- Bump Grype version from 0.69.1 to 0.73.1. [Ben Dalling]
- Increment release to fix 1.21.7 overwrite. [Ben Dalling]
-
Build(deps): bump urllib3 from 2.0.6 to 2.0.7. [dependabot[bot]]
Bumps urllib3 from 2.0.6 to 2.0.7.
updated-dependencies:
- dependency-name: urllib3 dependency-type: direct:production ...
-
Build(deps): bump gitpython from 3.1.35 to 3.1.37. [dependabot[bot]]
Bumps gitpython from 3.1.35 to 3.1.37.
updated-dependencies:
- dependency-name: gitpython dependency-type: direct:production ...
- Bump the version of Grype from 0.67.0 to 0.69.1. [Ben Dalling]
-
Build(deps): bump urllib3 from 2.0.2 to 2.0.6. [dependabot[bot]]
Bumps urllib3 from 2.0.2 to 2.0.6.
updated-dependencies:
- dependency-name: urllib3 dependency-type: direct:production ...
- Bump Grype version from 0.66.0 to 0.67.0. [Ben Dalling]
-
Build(deps): bump gitpython from 3.1.34 to 3.1.35. [dependabot[bot]]
Bumps gitpython from 3.1.34 to 3.1.35.
updated-dependencies:
- dependency-name: gitpython dependency-type: direct:production ...
-
Build(deps): bump gitpython from 3.1.32 to 3.1.34. [dependabot[bot]]
Bumps gitpython from 3.1.32 to 3.1.34.
updated-dependencies:
- dependency-name: gitpython dependency-type: direct:production ...
- Bump Grype from 0.64.0 to 0.66.0. [Ben Dalling]
-
Build(deps): bump gitpython from 3.1.31 to 3.1.32. [dependabot[bot]]
Bumps gitpython from 3.1.31 to 3.1.32.
updated-dependencies:
- dependency-name: gitpython dependency-type: direct:production ...
-
Unfixed CVE-2023-36632 (II). [Ben Dalling]
-
Unfixed CVE-2023-36632. [Ben Dalling]
- Bump Grype version from 0.63.1 to 0.64.0. [Ben Dalling]
- Correct issue when "Severity" is stored in related issues. [Ben Dalling]
-
Bump Grype version from 0.62.3 to 0.63.1. [Ben Dalling]
-
Bump Anchore Grype from 0.62.1 to 0.62.3. [Ben Dalling]
-
Bump Anchore Grype version from 0.62.1 to 0.62.3. [Ben Dalling]
- Update the Docker installation method on the image. [Ben Dalling]
- Bump Anchore Grype from 0.62.0 to 0.62.1. [Ben Dalling]
- Add --by-cve flags. [Ben Dalling]
- Bump Anchore Grype from 0.61.1 to 0.62.0. [Ben Dalling]
-
GHSA-p782-xgp4-8hr8 no longer found in any test scenario. [Ben Dalling]
-
GHSA-83g2-8m93-v3w7 no longer found in any test scenario. [Ben Dalling]
-
Update docker/login-action version tag. [Ben Dalling]
- Bump the underlying Grype version from 0.59.0 to 0.61.1. [Ben Dalling]
- Add GHSA-vvpx-j8f3-3w6h to the allowed list. [Ben Dalling]
- Bump Grype version from 0.56.0 to 0.59.0. [Ben Dalling]
-
Correct false reporting of if fixed vulnerabilities are being checked. [Ben Dalling]
-
Remove libperl5.32 from the build (CVE-2020-16156). [Ben Dalling]
-
CVE-2022-2097 is no longer found. [Ben Dalling]
-
Add vulnerabilities to the allowed list for Grype itself. [Ben Dalling]
-
Make CLI interpretation more flexible. [Ben Dalling]
- Bump Grype version from 0.55.0 to 0.56.0. [Ben Dalling]
- CVE-2015-5237 & CVE-2021-22570 are resolved. [Ben Dalling]
- Bump Grype from 0.54.0 to 0.55.0. [Ben Dalling]
- Resolve GHSA-r9hx-vwmv-q579/CVE-2022-40897. [Ben Dalling]
- Bump Grype version from 0.53.1 to 0.54.0. [Ben Dalling]
- Remove CVE-2021-46848 from the non-fixed, allowed vulnerability list. [Ben Dalling]
-
Migrate from Docker Hub to GitHub Container Registry. [Ben Dalling]
-
Bump Grype from 0.52.0 to 0.53.1. [Ben Dalling]
-
Build(deps): bump certifi from 2022.9.24 to 2022.12.7. [dependabot[bot]]
Bumps certifi from 2022.9.24 to 2022.12.7.
updated-dependencies:
- dependency-name: certifi dependency-type: direct:production ...
- Bump underlying Grype version from 0.50.2 to 0.52.0. [Ben Dalling]
- Bump Grype to 0.51.0. [Ben Dalling]
- Bump the underlying version of Grype from 0.50.1 to 0.50.2. [Ben Dalling]
- Bump the underlying Anchore Grype version from 0.49.0 to 0.50.1. [Ben Dalling]
-
Bug: fix: Remove vulnerabilities from scenarios that are no longer found. [Ben Dalling]
-
Doc: fix: Correct CONTRIBUTING.md. [Ben Dalling]
-
Build(deps): bump mako from 1.1.3 to 1.2.2. [dependabot[bot]]
Bumps mako from 1.1.3 to 1.2.2.
updated-dependencies:
- dependency-name: mako dependency-type: direct:production ...
- Add the ADD_CPES_IF_NONE option. [Ben Dalling]
-
Bump underlying Grype version from 0.48.0 to 0.49.0. [Ben Dalling]
-
Bump the version of Grype from 0.40.1 to 0.47.0. [Ben Dalling]
- Ensure allowed bugs are registered as found. [Ben Dalling]
- Bump the version of Grype from 0.47.0 to 0.48.0. [Ben Dalling]
- Add the Bandit analyzer. [Ben Dalling]
- Bump Grype version from 0.40.0 to 0.40.1. [Ben Dalling]
-
Implement Code Climate improvements. [Ben Dalling]
-
Bump Grype version from 0.39.0 to 0.40.0. [Ben Dalling]
-
Update non-fixed allowed vulnerability list. [Ben Dalling]
-
Bump the version of Anchore Grype from 0.37.0 to 0.39.0. [Ben Dalling]
- Bump the version of Anchore Grype from 0.35.0 to 0.37.0. [Ben Dalling]
-
No longer finding CVE-2022-21698, CVE-2022-24778 or GHSA-8v99-48m9-c8pm in the scan. [Ben Dalling]
-
Add CVE-2022-29458 to non-fixed allowed list. [Ben Dalling]
- Bump Grype version from 0.34.7 to 0.35.0. [Ben Dalling]
- Add GHSA-8v99-48m9-c8pm to the allowed list. [Ben Dalling]
-
Build(deps): bump paramiko from 2.7.2 to 2.10.1. [dependabot[bot]]
Bumps paramiko from 2.7.2 to 2.10.1.
updated-dependencies:
- dependency-name: paramiko dependency-type: direct:production ...
-
Bump image of Grype from 0.34.6 to 0.34.7. [Ben Dalling]
-
Add GHSA-c3xm-pvg7-gh7r, GHSA-fgv8-vj5c-2ppq & GHSA-q3j5-32m5-58c2 to the allowed list. [Ben Dalling]
-
Bump version of Anchore Grype from 0.34.3 to 0.34.6. [Ben Dalling]
-
Update allowed vulnerabilities list. [Ben Dalling]
-
Simply build with the latest Python 3 Docker image. [Ben Dalling]
-
Attempt to fix CVE-2022-0778. [Ben Dalling]
- Bump the Grype version from 0.33.0 to 0.34.3. [Ben Dalling]
- Fix build process to ensure requested version is installed. [Ben Dalling]
-
Bump Python version from 3.10.1 to 3.10.2. [Ben Dalling]
-
Ensure a specific version (0.33.0) of Grype is installed. [Ben Dalling]
- Add ShellCheck to CI. [Ben Dalling]
-
Bump Grype version from 0.31.1 to 0.32.0. [Ben Dalling]
-
Add test scenarios for with/without only fixed. [Ben Dalling]
-
Update from ancient versions of Docker in documentation. [Ben Dalling]
- Still run when not using only-fixed. [Ben Dalling]
- Bump Grype version from 0.28.0 to 0.31.1. [Ben Dalling]
- Stop shell diagnosic message appearing on the console. [Ben Dalling]
- Anchore Grype 0.28.0 is available. [Ben Dalling]
- Fix issues with tagging at release time. [Ben Dalling]
-
Bump the base image to python:3.10.1. [Ben Dalling]
-
New verion of Grype (0.27.3) is available. [Ben Dalling]
- GHSA-c3xm-pvg7-gh7r no longer present. [Ben Dalling]
- Add the ONLY_FIXED flag. [Ben Dalling]
- Bump Grype from 0.25.0 to 0.25.1. [Ben Dalling]
- Bump the version of Grype from 0.24.1 to 0.25.0. [Ben Dalling]
- GHSA-25xm-hr59-7c27 no longer being detected. [Ben Dalling]
-
Bump expected Grype version from 0.24.0 to 0.24.1. [Ben Dalling]
-
Bump Grype version from 0.23.0 to 0.24.0. [Ben Dalling]
- Add to the VULNERABILITIES_ALLOWED_LIST. [Ben Dalling]
- Bump Grype version from 0.17.0 to 0.23.0. [Ben Dalling]
-
Resolve vulnerability CVE-2021-41617. [Ben Dalling]
-
Resolve vulnerabilities CVE-2021-22945 & CVE-2021-22946. [Ben Dalling]
-
Bump base image from python:3.9.6 to python:3.10.0. This resolves the following vulnerabilities CVE-2021-3711, CVE-2021-3712 & CVE-2021-35940. [Ben Dalling]
- Bump the Grype version from 0.15.0 to 0.17.0. [Ben Dalling]
-
Add CVE-2021-29921 to VULNERABILITIES_ALLOWED_LIST. [Ben Dalling]
-
Remove CVE-2019-25013 from VULNERABILITIES_ALLOWED_LIST. [Ben Dalling]
-
Bump base Python image to latest stable (3.9.6). [Ben Dalling]
-
Bump expected Grype version from 0.13.0 to 0.15.0. [Ben Dalling]
- Bump base (Python) image from 3.9.4 to 3.9.5. [Ben Dalling]
- Remove CVE-2021-20231, CVE-2021-20232 and CVE-2021-20305 from the allowed list. [Ben Dalling]
- Add CVE-2021-33574 to the allowed list. [Ben Dalling]
-
Minor documentation additions and corrections. [Ben Dalling]
-
Bump Grype version from 0.12.1 to 0.13.0. [Ben Dalling]
-
Build(deps): bump urllib3 from 1.26.4 to 1.26.5. [dependabot[bot]]
Bumps urllib3 from 1.26.4 to 1.26.5.
updated-dependencies:
- dependency-name: urllib3 dependency-type: direct:production ...
- Bump Grype version from 0.11.0 to 0.12.1. [Ben Dalling]
-
Resolve CVE-2021-3517. [Ben Dalling]
-
Resolve CVE-2018-20225, CVE-2018-25011, CVE-2018-25014, CVE-2020-36328 & CVE-2020-36329. [Ben Dalling]
-
Correct lint issue in Dockerfile. [Ben Dalling]
-
Bump the expected version of Grype tp 0.11.0. [Ben Dalling]
-
Bump base Docker image for 3.9.4. [Ben Dalling]
- Add CVE-2021-20305 to the accepted risks. [Ben Dalling]
- Grype updated from 0.8.0 to 0.9.0. [Ben Dalling]
-
CVE-2021-3177 no longer being idendified as a vulnerability. [Ben Dalling]
-
Sort out the template for pull requests. [Ben Dalling]
-
Build(deps): bump urllib3 from 1.26.3 to 1.26.4. [dependabot[bot]]
Bumps urllib3 from 1.26.3 to 1.26.4.
-
Build(deps): bump pyyaml from 5.3.1 to 5.4. [dependabot[bot]]
Bumps pyyaml from 5.3.1 to 5.4.
- Bump base image from Python 3.8 to 3.9.2. [Ben Dalling]
- Add CVE-2021-20231 and CVE-2021-20232 to the whitelist. [Ben Dalling]
- Bump Grype version from 0.7.0 to 0.8.0. [Ben Dalling]
-
CVE-2018-20225 no longer an issue. [Ben Dalling]
-
Purge config durng autoremove. [Ben Dalling]
-
Build(deps): bump urllib3 from 1.26.2 to 1.26.3. [dependabot[bot]]
Bumps urllib3 from 1.26.2 to 1.26.3.
- Update Drone CI example. [Ben Dalling]
- Correct the number of columns in the vulnerability report. [Ben Dalling]
- Correct example code highlighting. [Ben Dalling]
-
Build(deps): bump cryptography from 3.3.1 to 3.3.2. [dependabot[bot]]
Bumps cryptography from 3.3.1 to 3.3.2.
- Add Drone CI (Kubernetes pipeline) example. [Ben Dalling]
- Stop dublicate vulnerabilitity reports. [Ben Dalling]
- Document persisting the Grype DB. [Ben Dalling]
- Docker Compose example testing on MacOS. [Ben Dalling]
- Remove CVE-2020-29363 and add CVE-2021-3177 to the allowed list. [Ben Dalling]
- Add the SHOW_ALL_VULNERABILITIES option. [Ben Dalling]
-
Documentation updates. [Ben Dalling]
-
Update the Grype version from 0.6.1 to 0.7.0. [Ben Dalling]
-
Remove tests link section as this is handled in GitHub well enough. [Ben Dalling]
-
Avoid DL3005 in hadolint. [Ben Dalling]
-
Update issue templates. [Ben Dalling]
-
Create CODE_OF_CONDUCT.md. [Ben Dalling]
- Warn if an entry in allowed list is not found in the scan. [Ben Dalling]
- Added CVE-2019-25013 to the allowed list. [Ben Dalling]
- Resolve CVE-2020-27843 & CVE-2020-27844. [Ben Dalling]
- Correct the example Docker Compose. [Ben Dalling]
-
All the user to login to Docker. [Ben Dalling]
-
YAML Lint Check. [Ben Dalling]
-
Allow CI build to be skipped. [Ben Dalling]
-
Resolve bad link issue. [Ben Dalling]
-
Migrate from GitFlow to GitHub Flow. [Ben Dalling]
- Enable continuous deployment. [Ben Dalling]
-
Add documentaion on options. [Ben Dalling]
-
Create automated change log mechanism. [Ben Dalling]
-
Add Docker Compose example. [Ben Dalling]
-
Implement CI. [Ben Dalling]
-
Implement an allowed list. [Ben Dalling]
-
Create a Docker image for Grype and verify the version (0.6.1). [Ben Dalling]