Bug Fixes
- detect multi-arch ingress-nginx [PR #5179 @CAOShurong]
- keep the epoch when parsing RPM manifest packages [PR #5201 @sueun-dev]
- correct Apache Derby group ID in purl generation [PR #5090 @Ankush-Pathak]
- move image hardlink handling upstream during image indexing [PR #5196 @wagoodman]
- keep epoch-pinned requirements in the SBOM [PR #5161 @sueun-dev]
- Prevent unnecessary allocations when parsing compressed ELF sections [PR #5187 @wagoodman]
- honor the io.ReaderAt contract in readerAtAdapter [PR #5186 @wagoodman]
- Support grafana binary various version [Issue #5059] [PR #5213 @pujitha24]
- Excluded paths are still scanned and cause syft to crash [Issue #3258]
- Dotnet: Incorrect relationship graph in case of using package locks [Issue #5125] [PR #5143 @pujitha24]
- Survive indexing not accessible files [Issue #3286] [PR #5170 @addielaruee]
- CPE target_sw not being set consistency for Rust crates [Issue #3956] [PR #5167 @Xenira]
- panic: nil pointer dereference in squashfs.(*File).Read when scanning snap (regression from 1.44.0) [Issue #4989] [PR #5119 @kzantow]
- golang remote license search attempts to resolve stdlib modules [Issue #3149] [PR #5192 @luantaraschi]
Additional Changes
- gzip binary classifier reports false-positive GNU gzip from BusyBox multicall binary via applet symlink [Issue #5171] [PR #5202 @spiffcs]
- pnpm v5 lockfile: underscore peer-dep suffixes are not stripped from package versions [Issue #5174] [PR #5175 @codeAnqiang-ma]
- pnpm cataloger reads only the first YAML document: SBOM contains pnpm's own binaries and no project dependencies [Issue #5168] [PR #5188 @hamodywe]
Dependencies
72 dependency changes (70 updated, 1 added, 1 removed). 3 vulnerabilities remediated.
🟢 Remediated (3)
- GO-2026-5158 (Medium) — go.opentelemetry.io/otel
- GO-2026-6179 (High) — golang.org/x/mod
- GO-2026-6180 (High) — golang.org/x/mod