MediaMarktSaturn / technolinator

GitHub app for SBOM creation using cdxgen and upload to Dependency-Track
Apache License 2.0
15 stars 1 forks source link

chore(deps): update dependency anchore/grype to v0.84.0 #598

Closed heubeck closed 3 weeks ago

heubeck commented 3 weeks ago

This PR contains the following updates:

Package Update Change
anchore/grype minor v0.83.0 -> v0.84.0

Release Notes

anchore/grype (anchore/grype) ### [`v0.84.0`](https://redirect.github.com/anchore/grype/releases/tag/v0.84.0) [Compare Source](https://redirect.github.com/anchore/grype/compare/v0.83.0...v0.84.0) ##### Added Features - Add support for scanning single purl from the CLI \[[#​2225](https://redirect.github.com/anchore/grype/issues/2225) [#​2223](https://redirect.github.com/anchore/grype/pull/2223) [@​wagoodman](https://redirect.github.com/wagoodman)] ##### Bug Fixes - Docker reports 0 vulnerabilities. Same file reports many vulnerabilites when ran directly on linux server \[[#​2235](https://redirect.github.com/anchore/grype/issues/2235)] - Flaky checks on STDIN for purl provider \[[#​2192](https://redirect.github.com/anchore/grype/issues/2192) [#​2223](https://redirect.github.com/anchore/grype/pull/2223) [@​wagoodman](https://redirect.github.com/wagoodman)] - Missing alpine patch version yields inaccurate results \[[#​2222](https://redirect.github.com/anchore/grype/issues/2222) [#​2226](https://redirect.github.com/anchore/grype/pull/2226) [@​wagoodman](https://redirect.github.com/wagoodman)] ##### Additional Changes - update Syft to v1.16.0 \[[#​2237](https://redirect.github.com/anchore/grype/pull/2237) [@​anchore-actions-token-generator](https://redirect.github.com/anchore-actions-token-generator)] **[(Full Changelog)](https://redirect.github.com/anchore/grype/compare/v0.83.0...v0.84.0)**

Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.



This PR has been generated by Renovate Bot.

technolinator-sbom-as-a-service[bot] commented 3 weeks ago

🏆 No vulnerabilities found