Skip to content

Releases: anchore/syft

v1.42.0

10 Feb 17:39
Immutable release. Only release title and notes can be modified.
9872ff3

Choose a tag to compare

Added Features

Additional Changes

  • CPE detection for APK libavif to use aomedia vendor [#4597 @naag]

(Full Changelog)

v1.41.2

03 Feb 18:13
Immutable release. Only release title and notes can be modified.
add2629

Choose a tag to compare

Bug Fixes

(Full Changelog)

v1.41.1

29 Jan 21:01
Immutable release. Only release title and notes can be modified.
8d836fb

Choose a tag to compare

Bug Fixes

  • [Bug Report] Missing some dependencies on cyclonedx formatted SBOM using syft [#4562 #4573 @spiffcs]

(Full Changelog)

v1.41.0

27 Jan 11:07
Immutable release. Only release title and notes can be modified.
e8b4527

Choose a tag to compare

Added Features

  • detect Debian version from /etc/debian_version [#4569 @kzantow]

Bug Fixes

  • correctly report supporting evidence for binary packages [#4558 @kzantow]

(Full Changelog)

v1.40.1

15 Jan 21:50
Immutable release. Only release title and notes can be modified.
63927ab

Choose a tag to compare

Important

This release bumps github.com/containerd/containerd to v2, which will cause compiler errors if used alongside other dependencies that use v1 of containerd. See anchore/stereoscope#495 for a detailed discussion.

Bug Fixes

(Full Changelog)

v1.40.0

08 Jan 12:49
Immutable release. Only release title and notes can be modified.
11e8715

Choose a tag to compare

Added Features

Bug Fixes

  • old bitnami images without spdx files arent getting picked up correctly in the catalog [#4529 #4532 @rezmoss]
  • wrong traefik rc versions at binary detection [#3535 #4499 @rezmoss]
  • FromPOSIX() in internals\windows\path.go assumes that all Windows root paths must have a colon terminator [#4070 #4075 @luissantosHCIT]
  • binary cataloger is picking up the go version instead of the actual binary version in traefik experimental images [#4498 #4499 @rezmoss]

(Full Changelog)

v1.39.0

22 Dec 21:15
Immutable release. Only release title and notes can be modified.
e9e3494

Choose a tag to compare

Added Features

Bug Fixes

(Full Changelog)

v1.38.2

09 Dec 22:02
Immutable release. Only release title and notes can be modified.
bfe63f8

Choose a tag to compare

Bug Fixes

(Full Changelog)

v1.38.0

17 Nov 17:55
Immutable release. Only release title and notes can be modified.
a033ae5

Choose a tag to compare

Added Features

Bug Fixes

  • Support extras statements in Python PDM cataloger [#4352 @wagoodman]
  • Preserve --from argument order [#4350 @wagoodman]
  • SBOM generated by Syft 1.28 contains license elements missing id or name (causing CycloneDX parser error) [#4363]
  • empty PURL output in dependency snapshot format breaks sbom-action [#4311]
  • Interface includes constraint elements, can only be used in type parameters [#4346]
  • Upgrade github.com/nwaples/rardecode@v1.1.3 to 2.2.1 [#4338]
  • Upgrade to Golang 1.25.4 [#4341]

Additional Changes

(Full Changelog)

v1.37.0

03 Nov 18:26
Immutable release. Only release title and notes can be modified.
4c93394

Choose a tag to compare

Added Features

Bug Fixes

(Full Changelog)