File tree Expand file tree Collapse file tree 1 file changed +24
-0
lines changed
Expand file tree Collapse file tree 1 file changed +24
-0
lines changed Original file line number Diff line number Diff line change 1+ <a name =" v1.5.36 " ></a >
2+ ## [ v1.5.36] - 2025-04-18
3+ [ v1.5.36 ] : https://github.com/quay/claircore/compare/v1.5.35...v1.5.36
4+
5+ - vex: allow timeout to pull down VEX archive to be configurable
6+ <details >
7+ As part of the RHEL VEX update process claircore will initially pull down an
8+ archive of all CVEs, this archive includes all CVEs not just the ones
9+ that affect Red Hat products. This means the file (while compressed)
10+ will be quite large. The code previously allowed a timeout of 2 minutes
11+ to pull down this file. This value remains the default but users have the
12+ option to configure it to a different value using
13+ updaters.config.rhel-vex.compressed_file_timeout.
14+ </details >
15+
16+ - rpm: add function to determine if packages are installed from RPMs
17+ <details >
18+ This change allows language detectors to be able to discard packages
19+ that have been determined to have come from an RPM package. This ensures
20+ that only the RPM package is matched to advisories and reduces
21+ false-positives where language packages are patched but their metadata
22+ is not updated (or cannot be updated).
23+ </details >
24+
125<a name =" v1.5.35 " ></a >
226## [ v1.5.35] - 2025-02-11
327[ v1.5.35 ] : https://github.com/quay/claircore/compare/v1.5.34...v1.5.35
You can’t perform that action at this time.
0 commit comments