Ecosyste.ms: Issues

An open API service for providing issue and pull request metadata for open source projects.

GitHub / anchore/grype issues and pull requests

#1998 - chore(deps): update tools to latest versions

Pull Request - State: closed - Opened by anchore-actions-token-generator[bot] 4 months ago
Labels: dependencies

#1997 - chore(deps): bump github.com/google/go-containerregistry from 0.20.0 to 0.20.1

Pull Request - State: closed - Opened by dependabot[bot] 4 months ago
Labels: dependencies, go

#1996 - chore: request artifact in issue template

Pull Request - State: closed - Opened by willmurphyscode 4 months ago
Labels: documentation, changelog-ignore

#1995 - Grype report showing wrong installed version for commons-beanutils jar.

Issue - State: closed - Opened by ayushs2k1 4 months ago - 3 comments

#1994 - docs: CODE_OF_CONDUCT.md

Pull Request - State: closed - Opened by popey 4 months ago
Labels: changelog-ignore

#1993 - Does grype support openeuler system?

Issue - State: open - Opened by DaddyXz 4 months ago - 2 comments
Labels: enhancement

#1992 - chore(deps): bump anchore/sbom-action from 0.16.1 to 0.17.0

Pull Request - State: open - Opened by dependabot[bot] 5 months ago
Labels: dependencies, github_actions

#1991 - chore(deps): bump github.com/charmbracelet/lipgloss from 0.11.1 to 0.12.1

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago
Labels: dependencies, go

#1990 - chore(deps): bump github/codeql-action from 3.25.11 to 3.25.12

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago
Labels: dependencies, github_actions

#1989 - chore(deps): update tools to latest versions

Pull Request - State: closed - Opened by anchore-actions-token-generator[bot] 5 months ago
Labels: dependencies

#1988 - False positive: GHSA-g3rq-g295-4j3m (CVE-2020-28493) python3-Jinja2 in SLES 15.5 Ecosystem

Issue - State: open - Opened by sekveaja 5 months ago - 4 comments
Labels: bug, blocked

#1986 - chore(deps): update Syft to v1.9.0

Pull Request - State: closed - Opened by anchore-actions-token-generator[bot] 5 months ago - 1 comment

#1985 - chore(deps): bump gorm.io/gorm from 1.25.10 to 1.25.11

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago - 3 comments
Labels: dependencies, go

#1983 - chore(deps): bump github.com/charmbracelet/lipgloss from 0.11.0 to 0.11.1

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago - 1 comment
Labels: dependencies, go

#1982 - chore(deps): bump actions/setup-go from 5.0.1 to 5.0.2

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago
Labels: dependencies, github_actions

#1981 - chore(deps): bump anchore/sbom-action from 0.16.0 to 0.16.1

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago
Labels: dependencies, github_actions

#1980 - chore(deps): bump github.com/adrg/xdg from 0.4.0 to 0.5.0

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago - 1 comment
Labels: dependencies, go

#1979 - chore(deps): bump github.com/google/go-containerregistry from 0.19.2 to 0.20.0

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago - 1 comment
Labels: dependencies, go

#1978 - False Positive: GHSA-5mj6-643f-2g85 (CVE-2013-2256),.... python3-nova Openstack

Issue - State: open - Opened by sekveaja 5 months ago - 1 comment
Labels: bug, blocked

#1977 - chore(deps): bump actions/upload-artifact from 4.3.3 to 4.3.4

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago
Labels: dependencies, github_actions

#1976 - Fix: Fully validate `vulnerability.db` by hash

Pull Request - State: open - Opened by joshuai96 5 months ago - 6 comments
Labels: blocked

#1975 - `db status` does not validate `vulnerability.db`

Issue - State: closed - Opened by joshuai96 5 months ago - 3 comments
Labels: bug, database

#1974 - docs: update readme with new default cyclone-dx format v1.6

Pull Request - State: closed - Opened by spiffcs 5 months ago
Labels: changelog-ignore

#1973 - epss score in grype results

Issue - State: open - Opened by TimBrown1611 5 months ago
Labels: enhancement

#1972 - test: update quality gate db to latest version

Pull Request - State: closed - Opened by anchore-actions-token-generator[bot] 5 months ago
Labels: changelog-ignore, test

#1971 - chore(deps): bump github.com/docker/docker from 26.1.4+incompatible to 27.0.3+incompatible

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago - 2 comments
Labels: dependencies, go

#1970 - support cvss 4.0

Issue - State: open - Opened by tomersein 5 months ago - 5 comments
Labels: enhancement

#1969 - chore(deps): update tools to latest versions

Pull Request - State: closed - Opened by anchore-actions-token-generator[bot] 5 months ago
Labels: dependencies

#1968 - chore(deps): bump github/codeql-action from 3.25.10 to 3.25.11

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago
Labels: dependencies, github_actions

#1967 - chore(deps): bump github.com/docker/docker from 26.1.4+incompatible to 27.0.2+incompatible

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago - 1 comment
Labels: dependencies, go

#1966 - chore: pin new sign installer to commit sha

Pull Request - State: closed - Opened by spiffcs 5 months ago
Labels: changelog-ignore

#1965 - False positive: GHSA-v5h6-c2hv-hv3r (CVE-2024-27280) ruby2.5-stdlib in SLES 15.5 Ecosystem

Issue - State: open - Opened by sekveaja 5 months ago - 1 comment
Labels: bug, blocked

#1964 - chore(deps): bump github.com/docker/docker from 26.1.4+incompatible to 27.0.1+incompatible

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago - 1 comment
Labels: dependencies, go

#1963 - chore(deps): bump github.com/charmbracelet/bubbletea from 0.26.5 to 0.26.6

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago
Labels: dependencies, go

#1962 - chore(deps): update tools to latest versions

Pull Request - State: closed - Opened by anchore-actions-token-generator[bot] 5 months ago
Labels: dependencies

#1961 - chore: add workflow to update quality test db

Pull Request - State: closed - Opened by spiffcs 5 months ago - 1 comment
Labels: changelog-ignore

#1960 - chore: update test_db_url

Pull Request - State: closed - Opened by spiffcs 5 months ago
Labels: changelog-ignore

#1959 - chore(deps): bump github.com/hashicorp/go-getter from 1.7.4 to 1.7.5

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago - 1 comment
Labels: dependencies, go

#1958 - chore(deps): bump github.com/go-test/deep from 1.1.0 to 1.1.1

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago - 1 comment
Labels: dependencies, go

#1957 - chore(deps): bump github.com/anchore/syft from 1.7.0 to 1.8.0

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago - 1 comment
Labels: dependencies, go

#1956 - Possible FP - CVE-2019-10222 ceph in ec2 linux

Issue - State: open - Opened by tomersein 5 months ago - 5 comments
Labels: bug

#1955 - chore(deps): bump github.com/charmbracelet/bubbletea from 0.26.4 to 0.26.5

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago
Labels: dependencies, go

#1954 - chore(deps): bump peter-evans/create-pull-request from 6.0.5 to 6.1.0

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago
Labels: dependencies, github_actions

#1953 - chore: enable dependabot to keep boostrap action updated

Pull Request - State: closed - Opened by westonsteimel 5 months ago
Labels: changelog-ignore

#1951 - Grype appears to be writing v1.6 spec cyclonedx files that grype itself cannot read (affects 0.79.0+)

Issue - State: closed - Opened by ragaskar 5 months ago - 10 comments
Labels: bug, changelog-ignore

#1950 - fix: use location `RealPath` not `String()` for match sorting

Pull Request - State: closed - Opened by luhring 5 months ago
Labels: bug

#1949 - chore: update CI to install golang at latest version

Pull Request - State: closed - Opened by spiffcs 5 months ago

#1948 - chore(deps): bump github.com/google/go-containerregistry from 0.19.1 to 0.19.2

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago
Labels: dependencies, go

#1947 - chore(deps): bump github.com/spf13/cobra from 1.8.0 to 1.8.1

Pull Request - State: closed - Opened by dependabot[bot] 5 months ago
Labels: dependencies, go

#1946 - feat: pass thru the cpe source if available

Pull Request - State: open - Opened by zhill 6 months ago - 1 comment

#1945 - chore: Update syft v1.7.0

Pull Request - State: closed - Opened by spiffcs 6 months ago
Labels: changelog-ignore

#1944 - fix match sort ordering for different locations

Pull Request - State: closed - Opened by luhring 6 months ago
Labels: bug

#1943 - chore(deps): update tools to latest versions

Pull Request - State: closed - Opened by anchore-actions-token-generator[bot] 6 months ago
Labels: dependencies

#1942 - chore(deps): bump github.com/docker/docker from 26.1.4+incompatible to 27.0.0+incompatible

Pull Request - State: closed - Opened by dependabot[bot] 6 months ago - 1 comment
Labels: dependencies, go

#1941 - chore(deps): bump actions/checkout from 4.1.6 to 4.1.7

Pull Request - State: closed - Opened by dependabot[bot] 6 months ago
Labels: dependencies, github_actions

#1940 - chore(deps): bump github/codeql-action from 3.25.8 to 3.25.10

Pull Request - State: closed - Opened by dependabot[bot] 6 months ago
Labels: dependencies, github_actions

#1939 - grype db is not being downloaded

Issue - State: closed - Opened by tomersein 6 months ago - 18 comments
Labels: bug, database

#1938 - Can you control the internal format used by Syft when scanning a directory?

Issue - State: closed - Opened by tomasr 6 months ago - 10 comments
Labels: enhancement

#1937 - False positive: GHSA-m2qf-hxjv-5gpq (CVE-2023-30861) python3-Flash in SLES 15.5 Ecosystem

Issue - State: open - Opened by sekveaja 6 months ago - 1 comment
Labels: bug, blocked

#1936 - False positive: GHSA-xg9f-g7g7-2323 (CVE-2023-25577) python3-Werkzeug in SLES 15.5 Ecosystem

Issue - State: open - Opened by sekveaja 6 months ago - 2 comments
Labels: bug, blocked

#1934 - Updating maven URLs in README.md

Pull Request - State: closed - Opened by JoshuaCooper 6 months ago
Labels: documentation

#1933 - Sort order for matches should consider fix info

Pull Request - State: closed - Opened by wagoodman 6 months ago
Labels: bug

#1932 - Look at package rebuild info on advisories for indirect matches

Issue - State: open - Opened by wagoodman 6 months ago - 2 comments
Labels: enhancement, needs-investigation

#1931 - Prefer direct match information over indirect matches

Issue - State: closed - Opened by wagoodman 6 months ago - 5 comments
Labels: enhancement

#1930 - Remove wordpress mentions in false positive list

Issue - State: closed - Opened by Javiery3889 6 months ago - 2 comments
Labels: changelog-ignore

#1929 - False positive: GHSA-w596-4wvx-j9j6 (CVE-2022-42969) in SLES 15.5 Ecosystem

Issue - State: open - Opened by sekveaja 6 months ago
Labels: bug, false-positive

#1928 - chore(deps): bump github.com/anchore/syft from 1.5.0 to 1.6.0

Pull Request - State: closed - Opened by dependabot[bot] 6 months ago - 1 comment
Labels: dependencies, go

#1927 - False positive: GHSA-v3c5-jqr6-7qm8 (CVE-2022-40899) python3-future in SLES 15.5 Ecosystem

Issue - State: open - Opened by sekveaja 6 months ago
Labels: bug, false-positive

#1926 - chore(deps): update Syft to v1.6.0

Pull Request - State: closed - Opened by anchore-actions-token-generator[bot] 6 months ago
Labels: dependencies

#1925 - chore(deps): update tools to latest versions

Pull Request - State: closed - Opened by anchore-actions-token-generator[bot] 6 months ago
Labels: dependencies

#1924 - False positive: GHSA-qwmp-2cf2-g9g6 (CVE-2022-40898) python3-wheel SLES 15.5 Ecosystem create by Syft noise

Issue - State: open - Opened by sekveaja 6 months ago - 1 comment
Labels: bug, false-positive

#1923 - False positive: GHSA-v973-fxgf-6xhp (CVE-2022-40023) python3-Mako in SLES 15.5 Ecosystem

Issue - State: open - Opened by sekveaja 6 months ago
Labels: bug, false-positive

#1922 - Exit with a different return code for a failed scan

Issue - State: open - Opened by Oh-Py-God 6 months ago - 1 comment
Labels: enhancement

#1922 - Exit with a different return code for a failed scan

Issue - State: open - Opened by Oh-Py-God 6 months ago - 2 comments
Labels: enhancement

#1921 - chore(deps): update tools to latest versions

Pull Request - State: closed - Opened by anchore-actions-token-generator[bot] 6 months ago
Labels: dependencies

#1921 - chore(deps): update tools to latest versions

Pull Request - State: closed - Opened by anchore-actions-token-generator[bot] 6 months ago
Labels: dependencies

#1920 - chore(deps): bump actions/checkout from 4.1.1 to 4.1.6

Pull Request - State: closed - Opened by dependabot[bot] 6 months ago
Labels: dependencies, github_actions

#1919 - chore(deps): update tools to latest versions

Pull Request - State: closed - Opened by anchore-actions-token-generator[bot] 6 months ago
Labels: dependencies

#1918 - Deduplicate vulnerabilities for SUSE linux

Issue - State: open - Opened by wagoodman 6 months ago
Labels: enhancement

#1918 - Deduplicate vulnerabilities for SUSE linux

Issue - State: open - Opened by wagoodman 6 months ago
Labels: enhancement

#1917 - Add `--from` flag

Issue - State: open - Opened by kzantow 6 months ago
Labels: enhancement

#1916 - chore(deps): bump github.com/docker/docker from 26.1.3+incompatible to 26.1.4+incompatible

Pull Request - State: closed - Opened by dependabot[bot] 6 months ago
Labels: dependencies, go

#1915 - Add skopeo to managed utilities

Pull Request - State: closed - Opened by wagoodman 6 months ago - 2 comments
Labels: changelog-ignore

#1914 - Remove DCO workflow

Pull Request - State: closed - Opened by wagoodman 6 months ago
Labels: changelog-ignore

#1914 - Remove DCO workflow

Pull Request - State: closed - Opened by wagoodman 6 months ago
Labels: changelog-ignore

#1914 - Remove DCO workflow

Pull Request - State: closed - Opened by wagoodman 6 months ago
Labels: changelog-ignore

#1913 - FP CVE-2024-20932 on jdk8

Issue - State: open - Opened by tomersein 6 months ago - 2 comments
Labels: bug, false-positive, changelog-ignore

#1913 - FP CVE-2024-20932 on jdk8

Issue - State: open - Opened by tomersein 6 months ago - 2 comments
Labels: bug, false-positive, changelog-ignore

#1913 - FP CVE-2024-20932 on jdk8

Issue - State: open - Opened by tomersein 6 months ago - 2 comments
Labels: bug, false-positive, changelog-ignore

#1912 - chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.8.0 to 0.9.0

Pull Request - State: closed - Opened by dependabot[bot] 6 months ago - 1 comment
Labels: dependencies, go

#1911 - chore(deps): update tools to latest versions

Pull Request - State: closed - Opened by anchore-actions-token-generator[bot] 6 months ago
Labels: dependencies

#1911 - chore(deps): update tools to latest versions

Pull Request - State: closed - Opened by anchore-actions-token-generator[bot] 6 months ago
Labels: dependencies

#1911 - chore(deps): update tools to latest versions

Pull Request - State: closed - Opened by anchore-actions-token-generator[bot] 6 months ago
Labels: dependencies

#1910 - Use tool for DCO checks

Pull Request - State: closed - Opened by wagoodman 6 months ago
Labels: changelog-ignore

#1909 - chore(deps): bump github/codeql-action from 3.25.7 to 3.25.8

Pull Request - State: closed - Opened by dependabot[bot] 6 months ago - 1 comment
Labels: dependencies, github_actions