Skip to content

Commit bba7ea1

Browse files
crozzygithub-actions[bot]
authored andcommitted
chore: v1.5.36 changelog bump
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
1 parent ff78510 commit bba7ea1

File tree

1 file changed

+24
-0
lines changed

1 file changed

+24
-0
lines changed

CHANGELOG.md

Lines changed: 24 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,3 +1,27 @@
1+
<a name="v1.5.36"></a>
2+
## [v1.5.36] - 2025-04-18
3+
[v1.5.36]: https://github.com/quay/claircore/compare/v1.5.35...v1.5.36
4+
5+
- vex: allow timeout to pull down VEX archive to be configurable
6+
<details>
7+
As part of the RHEL VEX update process claircore will initially pull down an
8+
archive of all CVEs, this archive includes all CVEs not just the ones
9+
that affect Red Hat products. This means the file (while compressed)
10+
will be quite large. The code previously allowed a timeout of 2 minutes
11+
to pull down this file. This value remains the default but users have the
12+
option to configure it to a different value using
13+
updaters.config.rhel-vex.compressed_file_timeout.
14+
</details>
15+
16+
- rpm: add function to determine if packages are installed from RPMs
17+
<details>
18+
This change allows language detectors to be able to discard packages
19+
that have been determined to have come from an RPM package. This ensures
20+
that only the RPM package is matched to advisories and reduces
21+
false-positives where language packages are patched but their metadata
22+
is not updated (or cannot be updated).
23+
</details>
24+
125
<a name="v1.5.35"></a>
226
## [v1.5.35] - 2025-02-11
327
[v1.5.35]: https://github.com/quay/claircore/compare/v1.5.34...v1.5.35

0 commit comments

Comments
 (0)