Added Features
- report the perl interpreter as a cpan package [PR #5132 @wagoodman]
- Add package cataloger for perl ecosystem [Issue #1906] [PR #5131 @wagoodman]
- Analyze with Non-Daemon podman [Issue #1173]
Bug Fixes
- write a name for the root package when the source has none [PR #5349 @DrVelvetFog]
- match opensource.org license URLs across SPDX URL forms [PR #5361 @willmurphyscode]
- Account for malformed GGUF and safetensors parameter counts [PR #5343 @wagoodman]
- don't panic on a root file without a supplier or null entries [PR #5326 @DrVelvetFog]
- do not panic on a stack.yaml rev pin [PR #5310 @arpitjain099]
- report scanner errors and raise the line cap in metadata parsers [PR #5353 @wagoodman]
- Harden cataloger parsers against truncated input (do not panic) [PR #5355 @wagoodman]
- bound CPE candidate generation for pathological package metadata [PR #5356 @wagoodman]
- account for UPX's loader padding when unpacking Go binaries [PR #5347 @huuyafwww]
- handle malformed GGUF headers without panicking [PR #5345 @wagoodman]
- bound model companion file reads and validate their contents [PR #5344 @wagoodman]
- don't fail the whole SBOM when a cataloger panics on one file [PR #5342 @wagoodman]
- release package collection lock in Ubuntu ESM detection [PR #5336 @sverrirsig]
- render TUI log lines on their own rows, with colors and a small header [PR #5324 @wagoodman]
- uv.lock: dependents are linked to every locked version of a dependency [Issue #5340] [PR #5351 @devtechedge]
- java-archive-cataloger maps Apache Groovy 4+ (org.apache.groovy) to obsolete org.codehaus.groovy [Issue #5311] [PR #5313 @texasich]
- Support traefik binary various versions [Issue #4980] [PR #5281 @mayanksekhar]
- File Digests Remain at Zero, No Hashes Available Despite .syft.yaml Settings Should Support [Issue #5325] [PR #5341 @wagoodman]
- not showing expat CVEs from syft generated sbom [Issue #4771] [PR #5259 @KR-Ravindra]
- PHP extensions are cataloged as upstream products using the PHP version [Issue #5014] [PR #5102 @pujitha24]
- Panic during scanning with gguf-cataloger/safetensors-cataloger [Issue #5327] [PR #5328 @tk1475]
- github-actions cataloger emits an invalid PURL for docker:// use statements [Issue #5299] [PR #5302 @yunaremaia]
- Crash when running syft on a directory that is the root file system of a Yocto build [Issue #5320] [PR #5321 @somaz94]
- Invalid PURLs when cataloging instrumentation classes/jars [Issue #2596]
Dependencies
79 dependency changes (48 updated, 28 added, 3 removed). 2 vulnerabilities remediated.
🟢 Remediated (2)
- GHSA-8wmf-6v46-5gfg (Low) — go.opentelemetry.io/otel/sdk
- GHSA-pg57-6jwg-q645 (Medium) — github.com/containerd/containerd/v2
Toolchains (1)
- Go minimum version:
1.26.3→1.26.8