What's Changed
- Adds discovery of software inside Debian and Alpine package archives, preserving package containment and separate package occurrences in SPDX SBOMs. Archive scanning is enabled by default and can be disabled with
SCOUT_SBOM_EXPAND_ARCHIVES=false. @brianru - Fixes manual vulnerability exception handling so image scans correctly mark suppressed vulnerabilities and filter them with
--ignore-suppressed, while reducing network requests. @whostolebenfrog - Moves exception details in
--format sbomoutput from the top-level inventory to each vulnerability’sexceptionsarray. Consumers counting manual suppressions must filter forMANUAL_EXCEPTION. @whostolebenfrog - Adds warnings when manual exceptions cannot be applied in local mode or when loading older native SBOMs with legacy exception inventories. Older SBOMs require rescanning to restore manual-exception suppression. @whostolebenfrog
- Updates the native Scout SBOM format to version 12 to support the expanded package inventory and SPDX relationships. @brianru