Added Features
- emit golang.org/x/net vulns from govlundb [PR #3534 @willmurphyscode]
- Merge Go vuln matches with GHSA matches [Issue #3515]
Bug Fixes
- only emit records for stdlib [PR #3527 @willmurphyscode]
- mark hummingbird distro as rolling [PR #3521 @willmurphyscode]
- disable go stdlib CPE matching by default [PR #3517 @willmurphyscode]
- merge in custom ranges when applicable [PR #3514 @willmurphyscode]
- exclude linux-kbuild deb indirect matches by default [PR #3506 @westonsteimel]
- avoid panic on invalid RHEL version IDs [PR #3490 @jspilman]
- Support reading CycloneDX 1.7 SBOMs [Issue #3373]
- Grype cannot read mariadb version correctly [Issue #3452]
- grype hangs when downloading certain images using registry client [Issue #3492]
- Can we get a fix for these Critical findings reported for grype [Issue #3484]
Additional Changes
- Security: bump golang.org/x/crypto to v0.52.0 to resolve multiple CVEs [Issue #3493]
- Security: bump golang.org/x/net to v0.55.0 to resolve CVEs [Issue #3494]
Dependencies
35 dependency changes (31 updated, 3 added, 1 removed). 5 vulnerabilities remediated.
🟢 Remediated (5)
- GHSA-33vj-92qq-66hc (High) — github.com/containerd/containerd/v2
- GHSA-cvxm-645q-p574 (Medium) — github.com/containerd/containerd/v2
- GHSA-jpcc-p29g-p8mq (Medium) — github.com/containerd/containerd/v2
- GHSA-rgh6-rfwx-v388 (High) — github.com/containerd/containerd/v2
- GHSA-xhf5-7wjv-pqxp (High) — github.com/containerd/containerd/v2