chore(deps): update dependency grype to v0.118.0 #34

Merged
danijel.simeunovic merged 2 commits from renovate/grype-0.x into main 2026-09-27 22:15:52 +00:00
Owner

This PR contains the following updates:

Package Update Change
grype minor 0.92.2 → 0.118.0

Release Notes

anchore/grype (grype)

v0.118.0

Added Features
Bug Fixes
Dependencies

72 dependency changes (70 updated, 1 added, 1 removed). 3 vulnerabilities remediated.

🟢 Remediated (3)

Updated (70 packages)
  • cel.dev/expr v0.25.1 → v0.25.2
  • cloud.google.com/go/auth v0.18.2 → v0.22.0
  • cloud.google.com/go/iam v1.5.3 → v1.11.0
  • cloud.google.com/go/logging v1.13.1 → v1.18.0
  • cloud.google.com/go/longrunning v0.8.0 → v1.2.0
  • cloud.google.com/go/monitoring v1.24.3 → v1.29.0
  • cloud.google.com/go/storage v1.61.3 → v1.64.0
  • cloud.google.com/go/trace v1.11.7 → v1.16.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.32.0 → v1.33.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.55.0 → v0.57.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock v0.55.0 → v0.57.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0 → v0.57.0
  • github.com/anchore/stereoscope v0.3.0 → v0.3.1
  • github.com/anchore/syft v1.51.0 → v1.51.1
  • github.com/aws/aws-sdk-go-v2 v1.41.5 → v1.43.4
  • github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.8 → v1.7.16
  • github.com/aws/aws-sdk-go-v2/config v1.32.12 → v1.32.35
  • github.com/aws/aws-sdk-go-v2/credentials v1.19.12 → v1.19.34
  • github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.20 → v1.18.35
  • github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.21 → v1.4.35
  • github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.21 → v2.7.35
  • github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.22 → v1.4.36
  • github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.7 → v1.13.15
  • github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.13 → v1.9.28
  • github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.21 → v1.13.35
  • github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.21 → v1.19.36
  • github.com/aws/aws-sdk-go-v2/service/s3 v1.97.3 → v1.106.5
  • github.com/aws/aws-sdk-go-v2/service/signin v1.0.8 → v1.5.4
  • github.com/aws/aws-sdk-go-v2/service/sso v1.30.13 → v1.33.4
  • github.com/aws/aws-sdk-go-v2/service/ssooidc v1.35.17 → v1.38.4
  • github.com/aws/aws-sdk-go-v2/service/sts v1.41.9 → v1.45.4
  • github.com/aws/smithy-go v1.24.2 → v1.27.6
  • github.com/containerd/containerd/v2 v2.3.3 → v2.3.4
  • github.com/containerd/platforms v1.0.0-rc.4 → v1.0.0-rc.5
  • github.com/docker/cli v29.6.1+incompatible → v29.7.2+incompatible
  • github.com/docker/go-connections v0.7.0 → v0.8.1
  • github.com/fatih/color v1.18.0 → v1.19.0
  • github.com/google/go-containerregistry v0.21.7 → v0.21.9
  • github.com/google/pprof v0.0.0-6e76a2b → v0.0.0-ef3492d
  • github.com/googleapis/enterprise-certificate-proxy v0.3.14 → v0.3.19
  • github.com/googleapis/gax-go/v2 v2.17.0 → v2.23.0
  • github.com/hashicorp/aws-sdk-go-base/v2 v2.0.0-beta.72 → v2.0.0-beta.74
  • github.com/hashicorp/go-getter v1.8.6 → v1.8.8
  • github.com/hashicorp/go-version v1.8.0 → v1.9.0
  • github.com/klauspost/compress v1.19.1 → v1.19.2
  • github.com/mattn/go-isatty v0.0.20 → v0.0.24
  • github.com/moby/moby/client v0.5.0 → v0.5.1
  • github.com/spiffe/go-spiffe/v2 v2.6.0 → v2.7.0
  • github.com/stretchr/objx v0.5.2 → v0.5.3
  • github.com/stretchr/testify v1.11.1 → v1.12.1
  • go.opentelemetry.io/contrib/detectors/gcp v1.43.0 → v1.44.0
  • go.opentelemetry.io/otel v1.43.0 → v1.44.0 (🟢 remediated GO-2026-5158)
  • go.opentelemetry.io/otel/exporters/stdout/stdoutmetric v1.40.0 → v1.44.0
  • go.opentelemetry.io/otel/metric v1.43.0 → v1.44.0
  • go.opentelemetry.io/otel/sdk v1.43.0 → v1.44.0
  • go.opentelemetry.io/otel/sdk/metric v1.43.0 → v1.44.0
  • go.opentelemetry.io/otel/trace v1.43.0 → v1.44.0
  • golang.org/x/crypto v0.54.0 → v0.55.0
  • golang.org/x/mod v0.38.0 → v0.40.0 (🟢 remediated GO-2026-6179, GO-2026-6180)
  • golang.org/x/net v0.57.0 → v0.58.0
  • golang.org/x/text v0.40.0 → v0.41.0
  • golang.org/x/tools v0.48.0 → v0.49.0
  • google.golang.org/api v0.271.0 → v0.292.0
  • google.golang.org/genproto v0.0.0-8636f87 → v0.0.0-aa98bba
  • google.golang.org/genproto/googleapis/api v0.0.0-afd174a → v0.0.0-925bb5d
  • google.golang.org/genproto/googleapis/rpc v0.0.0-afd174a → v0.0.0-6ac0973
  • google.golang.org/grpc v1.82.1 → v1.83.0
  • modernc.org/cc/v4 v4.29.0 → v4.29.1
  • modernc.org/libc v1.74.1 → v1.74.4
  • modernc.org/sqlite v1.55.0 → v1.56.0
Added (1 package)
  • go.opentelemetry.io/otel/metric/x v0.66.0
Removed (1 package)
  • github.com/aws/aws-sdk-go-v2/internal/ini v1.8.6

(Full Changelog)

v0.117.0

Added Features
Bug Fixes
Dependencies

11 dependency changes (11 updated). 2 vulnerabilities remediated.

🟢 Remediated (2)

Updated (11 packages)
  • github.com/anchore/syft v1.50.0 → v1.51.0
  • github.com/diskfs/go-diskfs v1.9.3 → v1.9.4
  • github.com/gabriel-vasile/mimetype v1.4.13 → v1.4.15
  • github.com/go-git/go-billy/v5 v5.9.0 → v5.9.1
  • github.com/go-git/go-git/v5 v5.19.1 → v5.19.2 (🟢 remediated GHSA-hc8v-wwc9-vgxm, GHSA-qgq7-7hm3-q39j)
  • github.com/klauspost/compress v1.19.0 → v1.19.1
  • github.com/magiconair/properties v1.8.10 → v1.18.11
  • github.com/santhosh-tekuri/jsonschema/v6 v6.0.2 → v6.0.3
  • github.com/ulikunitz/xz v0.5.15 → v0.5.16
  • go.yaml.in/yaml/v3 v3.0.4 → v3.0.5
  • modernc.org/sqlite v1.54.0 → v1.55.0

(Full Changelog)

v0.116.1

Bug Fixes
Dependencies

30 dependency changes (30 updated). 1 vulnerability remediated.

🟢 Remediated (1)

Updated (30 packages)
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.31.0 → v1.32.0
  • github.com/anchore/stereoscope v0.2.2 → v0.3.0
  • github.com/anchore/syft v1.48.0 → v1.50.0
  • github.com/cncf/xds/go v0.0.0-ee656c7 → v0.0.0-dba9d58
  • github.com/containerd/containerd/v2 v2.3.2 → v2.3.3
  • github.com/docker/cli v29.5.3+incompatible → v29.6.1+incompatible
  • github.com/envoyproxy/go-control-plane/envoy v1.36.0 → v1.37.0
  • github.com/envoyproxy/protoc-gen-validate v1.3.0 → v1.3.3
  • github.com/gkampitakis/go-snaps v0.5.22 → v0.5.23
  • github.com/gpustack/gguf-parser-go v0.24.1 → v0.25.0
  • github.com/moby/moby/api v1.54.2 → v1.55.0
  • github.com/moby/moby/client v0.4.1 → v0.5.0
  • github.com/pelletier/go-toml/v2 v2.3.1 → v2.4.3
  • go.opentelemetry.io/contrib/detectors/gcp v1.39.0 → v1.43.0
  • golang.org/x/crypto v0.53.0 → v0.54.0
  • golang.org/x/mod v0.37.0 → v0.38.0
  • golang.org/x/net v0.56.0 → v0.57.0
  • golang.org/x/sync v0.21.0 → v0.22.0
  • golang.org/x/sys v0.46.0 → v0.47.0
  • golang.org/x/term v0.44.0 → v0.45.0
  • golang.org/x/text v0.39.0 → v0.40.0
  • golang.org/x/tools v0.47.0 → v0.48.0
  • google.golang.org/genproto/googleapis/api v0.0.0-9d38bb4 → v0.0.0-afd174a
  • google.golang.org/genproto/googleapis/rpc v0.0.0-6f92a3b → v0.0.0-afd174a
  • google.golang.org/grpc v1.80.0 → v1.82.1 (🟢 remediated GHSA-hrxh-6v49-42gf)
  • modernc.org/cc/v4 v4.28.4 → v4.29.0
  • modernc.org/ccgo/v4 v4.34.4 → v4.34.6
  • modernc.org/gc/v3 v3.1.3 → v3.1.4
  • modernc.org/libc v1.73.4 → v1.74.1
  • modernc.org/sqlite v1.53.0 → v1.54.0

(Full Changelog)

v0.115.0

Added Features
Bug Fixes
Additional Changes
  • Security: bump golang.org/x/crypto to v0.52.0 to resolve multiple CVEs [Issue #​3493]
  • Security: bump golang.org/x/net to v0.55.0 to resolve CVEs [Issue #​3494]
Dependencies

35 dependency changes (31 updated, 3 added, 1 removed). 5 vulnerabilities remediated.

🟢 Remediated (5)

Updated (31 packages)
  • github.com/ProtonMail/go-crypto v1.4.0 → v1.4.1
  • github.com/anchore/bubbly v0.2.0 → v0.2.1
  • github.com/anchore/clio v0.1.0 → v0.1.1
  • github.com/anchore/fangs v0.1.0 → v0.1.1
  • github.com/anchore/go-collections v0.1.0 → v0.1.1
  • github.com/anchore/go-homedir v0.1.0 → v0.1.1
  • github.com/anchore/go-logger v0.1.0 → v0.1.1
  • github.com/anchore/go-lzo v0.1.0 → v0.1.1
  • github.com/anchore/go-macholibre v0.1.0 → v0.1.1
  • github.com/anchore/go-make v0.5.0 → v0.8.0
  • github.com/anchore/go-struct-converter v0.1.0 → v0.2.0-rc2
  • github.com/anchore/go-sync v0.1.0 → v0.1.1
  • github.com/anchore/stereoscope v0.2.1 → v0.2.2
  • github.com/anchore/syft v1.45.1 → v1.46.0
  • github.com/charmbracelet/colorprofile v0.4.1 → v0.4.3
  • github.com/clipperhouse/displaywidth v0.10.0 → v0.11.0
  • github.com/clipperhouse/uax29/v2 v2.6.0 → v2.7.0
  • github.com/containerd/containerd/v2 v2.3.1 → v2.3.2 (🟢 remediated GHSA-33vj-92qq-66hc, GHSA-cvxm-645q-p574, GHSA-jpcc-p29g-p8mq, GHSA-rgh6-rfwx-v388, GHSA-xhf5-7wjv-pqxp)
  • github.com/docker/cli v29.4.3+incompatible → v29.5.3+incompatible
  • github.com/google/go-containerregistry v0.21.6 → v0.21.7
  • github.com/mattn/go-runewidth v0.0.19 → v0.0.21
  • github.com/spdx/tools-golang v0.5.7 → v0.6.0-rc4
  • github.com/sylabs/sif/v2 v2.24.0 → v2.24.1
  • golang.org/x/crypto v0.52.0 → v0.53.0
  • golang.org/x/mod v0.36.0 → v0.37.0
  • golang.org/x/net v0.55.0 → v0.56.0
  • golang.org/x/sync v0.20.0 → v0.21.0
  • golang.org/x/sys v0.45.0 → v0.46.0
  • golang.org/x/term v0.43.0 → v0.44.0
  • golang.org/x/text v0.37.0 → v0.38.0
  • golang.org/x/tools v0.45.0 → v0.46.0
Added (3 packages)
  • github.com/piprate/json-gold v0.7.0
  • github.com/pquerna/cachecontrol v0.0.0-1555304
  • github.com/tailscale/hujson v0.0.0-ecc657c
Removed (1 package)
  • github.com/google/osv-scanner v1.9.2

(Full Changelog)

v0.114.0

Added Features
Additional Changes

(Full Changelog)

v0.113.0

Added Features
Bug Fixes

(Full Changelog)

v0.112.0

Added Features
Additional Changes

(Full Changelog)

v0.111.1

Bug Fixes

(Full Changelog)

v0.108.0

Added Features
Bug Fixes
Additional Changes

(Full Changelog)

v0.105.0

Added Features

(Full Changelog)

v0.104.4

Bug Fixes
Additional Changes

(Full Changelog)

v0.104.3

Bug Fixes

(Full Changelog)

v0.104.2

Bug Fixes
Additional Changes

(Full Changelog)

v0.104.1

Bug Fixes
Additional Changes

(Full Changelog)

v0.104.0

Added Features
Bug Fixes
Additional Changes

(Full Changelog)

v0.103.0

Added Features

(Full Changelog)

v0.102.0

Added Features
Bug Fixes
  • Bitnami packages with CPEs are not matched against CPE-based vulnerabilities [#​2997]
Additional Changes

(Full Changelog)

v0.101.1

Bug Fixes
  • Panic error scanning images with v0.101.0 on some java dependencies [#​3002]

(Full Changelog)

v0.101.0

Added Features
Bug Fixes
  • Issue installing Grype using documented curl command [#​2985]
  • Advisory ID blank in JSON output [#​2965]
Additional Changes

(Full Changelog)

v0.100.0

Added Features

(Full Changelog)


Configuration

📅 Schedule: (in timezone Europe/Oslo)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate CLI.

This PR contains the following updates: | Package | Update | Change | |---|---|---| | [grype](https://github.com/anchore/grype) | minor | `0.92.2` → `0.118.0` | --- ### Release Notes <details> <summary>anchore/grype (grype)</summary> ### [`v0.118.0`](https://github.com/anchore/grype/releases/tag/v0.118.0) ##### Added Features - apk matcher does alias aware aggregation \[PR [#&#8203;3634](https://github.com/anchore/grype/pull/3634) [@&#8203;crosleyzack](https://github.com/crosleyzack)] ##### Bug Fixes - prevent panic on portage versions without digits \[PR [#&#8203;3655](https://github.com/anchore/grype/pull/3655) [@&#8203;ashvinctrl](https://github.com/ashvinctrl)] - grype vex does not match oci purl with repository\_url \[Issue [#&#8203;3657](https://github.com/anchore/grype/issues/3657)] \[PR [#&#8203;3659](https://github.com/anchore/grype/pull/3659) [@&#8203;spiffcs](https://github.com/spiffcs)] - Old JVM version comparisons sometimes incorrect \[Issue [#&#8203;2701](https://github.com/anchore/grype/issues/2701)] \[PR [#&#8203;3583](https://github.com/anchore/grype/pull/3583) [@&#8203;Eljees](https://github.com/Eljees)] - CVSSv4 calculation can produce incorrect vulnerability severity \[Issue [#&#8203;3656](https://github.com/anchore/grype/issues/3656)] - Grype 0.90.0 DB update failed \[Issue [#&#8203;3629](https://github.com/anchore/grype/issues/3629)] ##### Dependencies 72 dependency changes (70 updated, 1 added, 1 removed). 3 vulnerabilities remediated. **🟢 Remediated (3)** - [GO-2026-5158](https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835) (Medium) — go.opentelemetry.io/otel - [GO-2026-6179](https://go.dev/issue/80744) (High) — golang.org/x/mod - [GO-2026-6180](https://go.dev/issue/80745) (High) — golang.org/x/mod <details> <summary>Updated (70 packages)</summary> - cel.dev/expr `v0.25.1` → `v0.25.2` - cloud.google.com/go/auth `v0.18.2` → `v0.22.0` - cloud.google.com/go/iam `v1.5.3` → `v1.11.0` - cloud.google.com/go/logging `v1.13.1` → `v1.18.0` - cloud.google.com/go/longrunning `v0.8.0` → `v1.2.0` - cloud.google.com/go/monitoring `v1.24.3` → `v1.29.0` - cloud.google.com/go/storage `v1.61.3` → `v1.64.0` - cloud.google.com/go/trace `v1.11.7` → `v1.16.0` - github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp `v1.32.0` → `v1.33.0` - github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric `v0.55.0` → `v0.57.0` - github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock `v0.55.0` → `v0.57.0` - github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping `v0.55.0` → `v0.57.0` - github.com/anchore/stereoscope `v0.3.0` → `v0.3.1` - github.com/anchore/syft `v1.51.0` → `v1.51.1` - github.com/aws/aws-sdk-go-v2 `v1.41.5` → `v1.43.4` - github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream `v1.7.8` → `v1.7.16` - github.com/aws/aws-sdk-go-v2/config `v1.32.12` → `v1.32.35` - github.com/aws/aws-sdk-go-v2/credentials `v1.19.12` → `v1.19.34` - github.com/aws/aws-sdk-go-v2/feature/ec2/imds `v1.18.20` → `v1.18.35` - github.com/aws/aws-sdk-go-v2/internal/configsources `v1.4.21` → `v1.4.35` - github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 `v2.7.21` → `v2.7.35` - github.com/aws/aws-sdk-go-v2/internal/v4a `v1.4.22` → `v1.4.36` - github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding `v1.13.7` → `v1.13.15` - github.com/aws/aws-sdk-go-v2/service/internal/checksum `v1.9.13` → `v1.9.28` - github.com/aws/aws-sdk-go-v2/service/internal/presigned-url `v1.13.21` → `v1.13.35` - github.com/aws/aws-sdk-go-v2/service/internal/s3shared `v1.19.21` → `v1.19.36` - github.com/aws/aws-sdk-go-v2/service/s3 `v1.97.3` → `v1.106.5` - github.com/aws/aws-sdk-go-v2/service/signin `v1.0.8` → `v1.5.4` - github.com/aws/aws-sdk-go-v2/service/sso `v1.30.13` → `v1.33.4` - github.com/aws/aws-sdk-go-v2/service/ssooidc `v1.35.17` → `v1.38.4` - github.com/aws/aws-sdk-go-v2/service/sts `v1.41.9` → `v1.45.4` - github.com/aws/smithy-go `v1.24.2` → `v1.27.6` - github.com/containerd/containerd/v2 `v2.3.3` → `v2.3.4` - github.com/containerd/platforms `v1.0.0-rc.4` → `v1.0.0-rc.5` - github.com/docker/cli `v29.6.1+incompatible` → `v29.7.2+incompatible` - github.com/docker/go-connections `v0.7.0` → `v0.8.1` - github.com/fatih/color `v1.18.0` → `v1.19.0` - github.com/google/go-containerregistry `v0.21.7` → `v0.21.9` - github.com/google/pprof `v0.0.0-6e76a2b` → `v0.0.0-ef3492d` - github.com/googleapis/enterprise-certificate-proxy `v0.3.14` → `v0.3.19` - github.com/googleapis/gax-go/v2 `v2.17.0` → `v2.23.0` - github.com/hashicorp/aws-sdk-go-base/v2 `v2.0.0-beta.72` → `v2.0.0-beta.74` - github.com/hashicorp/go-getter `v1.8.6` → `v1.8.8` - github.com/hashicorp/go-version `v1.8.0` → `v1.9.0` - github.com/klauspost/compress `v1.19.1` → `v1.19.2` - github.com/mattn/go-isatty `v0.0.20` → `v0.0.24` - github.com/moby/moby/client `v0.5.0` → `v0.5.1` - github.com/spiffe/go-spiffe/v2 `v2.6.0` → `v2.7.0` - github.com/stretchr/objx `v0.5.2` → `v0.5.3` - github.com/stretchr/testify `v1.11.1` → `v1.12.1` - go.opentelemetry.io/contrib/detectors/gcp `v1.43.0` → `v1.44.0` - go.opentelemetry.io/otel `v1.43.0` → `v1.44.0` **(🟢 remediated [GO-2026-5158](https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-5wrp-cwcj-q835))** - go.opentelemetry.io/otel/exporters/stdout/stdoutmetric `v1.40.0` → `v1.44.0` - go.opentelemetry.io/otel/metric `v1.43.0` → `v1.44.0` - go.opentelemetry.io/otel/sdk `v1.43.0` → `v1.44.0` - go.opentelemetry.io/otel/sdk/metric `v1.43.0` → `v1.44.0` - go.opentelemetry.io/otel/trace `v1.43.0` → `v1.44.0` - golang.org/x/crypto `v0.54.0` → `v0.55.0` - golang.org/x/mod `v0.38.0` → `v0.40.0` **(🟢 remediated [GO-2026-6179](https://go.dev/issue/80744), [GO-2026-6180](https://go.dev/issue/80745))** - golang.org/x/net `v0.57.0` → `v0.58.0` - golang.org/x/text `v0.40.0` → `v0.41.0` - golang.org/x/tools `v0.48.0` → `v0.49.0` - google.golang.org/api `v0.271.0` → `v0.292.0` - google.golang.org/genproto `v0.0.0-8636f87` → `v0.0.0-aa98bba` - google.golang.org/genproto/googleapis/api `v0.0.0-afd174a` → `v0.0.0-925bb5d` - google.golang.org/genproto/googleapis/rpc `v0.0.0-afd174a` → `v0.0.0-6ac0973` - google.golang.org/grpc `v1.82.1` → `v1.83.0` - modernc.org/cc/v4 `v4.29.0` → `v4.29.1` - modernc.org/libc `v1.74.1` → `v1.74.4` - modernc.org/sqlite `v1.55.0` → `v1.56.0` </details> <details> <summary>Added (1 package)</summary> - go.opentelemetry.io/otel/metric/x `v0.66.0` </details> <details> <summary>Removed (1 package)</summary> - github.com/aws/aws-sdk-go-v2/internal/ini `v1.8.6` </details> **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.117.0...v0.118.0)** ### [`v0.117.0`](https://github.com/anchore/grype/releases/tag/v0.117.0) ##### Added Features - Include vulnerable ranges in CycloneDX output format \[Issue [#&#8203;3512](https://github.com/anchore/grype/issues/3512)] \[PR [#&#8203;3519](https://github.com/anchore/grype/pull/3519) [@&#8203;somaz94](https://github.com/somaz94)] ##### Bug Fixes - honor match.rust.using-cpes configuration \[PR [#&#8203;3611](https://github.com/anchore/grype/pull/3611) [@&#8203;Dashtid](https://github.com/Dashtid)] ##### Dependencies 11 dependency changes (11 updated). 2 vulnerabilities remediated. **🟢 Remediated (2)** - [GHSA-hc8v-wwc9-vgxm](https://github.com/advisories/GHSA-hc8v-wwc9-vgxm) (High) — github.com/go-git/go-git/v5 - [GHSA-qgq7-7hm3-q39j](https://github.com/advisories/GHSA-qgq7-7hm3-q39j) (Medium) — github.com/go-git/go-git/v5 <details> <summary>Updated (11 packages)</summary> - github.com/anchore/syft `v1.50.0` → `v1.51.0` - github.com/diskfs/go-diskfs `v1.9.3` → `v1.9.4` - github.com/gabriel-vasile/mimetype `v1.4.13` → `v1.4.15` - github.com/go-git/go-billy/v5 `v5.9.0` → `v5.9.1` - github.com/go-git/go-git/v5 `v5.19.1` → `v5.19.2` **(🟢 remediated [GHSA-hc8v-wwc9-vgxm](https://github.com/advisories/GHSA-hc8v-wwc9-vgxm), [GHSA-qgq7-7hm3-q39j](https://github.com/advisories/GHSA-qgq7-7hm3-q39j))** - github.com/klauspost/compress `v1.19.0` → `v1.19.1` - github.com/magiconair/properties `v1.8.10` → `v1.18.11` - github.com/santhosh-tekuri/jsonschema/v6 `v6.0.2` → `v6.0.3` - github.com/ulikunitz/xz `v0.5.15` → `v0.5.16` - go.yaml.in/yaml/v3 `v3.0.4` → `v3.0.5` - modernc.org/sqlite `v1.54.0` → `v1.55.0` </details> **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.116.1...v0.117.0)** ### [`v0.116.1`](https://github.com/anchore/grype/releases/tag/v0.116.1) ##### Bug Fixes - Ensure channel parsing is consistent \[PR [#&#8203;3603](https://github.com/anchore/grype/pull/3603) [@&#8203;wagoodman](https://github.com/wagoodman)] - Scope Go GHSA twins by shared CVE \[PR [#&#8203;3592](https://github.com/anchore/grype/pull/3592) [@&#8203;wagoodman](https://github.com/wagoodman)] - do not cache a comparator that failed to build \[PR [#&#8203;3567](https://github.com/anchore/grype/pull/3567) [@&#8203;arpitjain099](https://github.com/arpitjain099)] - Add fix date to rhel minor records created from rhsa \[PR [#&#8203;3585](https://github.com/anchore/grype/pull/3585) [@&#8203;wagoodman](https://github.com/wagoodman)] - grype reporting CVE-64091 as critical - redhat says it is not affected \[Issue [#&#8203;3591](https://github.com/anchore/grype/issues/3591)] - panic: index out of range in distro.parseVersion for VERSION\_ID=v \[Issue [#&#8203;3588](https://github.com/anchore/grype/issues/3588)] \[PR [#&#8203;3589](https://github.com/anchore/grype/pull/3589) [@&#8203;matiasinsaurralde](https://github.com/matiasinsaurralde)] - False Positive: GO-2026-5932 \[Issue [#&#8203;3573](https://github.com/anchore/grype/issues/3573)] ##### Dependencies 30 dependency changes (30 updated). 1 vulnerability remediated. **🟢 Remediated (1)** - [GHSA-hrxh-6v49-42gf](https://github.com/advisories/GHSA-hrxh-6v49-42gf) (High) — google.golang.org/grpc <details> <summary>Updated (30 packages)</summary> - github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp `v1.31.0` → `v1.32.0` - github.com/anchore/stereoscope `v0.2.2` → `v0.3.0` - github.com/anchore/syft `v1.48.0` → `v1.50.0` - github.com/cncf/xds/go `v0.0.0-ee656c7` → `v0.0.0-dba9d58` - github.com/containerd/containerd/v2 `v2.3.2` → `v2.3.3` - github.com/docker/cli `v29.5.3+incompatible` → `v29.6.1+incompatible` - github.com/envoyproxy/go-control-plane/envoy `v1.36.0` → `v1.37.0` - github.com/envoyproxy/protoc-gen-validate `v1.3.0` → `v1.3.3` - github.com/gkampitakis/go-snaps `v0.5.22` → `v0.5.23` - github.com/gpustack/gguf-parser-go `v0.24.1` → `v0.25.0` - github.com/moby/moby/api `v1.54.2` → `v1.55.0` - github.com/moby/moby/client `v0.4.1` → `v0.5.0` - github.com/pelletier/go-toml/v2 `v2.3.1` → `v2.4.3` - go.opentelemetry.io/contrib/detectors/gcp `v1.39.0` → `v1.43.0` - golang.org/x/crypto `v0.53.0` → `v0.54.0` - golang.org/x/mod `v0.37.0` → `v0.38.0` - golang.org/x/net `v0.56.0` → `v0.57.0` - golang.org/x/sync `v0.21.0` → `v0.22.0` - golang.org/x/sys `v0.46.0` → `v0.47.0` - golang.org/x/term `v0.44.0` → `v0.45.0` - golang.org/x/text `v0.39.0` → `v0.40.0` - golang.org/x/tools `v0.47.0` → `v0.48.0` - google.golang.org/genproto/googleapis/api `v0.0.0-9d38bb4` → `v0.0.0-afd174a` - google.golang.org/genproto/googleapis/rpc `v0.0.0-6f92a3b` → `v0.0.0-afd174a` - google.golang.org/grpc `v1.80.0` → `v1.82.1` **(🟢 remediated [GHSA-hrxh-6v49-42gf](https://github.com/advisories/GHSA-hrxh-6v49-42gf))** - modernc.org/cc/v4 `v4.28.4` → `v4.29.0` - modernc.org/ccgo/v4 `v4.34.4` → `v4.34.6` - modernc.org/gc/v3 `v3.1.3` → `v3.1.4` - modernc.org/libc `v1.73.4` → `v1.74.1` - modernc.org/sqlite `v1.53.0` → `v1.54.0` </details> **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.116.0...v0.116.1)** ### [`v0.115.0`](https://github.com/anchore/grype/releases/tag/v0.115.0) ##### Added Features - emit golang.org/x/net vulns from govlundb \[PR [#&#8203;3534](https://github.com/anchore/grype/pull/3534) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - Merge Go vuln matches with GHSA matches \[Issue [#&#8203;3515](https://github.com/anchore/grype/issues/3515)] ##### Bug Fixes - only emit records for stdlib \[PR [#&#8203;3527](https://github.com/anchore/grype/pull/3527) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - mark hummingbird distro as rolling \[PR [#&#8203;3521](https://github.com/anchore/grype/pull/3521) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - disable go stdlib CPE matching by default \[PR [#&#8203;3517](https://github.com/anchore/grype/pull/3517) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - merge in custom ranges when applicable \[PR [#&#8203;3514](https://github.com/anchore/grype/pull/3514) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - exclude linux-kbuild deb indirect matches by default \[PR [#&#8203;3506](https://github.com/anchore/grype/pull/3506) [@&#8203;westonsteimel](https://github.com/westonsteimel)] - avoid panic on invalid RHEL version IDs \[PR [#&#8203;3490](https://github.com/anchore/grype/pull/3490) [@&#8203;jspilman](https://github.com/jspilman)] - Support reading CycloneDX 1.7 SBOMs \[Issue [#&#8203;3373](https://github.com/anchore/grype/issues/3373)] - Grype cannot read mariadb version correctly \[Issue [#&#8203;3452](https://github.com/anchore/grype/issues/3452)] - grype hangs when downloading certain images using registry client \[Issue [#&#8203;3492](https://github.com/anchore/grype/issues/3492)] - Can we get a fix for these Critical findings reported for grype \[Issue [#&#8203;3484](https://github.com/anchore/grype/issues/3484)] ##### Additional Changes - Security: bump golang.org/x/crypto to v0.52.0 to resolve multiple CVEs \[Issue [#&#8203;3493](https://github.com/anchore/grype/issues/3493)] - Security: bump golang.org/x/net to v0.55.0 to resolve CVEs \[Issue [#&#8203;3494](https://github.com/anchore/grype/issues/3494)] ##### Dependencies 35 dependency changes (31 updated, 3 added, 1 removed). 5 vulnerabilities remediated. **🟢 Remediated (5)** - [GHSA-33vj-92qq-66hc](https://github.com/advisories/GHSA-33vj-92qq-66hc) (High) — github.com/containerd/containerd/v2 - [GHSA-cvxm-645q-p574](https://github.com/advisories/GHSA-cvxm-645q-p574) (Medium) — github.com/containerd/containerd/v2 - [GHSA-jpcc-p29g-p8mq](https://github.com/advisories/GHSA-jpcc-p29g-p8mq) (Medium) — github.com/containerd/containerd/v2 - [GHSA-rgh6-rfwx-v388](https://github.com/advisories/GHSA-rgh6-rfwx-v388) (High) — github.com/containerd/containerd/v2 - [GHSA-xhf5-7wjv-pqxp](https://github.com/advisories/GHSA-xhf5-7wjv-pqxp) (High) — github.com/containerd/containerd/v2 <details> <summary>Updated (31 packages)</summary> - github.com/ProtonMail/go-crypto `v1.4.0` → `v1.4.1` - github.com/anchore/bubbly `v0.2.0` → `v0.2.1` - github.com/anchore/clio `v0.1.0` → `v0.1.1` - github.com/anchore/fangs `v0.1.0` → `v0.1.1` - github.com/anchore/go-collections `v0.1.0` → `v0.1.1` - github.com/anchore/go-homedir `v0.1.0` → `v0.1.1` - github.com/anchore/go-logger `v0.1.0` → `v0.1.1` - github.com/anchore/go-lzo `v0.1.0` → `v0.1.1` - github.com/anchore/go-macholibre `v0.1.0` → `v0.1.1` - github.com/anchore/go-make `v0.5.0` → `v0.8.0` - github.com/anchore/go-struct-converter `v0.1.0` → `v0.2.0-rc2` - github.com/anchore/go-sync `v0.1.0` → `v0.1.1` - github.com/anchore/stereoscope `v0.2.1` → `v0.2.2` - github.com/anchore/syft `v1.45.1` → `v1.46.0` - github.com/charmbracelet/colorprofile `v0.4.1` → `v0.4.3` - github.com/clipperhouse/displaywidth `v0.10.0` → `v0.11.0` - github.com/clipperhouse/uax29/v2 `v2.6.0` → `v2.7.0` - github.com/containerd/containerd/v2 `v2.3.1` → `v2.3.2` **(🟢 remediated [GHSA-33vj-92qq-66hc](https://github.com/advisories/GHSA-33vj-92qq-66hc), [GHSA-cvxm-645q-p574](https://github.com/advisories/GHSA-cvxm-645q-p574), [GHSA-jpcc-p29g-p8mq](https://github.com/advisories/GHSA-jpcc-p29g-p8mq), [GHSA-rgh6-rfwx-v388](https://github.com/advisories/GHSA-rgh6-rfwx-v388), [GHSA-xhf5-7wjv-pqxp](https://github.com/advisories/GHSA-xhf5-7wjv-pqxp))** - github.com/docker/cli `v29.4.3+incompatible` → `v29.5.3+incompatible` - github.com/google/go-containerregistry `v0.21.6` → `v0.21.7` - github.com/mattn/go-runewidth `v0.0.19` → `v0.0.21` - github.com/spdx/tools-golang `v0.5.7` → `v0.6.0-rc4` - github.com/sylabs/sif/v2 `v2.24.0` → `v2.24.1` - golang.org/x/crypto `v0.52.0` → `v0.53.0` - golang.org/x/mod `v0.36.0` → `v0.37.0` - golang.org/x/net `v0.55.0` → `v0.56.0` - golang.org/x/sync `v0.20.0` → `v0.21.0` - golang.org/x/sys `v0.45.0` → `v0.46.0` - golang.org/x/term `v0.43.0` → `v0.44.0` - golang.org/x/text `v0.37.0` → `v0.38.0` - golang.org/x/tools `v0.45.0` → `v0.46.0` </details> <details> <summary>Added (3 packages)</summary> - github.com/piprate/json-gold `v0.7.0` - github.com/pquerna/cachecontrol `v0.0.0-1555304` - github.com/tailscale/hujson `v0.0.0-ecc657c` </details> <details> <summary>Removed (1 package)</summary> - github.com/google/osv-scanner `v1.9.2` </details> **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.114.0...v0.115.0)** ### [`v0.114.0`](https://github.com/anchore/grype/releases/tag/v0.114.0) ##### Added Features - Add ability to scan zarf packages \[[#&#8203;3329](https://github.com/anchore/grype/issues/3329) [#&#8203;3366](https://github.com/anchore/grype/pull/3366) [@&#8203;brandtkeller](https://github.com/brandtkeller)] ##### Additional Changes - respect withdrawn status of Go Vuln DB OSV records \[[#&#8203;3495](https://github.com/anchore/grype/pull/3495) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - Govulndb OSV transformer \[[#&#8203;3485](https://github.com/anchore/grype/pull/3485) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.113.0...v0.114.0)** ### [`v0.113.0`](https://github.com/anchore/grype/releases/tag/v0.113.0) ##### Added Features - Include Ubuntu 26.04 "resolute" in distro codenames \[[#&#8203;3397](https://github.com/anchore/grype/pull/3397) [@&#8203;anchore-oss-update-bot](https://github.com/anchore-oss-update-bot)] - source RPM filtering on Hummingbird \[[#&#8203;3410](https://github.com/anchore/grype/pull/3410) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] ##### Bug Fixes - use relatedVulnerabilities description as fallback in SARIF output \[[#&#8203;3271](https://github.com/anchore/grype/pull/3271) [@&#8203;axidex](https://github.com/axidex)] - improve platform CPE determination logic \[[#&#8203;3470](https://github.com/anchore/grype/pull/3470) [@&#8203;westonsteimel](https://github.com/westonsteimel)] - normalize uppercase V in semantic version comparison \[[#&#8203;3461](https://github.com/anchore/grype/pull/3461) [@&#8203;immanuwell](https://github.com/immanuwell)] - purl handling in cgr maven libs \[[#&#8203;3420](https://github.com/anchore/grype/pull/3420) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - Treat uppercase V prefixes the same as lowercase v prefixes in fuzzy version comparison \[[#&#8203;3037](https://github.com/anchore/grype/issues/3037) [#&#8203;3089](https://github.com/anchore/grype/pull/3089) [@&#8203;wasup-yash](https://github.com/wasup-yash)] - Add Runtime Warnings When TLS Verification Is Disabled or HTTP Is Enabled \[[#&#8203;3101](https://github.com/anchore/grype/issues/3101) [#&#8203;3396](https://github.com/anchore/grype/pull/3396) [@&#8203;Dashtid](https://github.com/Dashtid)] - Add support for the aarch64 architecture when parsing the version of Ruby gems in lockfiles \[[#&#8203;3442](https://github.com/anchore/grype/issues/3442) [#&#8203;3475](https://github.com/anchore/grype/pull/3475) [@&#8203;msnandhis](https://github.com/msnandhis)] - zsh completion fails \[[#&#8203;2933](https://github.com/anchore/grype/issues/2933) [#&#8203;3433](https://github.com/anchore/grype/pull/3433) [@&#8203;brandtkeller](https://github.com/brandtkeller)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.112.0...v0.113.0)** ### [`v0.112.0`](https://github.com/anchore/grype/releases/tag/v0.112.0) ##### Added Features - Expand ignore rules to owned sub packages of distro packages \[[#&#8203;3368](https://github.com/anchore/grype/issues/3368) [#&#8203;3326](https://github.com/anchore/grype/pull/3326) [@&#8203;kzantow](https://github.com/kzantow)] ##### Additional Changes - update anchore dependencies \[[#&#8203;3391](https://github.com/anchore/grype/pull/3391) [@&#8203;anchore-oss-update-bot](https://github.com/anchore-oss-update-bot)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.111.1...v0.112.0)** ### [`v0.111.1`](https://github.com/anchore/grype/releases/tag/v0.111.1) ##### Bug Fixes - apply overlap by ownership removal to dynamically created relationships \[[#&#8203;3363](https://github.com/anchore/grype/pull/3363) [@&#8203;kzantow](https://github.com/kzantow)] - compare mismatched package / db versions \[[#&#8203;3372](https://github.com/anchore/grype/pull/3372) [@&#8203;kzantow](https://github.com/kzantow)] - Grype doesn't recognize debian component when `"group" : "debian"` is specified \[[#&#8203;2967](https://github.com/anchore/grype/issues/2967)] - HelpURI missing information in SARIF output \[[#&#8203;2874](https://github.com/anchore/grype/issues/2874) [#&#8203;3351](https://github.com/anchore/grype/pull/3351) [@&#8203;will-bates11](https://github.com/will-bates11)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.111.0...v0.111.1)** ### [`v0.108.0`](https://github.com/anchore/grype/releases/tag/v0.108.0) ##### Added Features - enable disabling EOL warnings \[[#&#8203;3204](https://github.com/anchore/grype/pull/3204) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] ##### Bug Fixes - fix fallback on major only distro \[[#&#8203;3213](https://github.com/anchore/grype/pull/3213) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - VEX Documents still not working with syft sbom \[[#&#8203;3167](https://github.com/anchore/grype/issues/3167)] - VEX: minimal OpenVEX Example not working \[[#&#8203;3212](https://github.com/anchore/grype/issues/3212)] ##### Additional Changes - support more accurate scanning for postmarketos \[[#&#8203;3182](https://github.com/anchore/grype/pull/3182) [@&#8203;westonsteimel](https://github.com/westonsteimel)] - charmbracelet/bubbletea erases grype ui status line \[[#&#8203;3214](https://github.com/anchore/grype/pull/3214) [@&#8203;spiffcs](https://github.com/spiffcs)] - bump labels and add several test images \[[#&#8203;3215](https://github.com/anchore/grype/pull/3215) [@&#8203;westonsteimel](https://github.com/westonsteimel)] - improve VEX product and subcomponent matching \[[#&#8203;3168](https://github.com/anchore/grype/pull/3168) [@&#8203;dariozachow](https://github.com/dariozachow)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.107.1...v0.108.0)** ### [`v0.105.0`](https://github.com/anchore/grype/releases/tag/v0.105.0) ##### Added Features - Add archlinux matcher to grype \[[#&#8203;3154](https://github.com/anchore/grype/pull/3154) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.4...v0.105.0)** ### [`v0.104.4`](https://github.com/anchore/grype/releases/tag/v0.104.4) ##### Bug Fixes - preserve local version segment in constraints for PEP 440 comparison \[[#&#8203;3146](https://github.com/anchore/grype/pull/3146) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] ##### Additional Changes - correct help text for return code for fail-on severity option \[[#&#8203;3138](https://github.com/anchore/grype/pull/3138) [@&#8203;u-ways](https://github.com/u-ways)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.3...v0.104.4)** ### [`v0.104.3`](https://github.com/anchore/grype/releases/tag/v0.104.3) ##### Bug Fixes - Use specifier matching rules when comparing python versions \[[#&#8203;3121](https://github.com/anchore/grype/pull/3121) [@&#8203;wagoodman](https://github.com/wagoodman)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.2...v0.104.3)** ### [`v0.104.2`](https://github.com/anchore/grype/releases/tag/v0.104.2) ##### Bug Fixes - Since version 0.104.0 shaded jars are not reported \[[#&#8203;3098](https://github.com/anchore/grype/issues/3098)] - db search fails with misleading message (out of memory) when no db is present \[[#&#8203;3049](https://github.com/anchore/grype/issues/3049) [#&#8203;3077](https://github.com/anchore/grype/pull/3077) [@&#8203;JvD-Ericsson](https://github.com/JvD-Ericsson)] ##### Additional Changes - replace os.Chdir with t.Chdir in test code \[[#&#8203;3067](https://github.com/anchore/grype/pull/3067) [@&#8203;joonas](https://github.com/joonas)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.1...v0.104.2)** ### [`v0.104.1`](https://github.com/anchore/grype/releases/tag/v0.104.1) ##### Bug Fixes - Redact during file output \[[#&#8203;3068](https://github.com/anchore/grype/pull/3068) [@&#8203;kzantow](https://github.com/kzantow)] - Unaffected match table does not filter results if CPE matching is enabled \[[#&#8203;3056](https://github.com/anchore/grype/issues/3056) [#&#8203;3066](https://github.com/anchore/grype/pull/3066) [@&#8203;kzantow](https://github.com/kzantow)] ##### Additional Changes - Migrate grype to use `mholt/archives` instead of anchore fork \[[#&#8203;3036](https://github.com/anchore/grype/pull/3036) [@&#8203;joonas](https://github.com/joonas)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.104.0...v0.104.1)** ### [`v0.104.0`](https://github.com/anchore/grype/releases/tag/v0.104.0) ##### Added Features - Add `--from` flag \[[#&#8203;3035](https://github.com/anchore/grype/pull/3035) [@&#8203;wagoodman](https://github.com/wagoodman)] - Let a suppression expire to prevent that one will forget to resolve a vulnerability \[[#&#8203;3031](https://github.com/anchore/grype/issues/3031)] ##### Bug Fixes - Unnormalized fix version triggers false-positive in mssql-jdbc \[[#&#8203;3042](https://github.com/anchore/grype/issues/3042) [#&#8203;3034](https://github.com/anchore/grype/pull/3034) [@&#8203;jamestexas](https://github.com/jamestexas)] ##### Additional Changes - junit template use CDATA block to prevent XML parse errors \[[#&#8203;3019](https://github.com/anchore/grype/pull/3019) [@&#8203;nvtkaszpir](https://github.com/nvtkaszpir)] - Keep nested loggers labeled \[[#&#8203;3040](https://github.com/anchore/grype/pull/3040) [@&#8203;wagoodman](https://github.com/wagoodman)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.103.0...v0.104.0)** ### [`v0.103.0`](https://github.com/anchore/grype/releases/tag/v0.103.0) ##### Added Features - Allow hyphen in version string \[[#&#8203;3021](https://github.com/anchore/grype/pull/3021) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - Respect rpmmod PURL qualifier \[[#&#8203;3020](https://github.com/anchore/grype/pull/3020) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.102.0...v0.103.0)** ### [`v0.102.0`](https://github.com/anchore/grype/releases/tag/v0.102.0) ##### Added Features - Use Alma Linux specific advisories for Alma Linux scans \[[#&#8203;2745](https://github.com/anchore/grype/issues/2745) [#&#8203;2939](https://github.com/anchore/grype/pull/2939) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] ##### Bug Fixes - Bitnami packages with CPEs are not matched against CPE-based vulnerabilities \[[#&#8203;2997](https://github.com/anchore/grype/issues/2997)] ##### Additional Changes - add markdown template \[[#&#8203;2987](https://github.com/anchore/grype/pull/2987) [@&#8203;sebdanielsson](https://github.com/sebdanielsson)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.101.1...v0.102.0)** ### [`v0.101.1`](https://github.com/anchore/grype/releases/tag/v0.101.1) ##### Bug Fixes - Panic error scanning images with v0.101.0 on some java dependencies \[[#&#8203;3002](https://github.com/anchore/grype/issues/3002)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.101.0...v0.101.1)** ### [`v0.101.0`](https://github.com/anchore/grype/releases/tag/v0.101.0) ##### Added Features - Add cyclonedx to RpmMetadata \[[#&#8203;2935](https://github.com/anchore/grype/pull/2935) [@&#8203;sfc-gh-rmaj](https://github.com/sfc-gh-rmaj)] - `grype db search` can filter by fixed state \[[#&#8203;2968](https://github.com/anchore/grype/pull/2968) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - Support using VEX documents with directory scans and SBOMs \[[#&#8203;2471](https://github.com/anchore/grype/issues/2471) [#&#8203;2811](https://github.com/anchore/grype/pull/2811) [@&#8203;alegrey91](https://github.com/alegrey91)] ##### Bug Fixes - Issue installing Grype using documented curl command \[[#&#8203;2985](https://github.com/anchore/grype/issues/2985)] - Advisory ID blank in JSON output \[[#&#8203;2965](https://github.com/anchore/grype/issues/2965)] ##### Additional Changes - update flags with v3 to not use default config \[[#&#8203;3000](https://github.com/anchore/grype/pull/3000) [@&#8203;spiffcs](https://github.com/spiffcs)] - fix Cosign documentation URL in installer \[[#&#8203;2995](https://github.com/anchore/grype/pull/2995) [@&#8203;lime](https://github.com/lime)] - set advisory id again \[[#&#8203;2979](https://github.com/anchore/grype/pull/2979) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] - add db schema validation \[[#&#8203;2962](https://github.com/anchore/grype/pull/2962) [@&#8203;willmurphyscode](https://github.com/willmurphyscode)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.100.0...v0.101.0)** ### [`v0.100.0`](https://github.com/anchore/grype/releases/tag/v0.100.0) ##### Added Features - Add unaffected package and CPE stores \[[#&#8203;2888](https://github.com/anchore/grype/pull/2888) [@&#8203;wagoodman](https://github.com/wagoodman)] - use unaffected match table to remove appropriate vulns \[[#&#8203;2886](https://github.com/anchore/grype/pull/2886) [@&#8203;CrosleyZack](https://github.com/CrosleyZack)] **[(Full Changelog)](https://github.com/anchore/grype/compare/v0.99.1...v0.100.0)** </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Oslo) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about this update again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate CLI](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0NC4xMTIuMyIsInVwZGF0ZWRJblZlciI6IjQ0LjExMi4zIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->
gitea_admin added 1 commit 2026-09-26 00:10:27 +00:00
chore(deps): update dependency grype to v0.118.0
renovate/stability-days Updates have met minimum release age requirement
/ test (pull_request) Successful in 24s
e94e57c1b8
danijel.simeunovic was assigned by gitea_admin 2026-09-26 00:10:30 +00:00
gitea_admin requested review from danijel.simeunovic 2026-09-26 00:10:33 +00:00
danijel.simeunovic added 1 commit 2026-09-27 22:15:24 +00:00
Merge branch 'main' into renovate/grype-0.x
AI Code Review / ai-review (pull_request) Has been skipped
/ test (pull_request) Successful in 19s
8d2a93193c
danijel.simeunovic approved these changes 2026-09-27 22:15:40 +00:00
danijel.simeunovic merged commit 52068dc533 into main 2026-09-27 22:15:52 +00:00
danijel.simeunovic deleted branch renovate/grype-0.x 2026-09-27 22:15:55 +00:00
Sign in to join this conversation.