syft

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

APACHE-2.0 License

Downloads
1.4K
Stars
5.4K
Committers
141

Bot releases are hidden (Show)

syft - v0.12.1

Published by anchoreops almost 4 years ago

Changelog

v0.12.1 (2021-01-05)

Full Changelog

Fixed bugs:

  • Update gemspec glob to include named nested specification directories #306 (wagoodman)
  • Add HasPath() to Resolver interface for existence check #305 (wagoodman)

* This Changelog was automatically generated by github_changelog_generator

syft - v0.12.0

Published by anchoreops almost 4 years ago

Changelog

v0.12.0 (2021-01-04)

Full Changelog

Implemented enhancements:

  • Bump stereoscope to pull in content API refactors #299 (wagoodman)

Fixed bugs:

* This Changelog was automatically generated by github_changelog_generator

syft - v0.11.1

Published by anchoreops almost 4 years ago

Changelog

v0.11.1 (2020-12-23)

Full Changelog

Fixed bugs:

  • Handle site packages based on which egg file is parsed #303 (luhring)
  • Python runtime is not a Python package itself, ignore it #301 (alfredodeza)

* This Changelog was automatically generated by github_changelog_generator

syft - v0.11.0

Published by anchoreops almost 4 years ago

Changelog

v0.11.0 (2020-12-18)

Full Changelog

Implemented enhancements:

  • Update dpkg license to only include single-word entries #298 (wagoodman)
  • Incorporate import changes + add image overwrite option #294 (wagoodman)
  • Improve performance of the python cataloger #290 (wagoodman)
  • Sort generated CPEs by specificity #289 (luhring)
  • Upload SBOM results to Anchore Engine #38

Fixed bugs:

  • Python egg-info may be a directory or file, Syft only looks for directories #295

* This Changelog was automatically generated by github_changelog_generator

syft - v0.10.0

Published by anchoreops almost 4 years ago

Changelog

v0.10.0 (2020-12-10)

Full Changelog

Enhancements:

  • Include in JSON output the raw manifest (and digest) from registry if available or a computed manifest (and digest) #272
  • Add support for uploading SBOM results to Anchore Engine #38

* This Changelog was automatically generated by github_changelog_generator

syft - v0.9.2

Published by anchoreops almost 4 years ago

Changelog

v0.9.2 (2020-12-03)

Full Changelog

Fixed bugs:

  • Unable to pull/analyze docker image as of 0.9.0 #284

* This Changelog was automatically generated by github_changelog_generator

syft - v0.9.1

Published by anchoreops almost 4 years ago

Changelog

v0.9.1 (2020-12-02)

Full Changelog

Implemented enhancements:

  • Include CPEs with elements from POM GroupId fields #279 (wagoodman)

* This Changelog was automatically generated by github_changelog_generator

syft - v0.9.0

Published by anchoreops almost 4 years ago

Changelog

v0.9.0 (2020-11-30)

Full Changelog

Implemented enhancements:

Fixed bugs:

  • Update stereoscope version to fix opaque directory merge issue #278 (luhring)
  • Our project's Docker image kills syft and grype #264 (luhring)

* This Changelog was automatically generated by github_changelog_generator

syft - v0.8.0

Published by anchoreops almost 4 years ago

Changelog

v0.8.0 (2020-11-17)

Full Changelog

Enhancements:

  • Add JSON document import #266

Fixed bugs:

  • Incorrect version parsing from certain java package names in syft 5.0 and newer #255
  • Unable to parse license field for certain npm dependencies #253

* This Changelog was automatically generated by github_changelog_generator

syft - v0.7.1

Published by anchoreops almost 4 years ago

Changelog

v0.7.1 (2020-11-12)

Full Changelog

Fixed bugs:

  • Add source to packages found by RPMdb cataloger #263 (wagoodman)

* This Changelog was automatically generated by github_changelog_generator

syft - v0.7.0

Published by anchoreops almost 4 years ago

Changelog

v0.7.0 (2020-11-11)

Full Changelog

Implemented enhancements:

  • Add identified distro and version to output for JSON presenter #169
  • Add signed and notarized ZIP release asset #261 (luhring)
  • Include ID_LIKE when parsing distro information #256

Fixed bugs:

  • Cataloging python packages errors out if "top_level.txt" entry is missing #259

* This Changelog was automatically generated by github_changelog_generator

syft - v0.6.0

Published by anchoreops almost 4 years ago

Changelog

v0.6.0 (2020-11-10)

Full Changelog

Implemented enhancements:

  • Add identified distro and version to output for JSON presenter #169
  • Add RPM file info sourced from the RPM DB #251 (wagoodman)

Fixed bugs:

* This Changelog was automatically generated by github_changelog_generator

syft - v0.5.1

Published by anchoreops almost 4 years ago

Changelog

v0.5.1 (2020-11-04)

Full Changelog

Fixed bugs:

* This Changelog was automatically generated by github_changelog_generator

syft - v0.5.0

Published by anchoreops almost 4 years ago

Changelog

v0.5.0 (2020-10-30)

Full Changelog

Implemented enhancements:

Fixed bugs:

  • Java cataloger doesn't scan the top-level directory during glob matching for pom and nested archives #238
  • Java cataloger reporting packages without name and version #220
  • Java cataloger miscellaneous fixes #245 (wagoodman)

* This Changelog was automatically generated by github_changelog_generator

syft - v0.4.1

Published by anchoreops almost 4 years ago

Changelog

v0.4.1 (2020-10-26)

Full Changelog

Fixed bugs:

  • errors+failures parsing package.json files #230
  • Update doublestar to include fix for open dirs issue #240 (luhring)

* This Changelog was automatically generated by github_changelog_generator

syft - v0.4.0

Published by anchoreops almost 4 years ago

Changelog

v0.4.0 (2020-10-23)

Full Changelog

Implemented enhancements:

  • Enhance python cataloger to be image/directory aware #205
  • Add support for package.json #200
  • Enable CodeQL Security Scan #222 (VinodAnandan)

Fixed bugs:

  • Reduce number of open files while processing nested java archives #227 (wagoodman)

* This Changelog was automatically generated by github_changelog_generator

syft - v0.3.0

Published by anchoreops about 4 years ago

Changelog

v0.3.0 (2020-10-15)

Full Changelog

Implemented enhancements:

  • Update install script arguments for proper argument processing #211 (wagoodman)
  • Run checks on PRs from forks #210 (wagoodman)
  • Fix acceptance tests & add notification upon failures #204 (wagoodman)
  • Add homepage field as output to the gemspec metadata #214

Fixed bugs:

  • Cataloger apkdb-cataloger failed to parse entries #212
  • Allow for gemspec metadata fields to be optional #218 (wagoodman)

* This Changelog was automatically generated by github_changelog_generator

syft - v0.2.0

Published by wagoodman about 4 years ago

Changelog

v0.2.0 (2020-10-08)

Full Changelog

Implemented enhancements:

  • Support cataloging gemspec files #197
  • Fix acceptance tests & add notification upon failures #204 (wagoodman)

Fixed bugs:

* This Changelog was automatically generated by github_changelog_generator

syft - v0.1.0

Published by anchoreops about 4 years ago

First Release! 🎉

syft - v0.1.0-beta.5

Published by anchoreops about 4 years ago

Changelog

v0.1.0-beta.5 (2020-09-26)

Full Changelog

Implemented enhancements:

  • Integrate the changelog generator into the release pipeline #182
  • Test DependencyTrack can utilize the CycloneDX report #161
  • Extend CycloneDx to use pURL #160
  • Add auto-changelog generation #159
  • JSON output for version details #122
  • Normalize the json image/dir source #180 (wagoodman)
  • Remove duplicate rows from the summary table #179 (wagoodman)
  • Add OCI support + use URI schemes #178 (wagoodman)

Fixed bugs:

Closed issues:

  • Expand matching of requirements.txt #167
  • Document release process #132
  • Add arch distro identification #49
  • Add suse distro identification #48

* This Changelog was automatically generated by github_changelog_generator