github google/osv-scanner v1.8.5

8 days ago

What's Changed

Features:

  • Feature #1160 Support fetching snapshot versions from a Maven registry.
  • Feature #1177 Support composite-based package overrides. This allows for ignoring entire manifests when scanning.
  • Feature #1210 Add FIXED-VULN-IDS to guided remediation non-interactive output.

Fixes:

  • Bug #1220 Fix govulncheck calls on C code.
  • Bug #1236 Alpine package scanning now falls back to latest release version if no release version can be found.

Full Changelog: v1.8.4...v1.8.5

Don't miss a new osv-scanner release

NewReleases is sending notifications on new releases.