-
Notifications
You must be signed in to change notification settings - Fork 699
Comparing changes
Open a pull request
base repository: anchore/grype
base: v0.101.0
head repository: anchore/grype
compare: main
- 10 commits
- 20 files changed
- 7 contributors
Commits on Oct 16, 2025
-
chore(deps): update tools to latest versions (#3003)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: westonsteimel <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 1efded8 - Browse repository at this point
Copy the full SHA 1efded8View commit details -
chore(deps): update anchore dependencies (#3005)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: willmurphyscode <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for dccc91b - Browse repository at this point
Copy the full SHA dccc91bView commit details -
chore(deps): bump anchore/sbom-action from 0.20.6 to 0.20.8 (#3006)
Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action) from 0.20.6 to 0.20.8. - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@f8bdd1d...aa0e114) --- updated-dependencies: - dependency-name: anchore/sbom-action dependency-version: 0.20.8 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for d6bc728 - Browse repository at this point
Copy the full SHA d6bc728View commit details -
feat: add markdown template (#2987)
* Add markdown template Add markdown template for displaying vulnerabilities. Signed-off-by: Sebastian <[email protected]> * Add more data to Vulnerability Report Signed-off-by: Sebastian <[email protected]> --------- Signed-off-by: Sebastian <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for d949ea5 - Browse repository at this point
Copy the full SHA d949ea5View commit details
Commits on Oct 20, 2025
-
chore(deps): bump sigstore/cosign-installer from 3.10.0 to 4.0.0 (#3007)
Bumps [sigstore/cosign-installer](https://github.com/sigstore/cosign-installer) from 3.10.0 to 4.0.0. - [Release notes](https://github.com/sigstore/cosign-installer/releases) - [Commits](sigstore/cosign-installer@d7543c9...faadad0) --- updated-dependencies: - dependency-name: sigstore/cosign-installer dependency-version: 4.0.0 dependency-type: direct:production update-type: version-update:semver-major ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 9aaa411 - Browse repository at this point
Copy the full SHA 9aaa411View commit details
Commits on Oct 21, 2025
-
feat: use AlmaLinux advisories for fix info in RPM matcher (#2939)
Previously, the RPM matcher assumed that an AlmaLinux system had identical vulnerability information to a RHEL system. However, AlmaLinux has its own set of advisories that may differ from RHEL. In order to address this gap, when AlmaLinux data is available and the distro is identified as AlmaLinux, the RPM matcher will consider Red Hat disclosures, but consider fix information from AlmaLinux advisories. This change is specifically meant to address the class of false positives where AlmaLinux advisories have a lower fix version than RHEL advisories for the same CVE, especially in cases where Alma patches a lower upstream than Red Hat, or cases where the RPM version contains a module build number, since AlmaLinux module build numbers are typically lower than RHEL ones. Signed-off-by: Will Murphy <[email protected]> Co-authored-by: Alex Goodman <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for ea9d52d - Browse repository at this point
Copy the full SHA ea9d52dView commit details
Commits on Oct 22, 2025
-
chore(deps): bump github/codeql-action from 4.30.8 to 4.30.9 (#3008)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 4.30.8 to 4.30.9. - [Release notes](https://github.com/github/codeql-action/releases) - [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md) - [Commits](github/codeql-action@f443b60...16140ae) --- updated-dependencies: - dependency-name: github/codeql-action dependency-version: 4.30.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for 9e4664d - Browse repository at this point
Copy the full SHA 9e4664dView commit details -
chore(deps): update tools to latest versions (#3009)
Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Co-authored-by: westonsteimel <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for 58c144c - Browse repository at this point
Copy the full SHA 58c144cView commit details -
chore(deps): update anchore dependencies (#3010)
* chore(deps): update anchore dependencies Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> * test: cover new Python PDM lock entry metadata Signed-off-by: Will Murphy <[email protected]> --------- Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com> Signed-off-by: Will Murphy <[email protected]> Co-authored-by: willmurphyscode <[email protected]> Co-authored-by: Will Murphy <[email protected]>
Configuration menu - View commit details
-
Copy full SHA for ad9579a - Browse repository at this point
Copy the full SHA ad9579aView commit details
Commits on Oct 23, 2025
-
chore(deps): bump anchore/sbom-action from 0.20.8 to 0.20.9 (#3012)
Bumps [anchore/sbom-action](https://github.com/anchore/sbom-action) from 0.20.8 to 0.20.9. - [Release notes](https://github.com/anchore/sbom-action/releases) - [Changelog](https://github.com/anchore/sbom-action/blob/main/RELEASE.md) - [Commits](anchore/sbom-action@aa0e114...8e94d75) --- updated-dependencies: - dependency-name: anchore/sbom-action dependency-version: 0.20.9 dependency-type: direct:production update-type: version-update:semver-patch ... Signed-off-by: dependabot[bot] <[email protected]> Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Configuration menu - View commit details
-
Copy full SHA for ab01450 - Browse repository at this point
Copy the full SHA ab01450View commit details
This comparison is taking too long to generate.
Unfortunately it looks like we can’t render this comparison for you right now. It might be too big, or there might be something weird with your repository.
You can try running this command locally to see the comparison on your machine:
git diff v0.101.0...main