Skip to content

Releases: future-architect/vuls

v0.40.1

Choose a tag to compare

@shino shino released this 30 Jul 02:15
e6624e9

Changelog

  • e6624e9 fix(release): resolve the pushed tag when multiple tags point at HEAD (#2616)

v0.40.1-rc.1

v0.40.1-rc.1 Pre-release
Pre-release

Choose a tag to compare

@shino shino released this 30 Jul 01:42
e6624e9

Changelog

  • e6624e9 fix(release): resolve the pushed tag when multiple tags point at HEAD (#2616)

v0.40.0-rc.1

v0.40.0-rc.1 Pre-release
Pre-release

Choose a tag to compare

@shino shino released this 29 Jul 06:29
25d03d6

Changelog

  • 25d03d6 feat(detector/vuls2): adopt forward-compatible enum serde and surface evaluation warnings (#2609)
  • 0050802 chore(deps): bump the go_modules group across 1 directory with 2 updates (#2611)
  • 7cc6c21 chore(deps): bump the trivy group across 1 directory with 2 updates (#2597)
  • 0b04ace chore(deps): bump the others group across 1 directory with 8 updates (#2608)
  • 8b2f7c4 feat(detector/vuls2): use JPCERT-AT reference_titles for JVN alert title (#2610)
  • 45714b6 feat(detector/vuls2): flatten CPE AND conjunctions to OR in vuls0 (#2606)
  • 76c616f feat(detector/vuls2): ignore rejected/withdrawn CPE vulnerabilities (#2603)
  • c4611e3 chore(deps): bump vuls-data-update and vuls2 to latest (#2602)
  • cf9e99e perf(detector): share one vuls2 db session across a server's detect and enrich (#2600)
  • b03f24e feat(detector): detect Seal Security patched library packages (#2596)
  • 77a2bfc perf(detector): derive verified-product suppression from the detection result (#2592)
  • 0d41be0 chore(deps): bump github.com/aquasecurity/trivy (#2573)
  • 698946a chore(deps): bump the others group across 1 directory with 10 updates (#2595)
  • 33eb699 chore(deps): bump the all group across 1 directory with 11 updates (#2593)
  • 89a602c chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.10.0 to 0.11.0 (#2594)
  • 7ea4a1e chore(deps): bump the all group across 1 directory with 2 updates (#2565)
  • f621477 feat!(detector): route VulnCheck and JVN to vuls2 (#2590)
  • 1297680 feat(detector): route Fortinet to vuls2 (#2591)
  • 2d80751 feat(detector): route Palo Alto to vuls2 (#2589)
  • c6b9778 feat!(detector): route Cisco to vuls2 (#2581)
  • 61f32a4 feat(detector): enrich MITRE CVE v5 via vuls2 (#2586)
  • 92e1e56 chore(deps): bump github.com/containerd/containerd (#2583)
  • 635222e feat!(detector): replace go-cti with vuls2 (#2530)
  • 9d8465a feat(detector/vuls2): enrich ENISA EUVD List via vuls2 (#2585)
  • 024b0e2 feat!(detector): route NVD to vuls2 (#2575)
  • e6acd26 test(detector/vuls2): rename enrich fixture mitre-v5 to mitre-cve-v5 (#2576)

v0.39.3

Choose a tag to compare

@shino shino released this 09 Jun 09:13
5ce5623

Changelog

  • 5ce5623 fix!(scanner): treat AnalyzeLibrary failures as warnings instead of errors (#2574)
  • 75fc521 chore(deps): bump the all group across 1 directory with 3 updates (#2572)
  • 30ed4d4 feat(config): update GetEOL with newly released OS versions (#2570)
  • 2b36046 chore(deps): bump the go_modules group across 1 directory with 2 updates (#2566)
  • 6ef6ba4 feat!(detector): detect windows with vuls2 (#2499)
  • 259e694 fix(detector/vuls2): normalize Amazon Linux release in preConvert (#2562)

v0.39.2

Choose a tag to compare

@shino shino released this 20 May 02:36
48f8c79

Changelog

  • 48f8c79 feat(scanner): support disablerepo option for yum/dnf (#2559)
  • da0e250 fix(detector): sort previous JSON dirs in descending order for diff (#2555)
  • 1b97518 docs(readme): remove community Slack links (#2554)

v0.39.1

Choose a tag to compare

@shino shino released this 18 May 09:41
140017b

Changelog

  • 140017b feat(scanner): expose Trivy dependency graph fields on Library (#2552)

v0.39.0

Choose a tag to compare

@shino shino released this 12 May 02:01
5cd03fc

Changelog

  • 5cd03fc chore(deps): bump github.com/go-git/go-git/v5 (#2549)
  • 6034b6d feat(scanner): add pylock.toml detection (PEP 751) (#2548)
  • 0244ae1 deps(dict): bump go-cve-dictionary, go-cti, gost (#2547)
  • c5262f8 chore(deps): bump github.com/aquasecurity/trivy (#2521)
  • a9079d5 chore(deps): bump the all group across 1 directory with 2 updates (#2546)
  • 1f896e5 chore(deps): bump the others group across 1 directory with 6 updates (#2540)
  • 230527e fix(config): refresh openSUSE Leap EOL entries (add 16.0, extend 15.6) (#2543)
  • 6372c4c fix(detector/library): regenerate PURL after JAR SHA1 canonicalization (#2533)
  • a975238 feat(detector/vuls2): thread RedHat CVE Mitigation into VulnInfo (#2532)
  • 18abe61 test(scanner): source lockfiles from vulsio/integration (#2531)
  • 52eff31 chore(deps): bump the go_modules group across 1 directory with 2 updates (#2527)
  • f235b9c chore(deps): bump the all group across 1 directory with 5 updates (#2526)
  • 0e039bb chore(deps): bump the all group across 1 directory with 2 updates (#2525)
  • c08f424 chore(deps): bump the others group across 1 directory with 5 updates (#2523)
  • bb3cad0 feat(config/os): add ubuntu 26.04 (#2524)
  • 71ddc50 chore(deps): bump the go_modules group across 1 directory with 5 updates (#2520)
  • 4c71b0a feat!(detector): replace go-exploitdb with vuls2 (#2517)
  • 9991a0f feat(scanner/windows): update kb supersession (#2518)
  • b780bb3 feat(detector): add DataSources filter to enrich function (#2513)
  • 8383d40 feat!(detector): relace go-msfdb with vuls2 (#2512)
  • 234664c feat!(detector): replace go-kev with vuls2 (#2509)
  • afd0c4d fix(detector): enrich all detected CVEs, not only vuls2-detected ones (#2511)
  • fadbbaa feat!(detector): replace gost.FillCVEsWithRedHat with vuls2 (#2505)
  • d9876d1 fix(detector/vuls2): skip advisory fallback for ignored vulns (#2508)
  • 5119155 refactor: remove GraphQL-based GitHub detection, add Dependency.PURL (#2502)
  • c7e3461 refactor(scanner/windows): detect version by build number only (#2503)
  • ff914c8 chore(deps): bump actions/setup-go in the all group across 1 directory (#2497)
  • 01e3a26 chore(deps): bump the others group across 1 directory with 12 updates (#2498)
  • b67629c chore(deps): bump the go_modules group across 1 directory with 2 updates (#2495)
  • 44e160e fix(contrib/trivy): dedup package names and add dup warnings (#2491)
  • 652294a deps: remove fanal framework, call Trivy parsers directly (#2476)
  • b9ac2ff chore!(contrib/docker): temporarily remove fvuls docker publish (#2483)
  • 35a36c1 fix(subcmds/report): remove trivy's tmp directory (#2482)
  • b610fa5 deps: remove trivy/pkg/cache import, replace with local helper (#2478)
  • d2acdcd chore(deps): bump google.golang.org/grpc (#2477)
  • f9865db chore(ci): update GitHub Actions workflows (#2474)
  • 95a1e30 fix(ci/diet): fix shell heredoc in diet-check.yml (#2471)
  • 622a72a chore(ci): add Diet PR metrics workflow (#2469)
  • 3fbd296 fix(models): include CPE vulns in total, set "unknown" patch status (#2460)
  • 16a9088 fix(detector/vuls2): backport ubuntu fix (#2458)
  • adbc480 fix(reporter/sbom): add WindowsKB to SBOM output (#2454)
  • 173aacf feat!(detector): detect debian with vuls2 (#2448)

v0.38.6

Choose a tag to compare

@shino shino released this 11 Mar 03:06
6827f2d

What's Changed

  • chore(deps): update dependencies and integration by @shino in #2443
  • fix(contrib/trivy): O(N²) library duplication in trivy-to-vuls ClassLangPkg handling by @Copilot in #2450
  • feat(detector/vuls2): amazon linux by vuls2 by @shino in #2441

New Contributors

  • @Copilot made their first contribution in #2450

Full Changelog: v0.38.5...v0.38.6

v0.38.5

Choose a tag to compare

@shino shino released this 03 Mar 09:56
b87a83a

Changelog

v0.38.4

Choose a tag to compare

@shino shino released this 02 Mar 07:34
9efad2a

Changelog

  • 9efad2a chore(deps): downgrade github.com/package-url/packageurl-go v0.1.4 => v0.1.3 (#2438)