Skip to content

Releases: grafeas/grafeas

v0.2.3

28 Aug 14:39
9879eca
Compare
Choose a tag to compare
  • SBOM enhancements.
  • SLSA enhancements.
  • Vex Assessment enhancements.

v0.2.2

24 Apr 15:03
f1fb34a
Compare
Choose a tag to compare
  • Enhanced support for Vulnerability Notes and Occurrences, with the following changes:
    • Indicate the location at which an affected package was found in the container image.
    • CVSS proto compatible with v2 and v3.
    • More detailed status of language package scans in the Discovery occurrence.
    • Added cvss_version field to indicate which version was used to populate fields: cvss_score and severity.
    • Added support for Vex Assessments.
  • Added support for language packages in Package Notes and Occurrences.
  • Enhanced SLSA support.
    • Added support for SLSA v0.2 to the intoto statement.
    • Added SLSA v0.2 converter.
  • Added SBOM support.
  • Updated versions of frameworks and libraries
    • Use ANTLR v4.
    • Golang 1.20.

v0.1.3

18 Oct 20:26
46886af
Compare
Choose a tag to compare

Release generated go protos along with the code in 0.1.2.