Skip to content

Releases: anchore/syft

v1.29.0

21 Jul 19:49
6f36b58
Compare
Choose a tag to compare

Added Features

Additional Changes

(Full Changelog)

v1.28.0

02 Jul 16:35
e8b62ab
Compare
Choose a tag to compare

Added Features

Additional Changes

(Full Changelog)

v1.27.1

12 Jun 13:51
10f0631
Compare
Choose a tag to compare

Bug Fixes

Additional Changes

(Full Changelog)

v1.27.0

09 Jun 18:45
18f9b5a
Compare
Choose a tag to compare

Added Features

Bug Fixes

  • Remove CPE product candidates for phf, prometheus, hyper and Rust crates [#3967 @jayvdb]
  • Remove CPE product candidates for opentelemetry and redis Rust crates [#3962 @jayvdb]
  • Harden Container Runtime with Non-Root User [#3941 @MikeTheCyberGuy]
  • terraform provider lock entries should not require constraints [#3934 @ghouscht]
  • sbom cataloger returning upstream package [#3662 #3981 @kzantow]
  • Syft missing md5 sums and list data for dpkg packages under status.d/ [#3912]
  • Failure to detect dependency relationships between Python packages [#3958 #3965 @christoph-blessing]
  • Heavy memory consumption when directory scanning deb source [#3928 #3953 @kzantow]
  • In versions 1.25.0 and later, graalvm-native-image-cataloger adds 3-6 hours to Syft [#3942 #3944 @kzantow]
  • Syft incorrectly reports multiple APKs as parents of symlinked files [#3847 #3923 @luhring]

(Full Changelog)

A HUGE thank you to @rezmoss for his help identifying and solving an issue causing excessive time and memory consumption with large numbers of symlinks! ❤️

v1.26.1

22 May 12:45
7bfb4c8
Compare
Choose a tag to compare

Bug Fixes

(Full Changelog)

v1.26.0

20 May 21:35
ac883f5
Compare
Choose a tag to compare

Added Features

Bug Fixes

  • pkg.JavaArchive.PomProperties is being populated even though no pom.properties file was present for analysis [#3922 @wagoodman]
  • syft 1.24.0 debug container - wget fails TLS [#3891 #3915 @spiffcs]

(Full Changelog)

v1.25.1

16 May 19:02
db77b54
Compare
Choose a tag to compare

Additional Changes

(Full Changelog)

v1.25.0

16 May 16:37
2d4fe51
Compare
Choose a tag to compare

Added Features

Bug Fixes

(Full Changelog)

v1.24.0

14 May 15:01
3c7018a
Compare
Choose a tag to compare

Added Features

Bug Fixes

  • update license sort to be stable with contents field [#3860 @spiffcs]
  • Improve detection of erlang binary in alpine Linux [#3839 @avodotiiets]
  • Do not search for main module versions within binary contents by default [#3874 @wagoodman]
  • dpkg license improvement for non SPDX licenses [#3090 #3888 @spiffcs]
  • CycloneDX group field not symmetrically handled by encoder/decoders [#2981 #3853 @kzantow]
  • Syft crash [signal SIGSEGV: segmentation violation code=0x80 addr=0x0 pc=0x123a0da] [#3872 #3875 @wagoodman]
  • Syft 1.23.1 shows version (devel) for grafana 12.0.0 [#3864]
  • .NET cataloger does not always pair up PE binaries and deps.json packages, resulting in duplicate packages on some runs [#3866 #3869 @wagoodman]
  • Propagate error in FileSourceProvider instead of warn log [#3831 #3845 @Rupikz]
  • Update github.com/Masterminds/semver package [#3829 #3836 @popey]
  • go-module-file-cataloger fails if symlinks in path [#3614 #3783 @VictorHuu]
  • Support fluent-bit some versions of arm/s390x images [#3793 #3817 @VictorHuu]

Additional Changes

(Full Changelog)

v1.23.1

25 Apr 15:02
a714fb8
Compare
Choose a tag to compare

Additional Changes

(Full Changelog)