syft

CLI tool and library for generating a Software Bill of Materials from container images and filesystems

APACHE-2.0 License

Downloads
1.4K
Stars
5.4K
Committers
141

Bot releases are visible (Hide)

syft - v0.44.0

Published by anchoreops over 2 years ago

Changelog

v0.44.0 (2022-04-12)

Full Changelog

Added Features

  • Detect Java Namespaces/Group IDs by hash [Issue #887]
  • Add additional Vendors for Springframework [PR #947 ]
syft - v0.43.2

Published by anchoreops over 2 years ago

Changelog

v0.43.2 (2022-04-06)

Full Changelog

Bug Fixes

  • Pulls from private DockerHub repo fails with 0.43.0 when working with 0.42.4 [Issue #936]
syft - v0.43.0

Published by anchoreops over 2 years ago

Changelog

v0.43.0 (2022-03-31)

Full Changelog

Added Features

Bug Fixes

  • Pull from DockerHub fails for public images when using SSO [PR #928] [wagoodman]
  • Panic in DirectoryResolver indexPath due to null info parameter [Issue #872]
syft - v0.42.4

Published by anchoreops over 2 years ago

Changelog

v0.42.4 (2022-03-24)

Full Changelog

Bug Fixes

syft - v0.42.3

Published by anchoreops over 2 years ago

Changelog

v0.42.3 (2022-03-23)

Full Changelog

Bug Fixes

syft - v0.42.2

Published by anchoreops over 2 years ago

Changelog

v0.42.2 (2022-03-22)

Full Changelog

Added Features

syft - v0.42.1

Published by anchoreops over 2 years ago

Changelog

v0.42.1 (2022-03-21)

Full Changelog

Bug Fixes

syft - v0.42.0

Published by anchoreops over 2 years ago

Changelog

v0.42.0 (2022-03-17)

Full Changelog

Added Features

Bug Fixes

  • Fix panic when CycloneDX BOM missing metadata.component [#895] [kzantow]
syft - v0.41.6

Published by anchoreops over 2 years ago

Changelog

v0.41.6 (2022-03-16)

Full Changelog

Bug Fixes

syft - v0.41.5

Published by anchoreops over 2 years ago

Changelog

v0.41.5 (2022-03-15)

Full Changelog

Bug Fixes

syft - v0.41.4

Published by anchoreops over 2 years ago

Changelog

v0.41.4 (2022-03-11)

Full Changelog

Added Features

Bug Fixes

  • Correct CycloneDX distro decoding, test relationships [PR #745] [kzantow]
  • RPM Epoch should be optional in the json schema [PR #880] [wagoodman]
  • syft packages fails to catalog golang binary's modules for binary built with vendored modules [Issue #871] [fg-j]
syft - v0.41.1

Published by anchoreops over 2 years ago

Changelog

v0.41.1 (2022-03-08)

Full Changelog

Bug Fixes

syft - v0.41.0

Published by anchoreops over 2 years ago

Changelog

v0.41.0 (2022-03-07)

Full Changelog

Added Features

Bug Fixes

syft - v0.40.1

Published by anchoreops over 2 years ago

Changelog

v0.40.1 (2022-03-04)

Full Changelog

Bug Fixes

syft - v0.40.0

Published by anchoreops over 2 years ago

Changelog

v0.40.0 (2022-03-02)

Full Changelog

Added Features

  • Add support for multiple CPEs in CycloneDX [Issue #818]
  • Use syft property namespace in CycloneDX [Issue #842]

Bug Fixes

  • Wrong digest used for in-toto statement subject when using Docker daemon source [Issue #855]
syft - v0.39.3

Published by anchoreops over 2 years ago

Changelog

v0.39.3 (2022-02-26)

Full Changelog

Added Features

  • Allow for CPE strings that can later be sanitized [PR #844] [wagoodman]
  • Ability to sign or attest the generated SBOM [Issue #510]

Bug Fixes

  • Resolve symlinks when fetching file contents [PR #782] [wagoodman]
  • Add exception for handlebars java package to generate nodejs CPE [PR #837] [wagoodman]
  • Do not generate empty CPEs for non-compliant CPE fields [PR #850] [spiffcs]
  • unable to catalog dpkg package=/var/lib/dpkg/status [Issue #733]
  • Deduplicate docker image manifests [Issue #825]
  • scan crash with panic: runtime error: index out of range [1] with length 1 when parsing invalid formatted requirements.txt file [Issue #831]
syft - v0.38.0

Published by anchoreops over 2 years ago

Changelog

v0.38.0 (2022-02-15)

Full Changelog

Added Features

Bug Fixes

  • use SYFT_LOG_FILE env var [PR #805] [jonasagx]
  • Syft stuck on some images (also affecting grype) [Issue #764]
  • Missing the metadata field for Kubernetes pod usage [Issue #787]
syft - v0.37.10

Published by anchoreops over 2 years ago

Changelog

v0.37.10 (2022-02-08)

Full Changelog

Added Features

  • Add distro information to package URLs for OS packages [PR #754] [wagoodman]
  • Encode upstream qualifier on OS package pURLs [PR #769] [wagoodman]
  • Extract language and package type from pURLs on SBOM decode [PR #777] [wagoodman]
  • Update SPDX license list to 3.16 [PR #801] [kzantow]
  • Extend CycloneDX presenters with syft-specific values [Issue #154]
  • Extend CycloneDX presenter with dependency graph [Issue #155]
syft - v0.36.0

Published by anchoreops over 2 years ago

Changelog

v0.36.0 (2022-01-19)

Full Changelog

Added Features

Bug Fixes

  • Missing checksums for other than Linux in 0.35.0 release [Issue #739]
  • Add support for "file" source type in syftjson unmarshaling [PR #750]

Docker images

  • docker pull anchore/syft:v0.36.0
syft - v0.35.1

Published by anchoreops almost 3 years ago

Changelog

v0.35.1 (2022-01-10)

Full Changelog

  • Update Containerd dependency to fix GHSA-mvff-h3cj-wj9c

Docker images

  • docker pull anchore/syft:v0.35.1