Skip to content

Releases: anchore/syft

v1.42.3

19 Mar 17:08
Immutable release. Only release title and notes can be modified.
860126c

Choose a tag to compare

Bug Fixes

  • Missing secondary evidence for .NET dependency in ghcr.io/open-telemetry/demo:2.0.0-accounting image [#4652]

Additional Changes

(Full Changelog)

v1.42.2

09 Mar 18:34
Immutable release. Only release title and notes can be modified.
75455f0

Choose a tag to compare

Bug Fixes

Additional Changes

(Full Changelog)

v1.42.1

18 Feb 17:50
Immutable release. Only release title and notes can be modified.
0a3f7bb

Choose a tag to compare

Bug Fixes

Additional Changes

(Full Changelog)

v1.42.0

10 Feb 17:39
Immutable release. Only release title and notes can be modified.
9872ff3

Choose a tag to compare

Added Features

Additional Changes

  • CPE detection for APK libavif to use aomedia vendor [#4597 @naag]

(Full Changelog)

v1.41.2

03 Feb 18:13
Immutable release. Only release title and notes can be modified.
add2629

Choose a tag to compare

Bug Fixes

(Full Changelog)

v1.41.1

29 Jan 21:01
Immutable release. Only release title and notes can be modified.
8d836fb

Choose a tag to compare

Bug Fixes

  • [Bug Report] Missing some dependencies on cyclonedx formatted SBOM using syft [#4562 #4573 @spiffcs]

(Full Changelog)

v1.41.0

27 Jan 11:07
Immutable release. Only release title and notes can be modified.
e8b4527

Choose a tag to compare

Added Features

  • detect Debian version from /etc/debian_version [#4569 @kzantow]

Bug Fixes

  • correctly report supporting evidence for binary packages [#4558 @kzantow]

(Full Changelog)

v1.40.1

15 Jan 21:50
Immutable release. Only release title and notes can be modified.
63927ab

Choose a tag to compare

Important

This release bumps github.com/containerd/containerd to v2, which will cause compiler errors if used alongside other dependencies that use v1 of containerd. See anchore/stereoscope#495 for a detailed discussion.

Bug Fixes

(Full Changelog)

v1.40.0

08 Jan 12:49
Immutable release. Only release title and notes can be modified.
11e8715

Choose a tag to compare

Added Features

Bug Fixes

  • old bitnami images without spdx files arent getting picked up correctly in the catalog [#4529 #4532 @rezmoss]
  • wrong traefik rc versions at binary detection [#3535 #4499 @rezmoss]
  • FromPOSIX() in internals\windows\path.go assumes that all Windows root paths must have a colon terminator [#4070 #4075 @luissantosHCIT]
  • binary cataloger is picking up the go version instead of the actual binary version in traefik experimental images [#4498 #4499 @rezmoss]

(Full Changelog)

v1.39.0

22 Dec 21:15
Immutable release. Only release title and notes can be modified.
e9e3494

Choose a tag to compare

Added Features

Bug Fixes

(Full Changelog)