Repository navigation
Releases: awarelyeu/awarely-sbom-scanner
Release list
Awarely Scan v0.9.0
Awarely Scan v0.9.0 — first stable release
Generate a local CycloneDX SBOM, check supported package versions through Awarely Monitor, or synchronize one configured inventory source. Guided setup includes input recovery, readable check summaries and reuse of existing SBOMs. Local collection is available without an account; API operations require Monitor Pro and a scoped credential.
This release retains the collector and API behavior of v0.9.0-alpha.1. Managed Syft remains pinned to 1.54.1. It is downloaded only with consent and verified against release-specific digests. Syft collects package identities; Awarely performs vulnerability assessment for the documented supported ecosystems and distributions. Unsupported or incomplete assessments remain explicit, including Go, NuGet, Composer, RubyGems, Cargo and Amazon Linux 2.
Upgrade an existing v0.9.0-alpha.1 installation with:
awarely-scan update --check
awarely-scan update
awarely-scan version --toolsThe update asks for confirmation and verifies repository, workflow, tag, build provenance and checksums before atomic replacement. One private backup supports rollback. Older versions without the update command can use this release's installer. No root or GitHub login is required. After upgrading, stable installations receive stable releases by default.
See the English walkthrough or Romanian walkthrough for installation, scanning, API credentials and interpretation of results. Coverage limits still apply; zero matches is not a security guarantee. Jenkins integration is the next planned stage.
Awarely Scan v0.9.0-alpha.1
Verified updates and rollback
Check for a newer release with awarely-scan update --check, then run awarely-scan update and confirm. The updater verifies signed release provenance, the binary digest and startup before atomic replacement, and keeps one private rollback backup. awarely-scan update --rollback restores the previous binary without network access. Scans never trigger updates.
Older installations can upgrade through this release's installer after verification and confirmation, without manually moving the old binary. Stable installations stay on stable releases; prerelease installations also see newer previews. No GitHub login, system gh or root access is needed.
Managed Syft is now 1.54.1, with verified architecture-specific digests. It changes only through a tested Awarely release. awarely-scan version --tools shows both versions; the next Syft scan requests consent if the new tool is not cached.
The English and Romanian walkthroughs include initial upgrade, subsequent updates, troubleshooting and rollback. This remains a prerelease; ecosystem CVE coverage is unchanged.
Awarely Scan v0.8.0-alpha.2
Installation without a system GitHub CLI
The installer can prepare a temporary pinned GitHub CLI verifier when gh is missing or too old, after explicit consent. It checks the upstream archive digest before execution and still requires signed provenance for the exact Awarely release. No GitHub account, root access or repository setup is needed for the verifier; temporary files are removed afterward.
Missing basic tools now show distribution-specific guidance and can be rechecked without restarting. Guided scans can explicitly retry temporary Syft download failures while keeping the selected directory. Integrity and unsafe-cache errors still stop.
The English and Romanian guides distinguish installation tools from scanner requirements. The scanner itself does not require gh. This remains a prerelease; ecosystem CVE coverage is unchanged.
Awarely Scan v0.8.0-alpha.1
A clearer guided scanning experience
The guided menu now lets you correct paths, labels, result directories and credential files without restarting. Use b to go back, q to quit, and option 6 to reopen a saved Awarely SBOM for check or sync. Relative paths, ~/ and quoted paths are supported without shell execution.
Terminal-only colors respect NO_COLOR and TERM=dumb. API checks include a readable check-summary.txt alongside the complete JSON evidence. Check retries need a new confirmation; uncertain syncs are never retried automatically. Report-saving recovery does not repeat an API request.
Local-first defaults, private files, verification of optional Syft, explicit transmission consent and partial-inventory sync restrictions remain in place. Noninteractive command contracts and ecosystem assessment coverage are unchanged.
See the English guide or Romanian guide. This is a prerelease.
Awarely Scan v0.7.0-alpha.2
Guided Linux and application scans
Start awarely-scan in a terminal, or run awarely-scan guided. Choose Linux, npm, Python, Java or other application ecosystems. The scanner checks inputs, explains missing prerequisites, creates a private SBOM and offers local export, API check or scoped API sync.
Optional Syft preparation uses a fixed, digest-verified archive and requires confirmation. It needs no separately installed Cosign, gh, Java or Python runtime to inspect existing artifacts. The initial Awarely installer verifies release provenance using public bundles without GitHub login. Project builds and dependency installation remain under your control.
API transmission requires a separate confirmation showing its destination and source. Partial inventories cannot sync. Native host/app/import commands retain their offline behavior; existing automation commands remain supported.
See the English guide and Romanian guide. This remains a prerelease pending the user walkthrough. Jenkins is a later stage. Ecosystem CVE coverage is unchanged; inventory support is not a vulnerability verdict.
Awarely Scan v0.7.0-alpha.1
Guided Linux and application scans
Start awarely-scan in a terminal, or run awarely-scan guided. Choose Linux, npm, Python, Java or other application ecosystems. The scanner checks inputs, explains missing prerequisites, creates a private SBOM and offers local export, API check or scoped API sync.
Optional Syft preparation uses a fixed, digest-verified archive and requires confirmation. It needs no separately installed Cosign, gh, Java or Python runtime to inspect existing artifacts. The initial Awarely installer verifies release provenance using public bundles without GitHub login. Project builds and dependency installation remain under your control.
API transmission requires a separate confirmation showing its destination and source. Partial inventories cannot sync. Native host/app/import commands retain their offline behavior; existing automation commands remain supported.
See the English guide and Romanian guide. This remains a prerelease pending the user walkthrough. Jenkins is a later stage. Ecosystem CVE coverage is unchanged; inventory support is not a vulnerability verdict.
Awarely Scan v0.6.0-alpha.1
Optional Syft import and Java assessment
Import selected CycloneDX JSON application inventories from Syft or another compatible producer. Keep native Linux/npm/Python collection, export locally, check through the API or synchronize a scoped source. Syft remains separately installed and optional; it is never automatically executed or downloaded.
Java assessment retains Maven coordinates and version ordering. NuGet, Go, Composer, RubyGems and Cargo support inventory/sync with explicit unevaluated CVE coverage. Import validates bounded input, removes arbitrary metadata, deduplicates identities and refuses to sync partial snapshots.
See English guide and Romanian guide. This remains a prerelease; Jenkins is a later stage.
Awarely Scan v0.5.0-alpha.1
Amazon Linux support
Linux amd64/arm64 binaries automatically recognize Amazon Linux 2023 and Amazon Linux 2. Local inventory remains offline and unprivileged; explicit API checks and source-scoped sync preserve Amazon RPM identity and evidence.
Amazon Linux 2023 uses official core-repository security advisories. Amazon Linux 2 inventory remains usable, with an explicit end-of-life notice and unevaluated security status. No new runtime dependency, subprocess, cloud credential discovery or image-scanning mode was added.
Rocky Linux and AlmaLinux support
The existing Linux amd64/arm64 binaries now detect Rocky Linux and AlmaLinux automatically. Local inventory, explicit API checks and source-scoped inventory sync support RPM packages on releases 8/9/10.
Local collection reads bounded SQLite/WAL and Berkeley DB snapshots without root, network access, subprocesses or package installation. API checks use official distribution advisories and RPM EVR ordering, preserving architecture, vendor, module stream and backported revisions. Unsupported or unassessed packages remain explicit in coverage.
See coverage and API semantics. Jenkins integration remains a later phase.
Awarely Scan v0.4.0-alpha.1
Rocky Linux and AlmaLinux support
The existing Linux amd64/arm64 binaries now detect Rocky Linux and AlmaLinux automatically. Local inventory, explicit API checks and source-scoped inventory sync support RPM packages on releases 8/9/10.
Local collection reads bounded SQLite/WAL and Berkeley DB snapshots without root, network access, subprocesses or package installation. API checks use official distribution advisories and RPM EVR ordering, preserving architecture, vendor, module stream and backported revisions. Unsupported or unassessed packages remain explicit in coverage.
See coverage and API semantics. Jenkins integration remains a later phase.
Awarely Scan v0.3.0-alpha.1
Distribution advisory checks
Host inventories now preserve source-package names and versions, including binary-only rebuilds. API checks evaluate supported Debian/Ubuntu packages against official distribution advisories and report fixed versions, advisory links and per-component evidence. Backported fixes use Debian version ordering. Unknown assessments and unsupported inputs remain explicit; unavailable or stale data cannot produce a clean result.
Local collection remains offline and rootless. Recollect host inventories created with earlier releases to include source-package metadata. Read the coverage and API documentation for supported releases and report semantics.