[5.5.0]
Improvements
- Include the vulnerability repositories used for the scan in the output: as
vulnerabilityRepositoriesin the JSON report, and asretirejs:vulnerability-repositoryentries undermetadata.propertiesin all CycloneDX reports. - CycloneDX 1.6 VEX output now identifies Retire.js as the source of each vulnerability and rating, including the repository URL when a single repository is used.
Bugfixes
- CycloneDX 1.6 VEX output was not schema valid:
ratings[].sourcewas a string rather than an object, and version ranges were reported asaffects[].rangerather than nested underaffects[].versions[].