chore(deps): update dependency grype to v0.118.0 (#34)
/ test (push) Failing after 14m26s

This PR contains the following updates:

| Package | Update | Change |
|---|---|---|
| [grype](https://github.com/anchore/grype) | minor | `0.92.2` → `0.118.0` |

---

### Release Notes

<details>
<summary>anchore/grype (grype)</summary>

### [`v0.118.0`](https://github.com/anchore/grype/releases/tag/v0.118.0)

##### Added Features

- apk matcher does alias aware aggregation \[PR [#&#8203;3634](https://github.com/anchore/grype/pull/3634) [@&#8203;crosleyzack](https://github.com/crosleyzack)]

##### Bug Fixes

- prevent panic on portage versions without digits \[PR [#&#8203;3655](https://github.com/anchore/grype/pull/3655) [@&#8203;ashvinctrl](https://github.com/ashvinctrl)]
- grype vex does not match oci purl with repository\_url \[Issue [#&#8203;3657](https://github.com/anchore/grype/issues/3657)] \[PR [#&#8203;3659](https://github.com/anchore/grype/pull/3659) [@&#8203;spiffcs](https://github.com/spiffcs)]
- Old JVM version comparisons sometimes incorrect \[Issue [#&#8203;2701](https://github.com/anchore/grype/issues/2701)] \[PR [#&#8203;3583](https://github.com/anchore/grype/pull/3583) [@&#8203;Eljees](https://github.com/Eljees)]
- CVSSv4 calculation can produce incorrect vulnerability severity \[Issue [#&#8203;3656](https://github.com/anchore/grype/issues/3656)]
- Grype 0.90.0 DB update failed \[Issue [#&#8203;3629](https://github.com/anchore/grype/issues/3629)]

##### Dependencies

72 dependency changes (70 updated, 1 added, 1 removed). 3 vulnerabilities remediated.

**🟢 Remediated (3)**

- [GO-2026-5158](https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835) (Medium) — go.opentelemetry.io/otel
- [GO-2026-6179](https://go.dev/issue/80744) (High) — golang.org/x/mod
- [GO-2026-6180](https://go.dev/issue/80745) (High) — golang.org/x/mod

<details>
<summary>Updated (70 packages)</summary>

- cel.dev/expr `v0.25.1` → `v0.25.2`
- cloud.google.com/go/auth `v0.18.2` → `v0.22.0`
- cloud.google.com/go/iam `v1.5.3` → `v1.11.0`
- cloud.google.com/go/logging `v1.13.1` → `v1.18.0`
- cloud.google.com/go/longrunning `v0.8.0` → `v1.2.0`
- cloud.google.com/go/monitoring `v1.24.3` → `v1.29.0`
- cloud.google.com/go/storage `v1.61.3` → `v1.64.0`
- cloud.google.com/go/trace `v1.11.7` → `v1.16.0`
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp `v1.32.0` → `v1.33.0`
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric `v0.55.0` → `v0.57.0`
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock `v0.55.0` → `v0.57.0`
- github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping `v0.55.0` → `v0.57.0`
- github.com/anchore/stereoscope `v0.3.0` → `v0.3.1`
- github.com/anchore/syft `v1.51.0` → `v1.51.1`
- github.com/aws/aws-sdk-go-v2 `v1.41.5` → `v1.43.4`
- github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream `v1.7.8` → `v1.7.16`
- github.com/aws/aws-sdk-go-v2/config `v1.32.12` → `v1.32.35`
- github.com/aws/aws-sdk-go-v2/credentials `v1.19.12` → `v1.19.34`
- github.com/aws/aws-sdk-go-v2/feature/ec2/imds `v1.18.20` → `v1.18.35`
- github.com/aws/aws-sdk-go-v2/internal/configsources `v1.4.21` → `v1.4.35`
- github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 `v2.7.21` → `v2.7.35`
- github.com/aws/aws-sdk-go-v2/internal/v4a `v1.4.22` → `v1.4.36`
- github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding `v1.13.7` → `v1.13.15`
- github.com/aws/aws-sdk-go-v2/service/internal/checksum `v1.9.13` → `v1.9.28`
- github.com/aws/aws-sdk-go-v2/service/internal/presigned-url `v1.13.21` → `v1.13.35`
- github.com/aws/aws-sdk-go-v2/service/internal/s3shared `v1.19.21` → `v1.19.36`
- github.com/aws/aws-sdk-go-v2/service/s3 `v1.97.3` → `v1.106.5`
- github.com/aws/aws-sdk-go-v2/service/signin `v1.0.8` → `v1.5.4`
- github.com/aws/aws-sdk-go-v2/service/sso `v1.30.13` → `v1.33.4`
- github.com/aws/aws-sdk-go-v2/service/ssooidc `v1.35.17` → `v1.38.4`
- github.com/aws/aws-sdk-go-v2/service/sts `v1.41.9` → `v1.45.4`
- github.com/aws/smithy-go `v1.24.2` → `v1.27.6`
- github.com/containerd/containerd/v2 `v2.3.3` → `v2.3.4`
- github.com/containerd/platforms `v1.0.0-rc.4` → `v1.0.0-rc.5`
- github.com/docker/cli `v29.6.1+incompatible` → `v29.7.2+incompatible`
- github.com/docker/go-connections `v0.7.0` → `v0.8.1`
- github.com/fatih/color `v1.18.0` → `v1.19.0`
- github.com/google/go-containerregistry `v0.21.7` → `v0.21.9`
- github.com/google/pprof `v0.0.0-6e76a2b` → `v0.0.0-ef3492d`
- github.com/googleapis/enterprise-certificate-proxy `v0.3.14` → `v0.3.19`
- github.com/googleapis/gax-go/v2 `v2.17.0` → `v2.23.0`
- github.com/hashicorp/aws-sdk-go-base/v2 `v2.0.0-beta.72` → `v2.0.0-beta.74`
- github.com/hashicorp/go-getter `v1.8.6` → `v1.8.8`
- github.com/hashicorp/go-version `v1.8.0` → `v1.9.0`
- github.com/klauspost/compress `v1.19.1` → `v1.19.2`
- github.com/mattn/go-isatty `v0.0.20` → `v0.0.24`
- github.com/moby/moby/client `v0.5.0` → `v0.5.1`
- github.com/spiffe/go-spiffe/v2 `v2.6.0` → `v2.7.0`
- github.com/stretchr/objx `v0.5.2` → `v0.5.3`
- github.com/stretchr/testify `v1.11.1` → `v1.12.1`
- go.opentelemetry.io/contrib/detectors/gcp `v1.43.0` → `v1.44.0`
- go.opentelemetry.io/otel `v1.43.0` → `v1.44.0` **(🟢 remediated [GO-2026-5158](https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835))**
- go.opentelemetry.io/otel/exporters/stdout/stdoutmetric `v1.40.0` → `v1.44.0`
- go.opentelemetry.io/otel/metric `v1.43.0` → `v1.44.0`
- go.opentelemetry.io/otel/sdk `v1.43.0` → `v1.44.0`
- go.opentelemetry.io/otel/sdk/metric `v1.43.0` → `v1.44.0`
- go.opentelemetry.io/otel/trace `v1.43.0` → `v1.44.0`
- golang.org/x/crypto `v0.54.0` → `v0.55.0`
- golang.org/x/mod `v0.38.0` → `v0.40.0` **(🟢 remediated [GO-2026-6179](https://go.dev/issue/80744), [GO-2026-6180](https://go.dev/issue/80745))**
- golang.org/x/net `v0.57.0` → `v0.58.0`
- golang.org/x/text `v0.40.0` → `v0.41.0`
- golang.org/x/tools `v0.48.0` → `v0.49.0`
- google.golang.org/api `v0.271.0` → `v0.292.0`
- google.golang.org/genproto `v0.0.0-8636f87` → `v0.0.0-aa98bba`
- google.golang.org/genproto/googleapis/api `v0.0.0-afd174a` → `v0.0.0-925bb5d`
- google.golang.org/genproto/googleapis/rpc `v0.0.0-afd174a` → `v0.0.0-6ac0973`
- google.golang.org/grpc `v1.82.1` → `v1.83.0`
- modernc.org/cc/v4 `v4.29.0` → `v4.29.1`
- modernc.org/libc `v1.74.1` → `v1.74.4`
- modernc.org/sqlite `v1.55.0` → `v1.56.0`

</details>

<details>
<summary>Added (1 package)</summary>

- go.opentelemetry.io/otel/metric/x `v0.66.0`

</details>

<details>
<summary>Removed (1 package)</summary>

- github.com/aws/aws-sdk-go-v2/internal/ini `v1.8.6`

</details>

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.117.0...v0.118.0)**

### [`v0.117.0`](https://github.com/anchore/grype/releases/tag/v0.117.0)

##### Added Features

- Include vulnerable ranges in CycloneDX output format \[Issue [#&#8203;3512](https://github.com/anchore/grype/issues/3512)] \[PR [#&#8203;3519](https://github.com/anchore/grype/pull/3519) [@&#8203;somaz94](https://github.com/somaz94)]

##### Bug Fixes

- honor match.rust.using-cpes configuration \[PR [#&#8203;3611](https://github.com/anchore/grype/pull/3611) [@&#8203;Dashtid](https://github.com/Dashtid)]

##### Dependencies

11 dependency changes (11 updated). 2 vulnerabilities remediated.

**🟢 Remediated (2)**

- [GHSA-hc8v-wwc9-vgxm](https://github.com/advisories/GHSA-hc8v-wwc9-vgxm) (High) — github.com/go-git/go-git/v5
- [GHSA-qgq7-7hm3-q39j](https://github.com/advisories/GHSA-qgq7-7hm3-q39j) (Medium) — github.com/go-git/go-git/v5

<details>
<summary>Updated (11 packages)</summary>

- github.com/anchore/syft `v1.50.0` → `v1.51.0`
- github.com/diskfs/go-diskfs `v1.9.3` → `v1.9.4`
- github.com/gabriel-vasile/mimetype `v1.4.13` → `v1.4.15`
- github.com/go-git/go-billy/v5 `v5.9.0` → `v5.9.1`
- github.com/go-git/go-git/v5 `v5.19.1` → `v5.19.2` **(🟢 remediated [GHSA-hc8v-wwc9-vgxm](https://github.com/advisories/GHSA-hc8v-wwc9-vgxm), [GHSA-qgq7-7hm3-q39j](https://github.com/advisories/GHSA-qgq7-7hm3-q39j))**
- github.com/klauspost/compress `v1.19.0` → `v1.19.1`
- github.com/magiconair/properties `v1.8.10` → `v1.18.11`
- github.com/santhosh-tekuri/jsonschema/v6 `v6.0.2` → `v6.0.3`
- github.com/ulikunitz/xz `v0.5.15` → `v0.5.16`
- go.yaml.in/yaml/v3 `v3.0.4` → `v3.0.5`
- modernc.org/sqlite `v1.54.0` → `v1.55.0`

</details>

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.116.1...v0.117.0)**

### [`v0.116.1`](https://github.com/anchore/grype/releases/tag/v0.116.1)

##### Bug Fixes

- Ensure channel parsing is consistent \[PR [#&#8203;3603](https://github.com/anchore/grype/pull/3603) [@&#8203;wagoodman](https://github.com/wagoodman)]
- Scope Go GHSA twins by shared CVE \[PR [#&#8203;3592](https://github.com/anchore/grype/pull/3592) [@&#8203;wagoodman](https://github.com/wagoodman)]
- do not cache a comparator that failed to build \[PR [#&#8203;3567](https://github.com/anchore/grype/pull/3567) [@&#8203;arpitjain099](https://github.com/arpitjain099)]
- Add fix date to rhel minor records created from rhsa \[PR [#&#8203;3585](https://github.com/anchore/grype/pull/3585) [@&#8203;wagoodman](https://github.com/wagoodman)]
- grype reporting CVE-64091 as critical - redhat says it is not affected \[Issue [#&#8203;3591](https://github.com/anchore/grype/issues/3591)]
- panic: index out of range in distro.parseVersion for VERSION\_ID=v \[Issue [#&#8203;3588](https://github.com/anchore/grype/issues/3588)] \[PR [#&#8203;3589](https://github.com/anchore/grype/pull/3589) [@&#8203;matiasinsaurralde](https://github.com/matiasinsaurralde)]
- False Positive: GO-2026-5932 \[Issue [#&#8203;3573](https://github.com/anchore/grype/issues/3573)]

##### Dependencies

30 dependency changes (30 updated). 1 vulnerability remediated.

**🟢 Remediated (1)**

- [GHSA-hrxh-6v49-42gf](https://github.com/advisories/GHSA-hrxh-6v49-42gf) (High) — google.golang.org/grpc

<details>
<summary>Updated (30 packages)</summary>

- github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp `v1.31.0` → `v1.32.0`
- github.com/anchore/stereoscope `v0.2.2` → `v0.3.0`
- github.com/anchore/syft `v1.48.0` → `v1.50.0`
- github.com/cncf/xds/go `v0.0.0-ee656c7` → `v0.0.0-dba9d58`
- github.com/containerd/containerd/v2 `v2.3.2` → `v2.3.3`
- github.com/docker/cli `v29.5.3+incompatible` → `v29.6.1+incompatible`
- github.com/envoyproxy/go-control-plane/envoy `v1.36.0` → `v1.37.0`
- github.com/envoyproxy/protoc-gen-validate `v1.3.0` → `v1.3.3`
- github.com/gkampitakis/go-snaps `v0.5.22` → `v0.5.23`
- github.com/gpustack/gguf-parser-go `v0.24.1` → `v0.25.0`
- github.com/moby/moby/api `v1.54.2` → `v1.55.0`
- github.com/moby/moby/client `v0.4.1` → `v0.5.0`
- github.com/pelletier/go-toml/v2 `v2.3.1` → `v2.4.3`
- go.opentelemetry.io/contrib/detectors/gcp `v1.39.0` → `v1.43.0`
- golang.org/x/crypto `v0.53.0` → `v0.54.0`
- golang.org/x/mod `v0.37.0` → `v0.38.0`
- golang.org/x/net `v0.56.0` → `v0.57.0`
- golang.org/x/sync `v0.21.0` → `v0.22.0`
- golang.org/x/sys `v0.46.0` → `v0.47.0`
- golang.org/x/term `v0.44.0` → `v0.45.0`
- golang.org/x/text `v0.39.0` → `v0.40.0`
- golang.org/x/tools `v0.47.0` → `v0.48.0`
- google.golang.org/genproto/googleapis/api `v0.0.0-9d38bb4` → `v0.0.0-afd174a`
- google.golang.org/genproto/googleapis/rpc `v0.0.0-6f92a3b` → `v0.0.0-afd174a`
- google.golang.org/grpc `v1.80.0` → `v1.82.1` **(🟢 remediated [GHSA-hrxh-6v49-42gf](https://github.com/advisories/GHSA-hrxh-6v49-42gf))**
- modernc.org/cc/v4 `v4.28.4` → `v4.29.0`
- modernc.org/ccgo/v4 `v4.34.4` → `v4.34.6`
- modernc.org/gc/v3 `v3.1.3` → `v3.1.4`
- modernc.org/libc `v1.73.4` → `v1.74.1`
- modernc.org/sqlite `v1.53.0` → `v1.54.0`

</details>

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.116.0...v0.116.1)**

### [`v0.115.0`](https://github.com/anchore/grype/releases/tag/v0.115.0)

##### Added Features

- emit golang.org/x/net vulns from govlundb \[PR [#&#8203;3534](https://github.com/anchore/grype/pull/3534) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- Merge Go vuln matches with GHSA matches \[Issue [#&#8203;3515](https://github.com/anchore/grype/issues/3515)]

##### Bug Fixes

- only emit records for stdlib \[PR [#&#8203;3527](https://github.com/anchore/grype/pull/3527) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- mark hummingbird distro as rolling \[PR [#&#8203;3521](https://github.com/anchore/grype/pull/3521) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- disable go stdlib CPE matching by default \[PR [#&#8203;3517](https://github.com/anchore/grype/pull/3517) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- merge in custom ranges when applicable \[PR [#&#8203;3514](https://github.com/anchore/grype/pull/3514) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- exclude linux-kbuild deb indirect matches by default \[PR [#&#8203;3506](https://github.com/anchore/grype/pull/3506) [@&#8203;westonsteimel](https://github.com/westonsteimel)]
- avoid panic on invalid RHEL version IDs \[PR [#&#8203;3490](https://github.com/anchore/grype/pull/3490) [@&#8203;jspilman](https://github.com/jspilman)]
- Support reading CycloneDX 1.7 SBOMs \[Issue [#&#8203;3373](https://github.com/anchore/grype/issues/3373)]
- Grype cannot read mariadb version correctly \[Issue [#&#8203;3452](https://github.com/anchore/grype/issues/3452)]
- grype hangs when downloading certain images using registry client \[Issue [#&#8203;3492](https://github.com/anchore/grype/issues/3492)]
- Can we get a fix for these Critical findings reported for grype \[Issue [#&#8203;3484](https://github.com/anchore/grype/issues/3484)]

##### Additional Changes

- Security: bump golang.org/x/crypto to v0.52.0 to resolve multiple CVEs \[Issue [#&#8203;3493](https://github.com/anchore/grype/issues/3493)]
- Security: bump golang.org/x/net to v0.55.0 to resolve CVEs \[Issue [#&#8203;3494](https://github.com/anchore/grype/issues/3494)]

##### Dependencies

35 dependency changes (31 updated, 3 added, 1 removed). 5 vulnerabilities remediated.

**🟢 Remediated (5)**

- [GHSA-33vj-92qq-66hc](https://github.com/advisories/GHSA-33vj-92qq-66hc) (High) — github.com/containerd/containerd/v2
- [GHSA-cvxm-645q-p574](https://github.com/advisories/GHSA-cvxm-645q-p574) (Medium) — github.com/containerd/containerd/v2
- [GHSA-jpcc-p29g-p8mq](https://github.com/advisories/GHSA-jpcc-p29g-p8mq) (Medium) — github.com/containerd/containerd/v2
- [GHSA-rgh6-rfwx-v388](https://github.com/advisories/GHSA-rgh6-rfwx-v388) (High) — github.com/containerd/containerd/v2
- [GHSA-xhf5-7wjv-pqxp](https://github.com/advisories/GHSA-xhf5-7wjv-pqxp) (High) — github.com/containerd/containerd/v2

<details>
<summary>Updated (31 packages)</summary>

- github.com/ProtonMail/go-crypto `v1.4.0` → `v1.4.1`
- github.com/anchore/bubbly `v0.2.0` → `v0.2.1`
- github.com/anchore/clio `v0.1.0` → `v0.1.1`
- github.com/anchore/fangs `v0.1.0` → `v0.1.1`
- github.com/anchore/go-collections `v0.1.0` → `v0.1.1`
- github.com/anchore/go-homedir `v0.1.0` → `v0.1.1`
- github.com/anchore/go-logger `v0.1.0` → `v0.1.1`
- github.com/anchore/go-lzo `v0.1.0` → `v0.1.1`
- github.com/anchore/go-macholibre `v0.1.0` → `v0.1.1`
- github.com/anchore/go-make `v0.5.0` → `v0.8.0`
- github.com/anchore/go-struct-converter `v0.1.0` → `v0.2.0-rc2`
- github.com/anchore/go-sync `v0.1.0` → `v0.1.1`
- github.com/anchore/stereoscope `v0.2.1` → `v0.2.2`
- github.com/anchore/syft `v1.45.1` → `v1.46.0`
- github.com/charmbracelet/colorprofile `v0.4.1` → `v0.4.3`
- github.com/clipperhouse/displaywidth `v0.10.0` → `v0.11.0`
- github.com/clipperhouse/uax29/v2 `v2.6.0` → `v2.7.0`
- github.com/containerd/containerd/v2 `v2.3.1` → `v2.3.2` **(🟢 remediated [GHSA-33vj-92qq-66hc](https://github.com/advisories/GHSA-33vj-92qq-66hc), [GHSA-cvxm-645q-p574](https://github.com/advisories/GHSA-cvxm-645q-p574), [GHSA-jpcc-p29g-p8mq](https://github.com/advisories/GHSA-jpcc-p29g-p8mq), [GHSA-rgh6-rfwx-v388](https://github.com/advisories/GHSA-rgh6-rfwx-v388), [GHSA-xhf5-7wjv-pqxp](https://github.com/advisories/GHSA-xhf5-7wjv-pqxp))**
- github.com/docker/cli `v29.4.3+incompatible` → `v29.5.3+incompatible`
- github.com/google/go-containerregistry `v0.21.6` → `v0.21.7`
- github.com/mattn/go-runewidth `v0.0.19` → `v0.0.21`
- github.com/spdx/tools-golang `v0.5.7` → `v0.6.0-rc4`
- github.com/sylabs/sif/v2 `v2.24.0` → `v2.24.1`
- golang.org/x/crypto `v0.52.0` → `v0.53.0`
- golang.org/x/mod `v0.36.0` → `v0.37.0`
- golang.org/x/net `v0.55.0` → `v0.56.0`
- golang.org/x/sync `v0.20.0` → `v0.21.0`
- golang.org/x/sys `v0.45.0` → `v0.46.0`
- golang.org/x/term `v0.43.0` → `v0.44.0`
- golang.org/x/text `v0.37.0` → `v0.38.0`
- golang.org/x/tools `v0.45.0` → `v0.46.0`

</details>

<details>
<summary>Added (3 packages)</summary>

- github.com/piprate/json-gold `v0.7.0`
- github.com/pquerna/cachecontrol `v0.0.0-1555304`
- github.com/tailscale/hujson `v0.0.0-ecc657c`

</details>

<details>
<summary>Removed (1 package)</summary>

- github.com/google/osv-scanner `v1.9.2`

</details>

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.114.0...v0.115.0)**

### [`v0.114.0`](https://github.com/anchore/grype/releases/tag/v0.114.0)

##### Added Features

- Add ability to scan zarf packages \[[#&#8203;3329](https://github.com/anchore/grype/issues/3329) [#&#8203;3366](https://github.com/anchore/grype/pull/3366) [@&#8203;brandtkeller](https://github.com/brandtkeller)]

##### Additional Changes

- respect withdrawn status of Go Vuln DB OSV records \[[#&#8203;3495](https://github.com/anchore/grype/pull/3495) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- Govulndb OSV transformer \[[#&#8203;3485](https://github.com/anchore/grype/pull/3485) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.113.0...v0.114.0)**

### [`v0.113.0`](https://github.com/anchore/grype/releases/tag/v0.113.0)

##### Added Features

- Include Ubuntu 26.04 "resolute" in distro codenames \[[#&#8203;3397](https://github.com/anchore/grype/pull/3397) [@&#8203;anchore-oss-update-bot](https://github.com/anchore-oss-update-bot)]
- source RPM filtering on Hummingbird \[[#&#8203;3410](https://github.com/anchore/grype/pull/3410) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]

##### Bug Fixes

- use relatedVulnerabilities description as fallback in SARIF output \[[#&#8203;3271](https://github.com/anchore/grype/pull/3271) [@&#8203;axidex](https://github.com/axidex)]
- improve platform CPE determination logic \[[#&#8203;3470](https://github.com/anchore/grype/pull/3470) [@&#8203;westonsteimel](https://github.com/westonsteimel)]
- normalize uppercase V in semantic version comparison \[[#&#8203;3461](https://github.com/anchore/grype/pull/3461) [@&#8203;immanuwell](https://github.com/immanuwell)]
- purl handling in cgr maven libs \[[#&#8203;3420](https://github.com/anchore/grype/pull/3420) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- Treat uppercase V prefixes the same as lowercase v prefixes in fuzzy version comparison \[[#&#8203;3037](https://github.com/anchore/grype/issues/3037) [#&#8203;3089](https://github.com/anchore/grype/pull/3089) [@&#8203;wasup-yash](https://github.com/wasup-yash)]
- Add Runtime Warnings When TLS Verification Is Disabled or HTTP Is Enabled \[[#&#8203;3101](https://github.com/anchore/grype/issues/3101) [#&#8203;3396](https://github.com/anchore/grype/pull/3396) [@&#8203;Dashtid](https://github.com/Dashtid)]
- Add support for the aarch64 architecture when parsing the version of Ruby gems in lockfiles \[[#&#8203;3442](https://github.com/anchore/grype/issues/3442) [#&#8203;3475](https://github.com/anchore/grype/pull/3475) [@&#8203;msnandhis](https://github.com/msnandhis)]
- zsh completion fails \[[#&#8203;2933](https://github.com/anchore/grype/issues/2933) [#&#8203;3433](https://github.com/anchore/grype/pull/3433) [@&#8203;brandtkeller](https://github.com/brandtkeller)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.112.0...v0.113.0)**

### [`v0.112.0`](https://github.com/anchore/grype/releases/tag/v0.112.0)

##### Added Features

- Expand ignore rules to owned sub packages of distro packages \[[#&#8203;3368](https://github.com/anchore/grype/issues/3368) [#&#8203;3326](https://github.com/anchore/grype/pull/3326) [@&#8203;kzantow](https://github.com/kzantow)]

##### Additional Changes

- update anchore dependencies \[[#&#8203;3391](https://github.com/anchore/grype/pull/3391) [@&#8203;anchore-oss-update-bot](https://github.com/anchore-oss-update-bot)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.111.1...v0.112.0)**

### [`v0.111.1`](https://github.com/anchore/grype/releases/tag/v0.111.1)

##### Bug Fixes

- apply overlap by ownership removal to dynamically created relationships \[[#&#8203;3363](https://github.com/anchore/grype/pull/3363) [@&#8203;kzantow](https://github.com/kzantow)]
- compare mismatched package / db versions \[[#&#8203;3372](https://github.com/anchore/grype/pull/3372) [@&#8203;kzantow](https://github.com/kzantow)]
- Grype doesn't recognize debian component when `"group" : "debian"` is specified \[[#&#8203;2967](https://github.com/anchore/grype/issues/2967)]
- HelpURI missing information in SARIF output \[[#&#8203;2874](https://github.com/anchore/grype/issues/2874) [#&#8203;3351](https://github.com/anchore/grype/pull/3351) [@&#8203;will-bates11](https://github.com/will-bates11)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.111.0...v0.111.1)**

### [`v0.108.0`](https://github.com/anchore/grype/releases/tag/v0.108.0)

##### Added Features

- enable disabling EOL warnings \[[#&#8203;3204](https://github.com/anchore/grype/pull/3204) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]

##### Bug Fixes

- fix fallback on major only distro \[[#&#8203;3213](https://github.com/anchore/grype/pull/3213) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- VEX Documents still not working with syft sbom \[[#&#8203;3167](https://github.com/anchore/grype/issues/3167)]
- VEX: minimal OpenVEX Example not working \[[#&#8203;3212](https://github.com/anchore/grype/issues/3212)]

##### Additional Changes

- support more accurate scanning for postmarketos \[[#&#8203;3182](https://github.com/anchore/grype/pull/3182) [@&#8203;westonsteimel](https://github.com/westonsteimel)]
- charmbracelet/bubbletea erases grype ui status line \[[#&#8203;3214](https://github.com/anchore/grype/pull/3214) [@&#8203;spiffcs](https://github.com/spiffcs)]
- bump labels and add several test images \[[#&#8203;3215](https://github.com/anchore/grype/pull/3215) [@&#8203;westonsteimel](https://github.com/westonsteimel)]
- improve VEX product and subcomponent matching \[[#&#8203;3168](https://github.com/anchore/grype/pull/3168) [@&#8203;dariozachow](https://github.com/dariozachow)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.107.1...v0.108.0)**

### [`v0.105.0`](https://github.com/anchore/grype/releases/tag/v0.105.0)

##### Added Features

- Add archlinux matcher to grype \[[#&#8203;3154](https://github.com/anchore/grype/pull/3154) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.4...v0.105.0)**

### [`v0.104.4`](https://github.com/anchore/grype/releases/tag/v0.104.4)

##### Bug Fixes

- preserve local version segment in constraints for PEP 440 comparison \[[#&#8203;3146](https://github.com/anchore/grype/pull/3146) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]

##### Additional Changes

- correct help text for return code for fail-on severity option \[[#&#8203;3138](https://github.com/anchore/grype/pull/3138) [@&#8203;u-ways](https://github.com/u-ways)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.3...v0.104.4)**

### [`v0.104.3`](https://github.com/anchore/grype/releases/tag/v0.104.3)

##### Bug Fixes

- Use specifier matching rules when comparing python versions \[[#&#8203;3121](https://github.com/anchore/grype/pull/3121) [@&#8203;wagoodman](https://github.com/wagoodman)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.2...v0.104.3)**

### [`v0.104.2`](https://github.com/anchore/grype/releases/tag/v0.104.2)

##### Bug Fixes

- Since version 0.104.0 shaded jars are not reported \[[#&#8203;3098](https://github.com/anchore/grype/issues/3098)]
- db search fails with misleading message (out of memory) when no db is present \[[#&#8203;3049](https://github.com/anchore/grype/issues/3049) [#&#8203;3077](https://github.com/anchore/grype/pull/3077) [@&#8203;JvD-Ericsson](https://github.com/JvD-Ericsson)]

##### Additional Changes

- replace os.Chdir with t.Chdir in test code \[[#&#8203;3067](https://github.com/anchore/grype/pull/3067) [@&#8203;joonas](https://github.com/joonas)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.1...v0.104.2)**

### [`v0.104.1`](https://github.com/anchore/grype/releases/tag/v0.104.1)

##### Bug Fixes

- Redact during file output \[[#&#8203;3068](https://github.com/anchore/grype/pull/3068) [@&#8203;kzantow](https://github.com/kzantow)]
- Unaffected match table does not filter results if CPE matching is enabled \[[#&#8203;3056](https://github.com/anchore/grype/issues/3056) [#&#8203;3066](https://github.com/anchore/grype/pull/3066) [@&#8203;kzantow](https://github.com/kzantow)]

##### Additional Changes

- Migrate grype to use `mholt/archives` instead of anchore fork \[[#&#8203;3036](https://github.com/anchore/grype/pull/3036) [@&#8203;joonas](https://github.com/joonas)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.0...v0.104.1)**

### [`v0.104.0`](https://github.com/anchore/grype/releases/tag/v0.104.0)

##### Added Features

- Add `--from` flag \[[#&#8203;3035](https://github.com/anchore/grype/pull/3035) [@&#8203;wagoodman](https://github.com/wagoodman)]
- Let a suppression expire to prevent that one will forget to resolve a vulnerability \[[#&#8203;3031](https://github.com/anchore/grype/issues/3031)]

##### Bug Fixes

- Unnormalized fix version triggers false-positive in mssql-jdbc \[[#&#8203;3042](https://github.com/anchore/grype/issues/3042) [#&#8203;3034](https://github.com/anchore/grype/pull/3034) [@&#8203;jamestexas](https://github.com/jamestexas)]

##### Additional Changes

- junit template use CDATA block to prevent XML parse errors \[[#&#8203;3019](https://github.com/anchore/grype/pull/3019) [@&#8203;nvtkaszpir](https://github.com/nvtkaszpir)]
- Keep nested loggers labeled \[[#&#8203;3040](https://github.com/anchore/grype/pull/3040) [@&#8203;wagoodman](https://github.com/wagoodman)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.103.0...v0.104.0)**

### [`v0.103.0`](https://github.com/anchore/grype/releases/tag/v0.103.0)

##### Added Features

- Allow hyphen in version string \[[#&#8203;3021](https://github.com/anchore/grype/pull/3021) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- Respect rpmmod PURL qualifier \[[#&#8203;3020](https://github.com/anchore/grype/pull/3020) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.102.0...v0.103.0)**

### [`v0.102.0`](https://github.com/anchore/grype/releases/tag/v0.102.0)

##### Added Features

- Use Alma Linux specific advisories for Alma Linux scans \[[#&#8203;2745](https://github.com/anchore/grype/issues/2745) [#&#8203;2939](https://github.com/anchore/grype/pull/2939) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]

##### Bug Fixes

- Bitnami packages with CPEs are not matched against CPE-based vulnerabilities \[[#&#8203;2997](https://github.com/anchore/grype/issues/2997)]

##### Additional Changes

- add markdown template \[[#&#8203;2987](https://github.com/anchore/grype/pull/2987) [@&#8203;sebdanielsson](https://github.com/sebdanielsson)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.101.1...v0.102.0)**

### [`v0.101.1`](https://github.com/anchore/grype/releases/tag/v0.101.1)

##### Bug Fixes

- Panic error scanning images with v0.101.0 on some java dependencies \[[#&#8203;3002](https://github.com/anchore/grype/issues/3002)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.101.0...v0.101.1)**

### [`v0.101.0`](https://github.com/anchore/grype/releases/tag/v0.101.0)

##### Added Features

- Add cyclonedx to RpmMetadata \[[#&#8203;2935](https://github.com/anchore/grype/pull/2935) [@&#8203;sfc-gh-rmaj](https://github.com/sfc-gh-rmaj)]
- `grype db search` can filter by fixed state \[[#&#8203;2968](https://github.com/anchore/grype/pull/2968) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- Support using VEX documents with directory scans and SBOMs \[[#&#8203;2471](https://github.com/anchore/grype/issues/2471) [#&#8203;2811](https://github.com/anchore/grype/pull/2811) [@&#8203;alegrey91](https://github.com/alegrey91)]

##### Bug Fixes

- Issue installing Grype using documented curl command \[[#&#8203;2985](https://github.com/anchore/grype/issues/2985)]
- Advisory ID blank in JSON output \[[#&#8203;2965](https://github.com/anchore/grype/issues/2965)]

##### Additional Changes

- update flags with v3 to not use default config \[[#&#8203;3000](https://github.com/anchore/grype/pull/3000) [@&#8203;spiffcs](https://github.com/spiffcs)]
- fix Cosign documentation URL in installer \[[#&#8203;2995](https://github.com/anchore/grype/pull/2995) [@&#8203;lime](https://github.com/lime)]
- set advisory id again \[[#&#8203;2979](https://github.com/anchore/grype/pull/2979) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]
- add db schema validation \[[#&#8203;2962](https://github.com/anchore/grype/pull/2962) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.100.0...v0.101.0)**

### [`v0.100.0`](https://github.com/anchore/grype/releases/tag/v0.100.0)

##### Added Features

- Add unaffected package and CPE stores \[[#&#8203;2888](https://github.com/anchore/grype/pull/2888) [@&#8203;wagoodman](https://github.com/wagoodman)]
- use unaffected match table to remove appropriate vulns \[[#&#8203;2886](https://github.com/anchore/grype/pull/2886) [@&#8203;CrosleyZack](https://github.com/CrosleyZack)]

**[(Full Changelog)](https://github.com/anchore/grype/compare/v0.99.1...v0.100.0)**

</details>

---

### Configuration

📅 **Schedule**: (in timezone Europe/Oslo)

- Branch creation
  - At any time (no schedule defined)
- Automerge
  - At any time (no schedule defined)

🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied.

♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 **Ignore**: Close this PR and you won't be reminded about this update again.

---

 - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box

---

This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate).
<!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->

---------

Co-authored-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: Renovate Bot <renovate@forteapps.net>
Reviewed-on: https://git.forteapps.net/Forte/launchpad/pulls/34
Reviewed-by: Danijel Simeunovic <danijel.simeunovic@fortedigital.com>
Co-authored-by: gitea_admin <admin@forteapps.net>
Co-committed-by: gitea_admin <admin@forteapps.net>
This commit was merged in pull request #34.
This commit is contained in:
2026-09-27 22:15:50 +00:00
committed by danijel.simeunovic
co-authored by danijel.simeunovic Renovate Bot
parent 365661853a
commit 52068dc533
+1 -1
View File
@@ -12,7 +12,7 @@
"kustomize@5.7.0", "kustomize@5.7.0",
"kyverno@1.14.3", "kyverno@1.14.3",
"syft@1.29.0", "syft@1.29.0",
"grype@0.92.2", "grype@0.118.0",
"traefik@3.6.7", "traefik@3.6.7",
"claude-code@0.2.122", "claude-code@0.2.122",
"go@latest", "go@latest",