https://github.com/anchore/grype/issues/2997)] ##### Additional Changes - add markdown template \[[#​2987](https://github.com/anchore/grype/pull/2987) [@​sebdanielsson](https://github.com/sebdanielsson)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.101.1...v0.102.0)** ### [`v0.101.1`](https://github.com/anchore/grype/releases/tag/v0.101.1) ##### Bug Fixes - Panic error scanning images with v0.101.0 on some java dependencies \[[#​3002](https://github.com/anchore/grype/issues/3002)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.101.0...v0.101.1)** ### [`v0.101.0`](https://github.com/anchore/grype/releases/tag/v0.101.0) ##### Added Features - Add cyclonedx to RpmMetadata \[[#​2935](https://github.com/anchore/grype/pull/2935) [@​sfc-gh-rmaj](https://github.com/sfc-gh-rmaj)] - `grype db search` can filter by fixed state \[[#​2968](https://github.com/anchore/grype/pull/2968) [@​willmurphyscode](https://github.com/willmurphyscode)] - Support using VEX documents with directory scans and SBOMs \[[#​2471](https://github.com/anchore/grype/issues/2471) [#​2811](https://github.com/anchore/grype/pull/2811) [@​alegrey91](https://github.com/alegrey91)] ##### Bug Fixes - Issue installing Grype using documented curl command \[[#​2985](https://github.com/anchore/grype/issues/2985)] - Advisory ID blank in JSON output \[[#​2965](https://github.com/anchore/grype/issues/2965)] ##### Additional Changes - update flags with v3 to not use default config \[[#​3000](https://github.com/anchore/grype/pull/3000) [@​spiffcs](https://github.com/spiffcs)] - fix Cosign documentation URL in installer \[[#​2995](https://github.com/anchore/grype/pull/2995) [@​lime](https://github.com/lime)] - set advisory id again \[[#​2979](https://github.com/anchore/grype/pull/2979) [@​willmurphyscode](https://github.com/willmurphyscode)] - add db schema validation \[[#​2962](https://github.com/anchore/grype/pull/2962) [@​willmurphyscode](https://github.com/willmurphyscode)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.100.0...v0.101.0)** ### [`v0.100.0`](https://github.com/anchore/grype/releases/tag/v0.100.0) ##### Added Features - Add unaffected package and CPE stores \[[#​2888](https://github.com/anchore/grype/pull/2888) [@​wagoodman](https://github.com/wagoodman)] - use unaffected match table to remove appropriate vulns \[[#​2886](https://github.com/anchore/grype/pull/2886) [@​CrosleyZack](https://github.com/CrosleyZack)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.99.1...v0.100.0)**
--- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). --------- Co-authored-by: Danijel Simeunovic Co-authored-by: Renovate Bot Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/34 Reviewed-by: Danijel Simeunovic Co-authored-by: gitea_admin Co-committed-by: gitea_admin --- devbox.json | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/devbox.json b/devbox.json index bceb9c6..8f0170d 100644 --- a/devbox.json +++ b/devbox.json @@ -12,7 +12,7 @@ "kustomize@5.7.0", "kyverno@1.14.3", "syft@1.29.0", - "grype@0.92.2", + "grype@0.118.0", "traefik@3.6.7", "claude-code@0.2.122", "go@latest",