github future-architect/vuls v0.31.0

latest releases: v0.34.0, v0.33.4, v0.33.3...
pre-release4 months ago

What's Changed

  • chore(deps): bump github.com/containerd/containerd from 1.7.25 to 1.7.27 by @dependabot in #2151
  • fix(scanner/redhatbase): fix cmd in scanUpdatablePackages by @MaineK00n in #2156
  • chore(deps): bump github.com/golang-jwt/jwt/v5 from 5.2.1 to 5.2.2 by @dependabot in #2152
  • chore(actions): Adjust GitHub Actions permissions (write for release, read-only for others) by @kotakanbe in #2154
  • chore(deps): bump github.com/golang-jwt/jwt/v4 from 4.5.1 to 4.5.2 by @MaineK00n in #2160
  • fix(actions): Add security-events write permission to CodeQL results upload by @kotakanbe in #2162
  • chore(deps): bump github.com/aquasecurity/trivy from 0.60.0 to 0.61.0 by @dependabot in #2163
  • fix(report): Refactor SBOM generation: split functions, improve PURL logic, set OS as root by @kl-sinclair in #2171
  • chore(deps): bump golangci/golangci-lint-action from 6 to 7 by @dependabot in #2166
  • chore(deps): Pin GitHub Actions and Docker image, configure Dependabot by @kotakanbe in #2159
  • fix(report): skip empty properties in OS package SBOM components by @kl-sinclair in #2181
  • fix(report): omit empty CWE and rating fields in CycloneDX SBOM by @kl-sinclair in #2182
  • feat(detector/vuls2): open with Read Only Mode by @MaineK00n in #2180
  • fix(cmd/saas): add timeout option by @wadda0714 in #2183
  • chore(deps): bump golang.org/x/text from 0.23.0 to 0.24.0 by @dependabot in #2167
  • chore(deps): bump the aws group with 4 updates by @dependabot in #2170
  • chore(deps): bump docker/setup-buildx-action from afeb29a6e0d7d6258844ecabe6eba67d13443680 to 941183f0a080fa6be59a9e3d3f4108c19a528204 by @dependabot in #2174
  • chore(deps): bump goreleaser/goreleaser-action from 6.2.1 to 6.3.0 by @dependabot in #2177
  • chore(deps): bump docker/build-push-action from 84ad562665bb303b549fec655d1b64f9945f3f91 to 88844b95d8cbbb41035fa9c94e5967a33b92db78 by @dependabot in #2175
  • chore(deps): bump github/codeql-action from e0ea141027937784e3c10ed1679e503fcc2245bc to 45775bd8235c68ba998cffa5171334d58593da47 by @dependabot in #2176
  • chore(deps): bump golang.org/x/oauth2 from 0.28.0 to 0.29.0 by @dependabot in #2169
  • chore(deps): bump the go_modules group across 1 directory with 2 updates by @dependabot in #2179
  • feat!(detector): timeout can be set, default is no timeout by @MaineK00n in #2185
  • feat(detector/vuls2): fill cvss v4.0 by @MaineK00n in #2186
  • chore(deps): bump github.com/kotakanbe/go-pingscanner by @MaineK00n in #2201
  • feat(ci): support signed release by @kotakanbe in #2184

Full Changelog: v0.30.0...v0.31.0

Don't miss a new vuls release

NewReleases is sending notifications on new releases.