Skip to content

Choose a tag to compare

@docker-scout-ci docker-scout-ci released this 30 Sep 16:53
· 2 commits to main since this release
221e7f4

What's Changed

  • Adds discovery of software inside Debian and Alpine package archives, preserving package containment and separate package occurrences in SPDX SBOMs. Archive scanning is enabled by default and can be disabled with SCOUT_SBOM_EXPAND_ARCHIVES=false. @brianru
  • Fixes manual vulnerability exception handling so image scans correctly mark suppressed vulnerabilities and filter them with --ignore-suppressed, while reducing network requests. @whostolebenfrog
  • Moves exception details in --format sbom output from the top-level inventory to each vulnerability’s exceptions array. Consumers counting manual suppressions must filter for MANUAL_EXCEPTION. @whostolebenfrog
  • Adds warnings when manual exceptions cannot be applied in local mode or when loading older native SBOMs with legacy exception inventories. Older SBOMs require rescanning to restore manual-exception suppression. @whostolebenfrog
  • Updates the native Scout SBOM format to version 12 to support the expanded package inventory and SPDX relationships. @brianru