Skip to content
This repository was archived by the owner on Oct 14, 2024. It is now read-only.

chore(deps): bump github.com/anchore/grype from 0.65.2 to 0.74.0 #1096

Merged
merged 5 commits into from
Feb 1, 2024

Conversation

dependabot[bot]
Copy link
Contributor

@dependabot dependabot bot commented on behalf of github Jan 16, 2024

Bumps github.com/anchore/grype from 0.65.2 to 0.74.0.

Release notes

Sourced from github.com/anchore/grype's releases.

v0.74.0

Added Features

  • Vulnerabilities marked as fixed in distro packages should be reported as fixed for all contained packages too [#1236 #1603 @​luhring]

Bug Fixes

  • Parameter quiet is ignored in configuration file [#1645 #1646 @​plavy]
  • 401 unauthorized pulling from public registry [#1637]

Additional Changes

  • Update Syft to 0.100.0 [#1649]

(Full Changelog)

v0.73.5

Additional Changes

(Full Changelog)

v0.73.4

Additional Changes

(Full Changelog)

v0.73.3

Additional Changes

(Full Changelog)

v0.73.2

Bug Fixes

(Full Changelog)

v0.73.1

Bug Fixes

... (truncated)

Commits
  • a808408 chore(deps): update Syft to v0.100.0 (#1649)
  • 474030c fix: distro FP data not applied correctly (#1603)
  • 33b1573 chore(deps): bump anchore/sbom-action from 0.15.1 to 0.15.2 (#1647)
  • c6fbffe chore(deps): update bootstrap tools to latest versions (#1644)
  • 89610e1 docs: fix logging configuration in README (#1646)
  • 55ef6b6 chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.7.2 to 0.8.0 (#1633)
  • 634cdf3 chore(deps): bump golang.org/x/crypto from 0.16.0 to 0.17.0 (#1641)
  • 010b258 chore(deps): bump github.com/containerd/containerd from 1.7.8 to 1.7.11 (#1642)
  • a88a00a chore(deps): bump actions/upload-artifact from 3.1.3 to 4.0.0 (#1638)
  • 556c8c0 chore(deps): bump sigstore/cosign-installer from 3.2.0 to 3.3.0 (#1632)
  • Additional commits viewable in compare view

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot merge will merge this PR after your CI passes on it
  • @dependabot squash and merge will squash and merge this PR after your CI passes on it
  • @dependabot cancel merge will cancel a previously requested merge and block automerging
  • @dependabot reopen will reopen this PR if it is closed
  • @dependabot close will close this PR and stop Dependabot recreating it. You can achieve the same result by closing it manually
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore <dependency name> major version will close this group update PR and stop Dependabot creating any more for the specific dependency's major version (unless you unignore this specific dependency's major version or upgrade to it yourself)
  • @dependabot ignore <dependency name> minor version will close this group update PR and stop Dependabot creating any more for the specific dependency's minor version (unless you unignore this specific dependency's minor version or upgrade to it yourself)
  • @dependabot ignore <dependency name> will close this group update PR and stop Dependabot creating any more for the specific dependency (unless you unignore this specific dependency or upgrade to it yourself)
  • @dependabot unignore <dependency name> will remove all of the ignore conditions of the specified dependency
  • @dependabot unignore <dependency name> <ignore condition> will remove the ignore condition of the specified dependency and ignore conditions

@dependabot dependabot bot requested a review from a team as a code owner January 16, 2024 04:54
@dependabot dependabot bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Jan 16, 2024
@paralta paralta force-pushed the dependabot/go_modules/github.com/anchore/grype-0.74.0 branch from eb1c3b1 to 0c379c4 Compare January 16, 2024 12:12
@paralta
Copy link
Contributor

paralta commented Jan 17, 2024

Currently failing with

1.164 /go/pkg/mod/github.com/aquasecurity/[email protected]/pkg/sbom/cyclonedx/core/cyclonedx.go:186:10: cannot use &[]cdx.Tool{…} (value of type *[]cyclonedx.Tool) as *cyclonedx.ToolsChoice value in struct literal
1.164 /go/pkg/mod/github.com/aquasecurity/[email protected]/pkg/sbom/cyclonedx/core/cyclonedx.go:315:23: cannot range over *c.Metadata.Tools (variable of type cyclonedx.ToolsChoice)

Copy link
Contributor Author

dependabot bot commented on behalf of github Jan 18, 2024

A newer version of github.com/anchore/grype exists, but since this PR has been edited by someone other than Dependabot I haven't updated it. You'll get a PR for the updated version as normal once this PR is merged.

@paralta paralta self-assigned this Jan 22, 2024
@paralta
Copy link
Contributor

paralta commented Jan 23, 2024

PR to bump cyclonedx in trivy merged today! Waiting for next release 🚀

dependabot bot and others added 3 commits February 1, 2024 09:47
Bumps [github.com/anchore/grype](https://github.com/anchore/grype) from 0.65.2 to 0.74.0.
- [Release notes](https://github.com/anchore/grype/releases)
- [Changelog](https://github.com/anchore/grype/blob/main/.goreleaser.yaml)
- [Commits](anchore/grype@v0.65.2...v0.74.0)

---
updated-dependencies:
- dependency-name: github.com/anchore/grype
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <[email protected]>
@paralta paralta force-pushed the dependabot/go_modules/github.com/anchore/grype-0.74.0 branch from 0c379c4 to b0c4ac3 Compare February 1, 2024 14:38
Copy link

github-actions bot commented Feb 1, 2024

Hey!

Your images are ready:

  • ghcr.io/openclarity/vmclarity-apiserver-dev:pr1096-bce3e800f1f2f3df239bec2c443346fbb2d834d0
  • ghcr.io/openclarity/vmclarity-orchestrator-dev:pr1096-bce3e800f1f2f3df239bec2c443346fbb2d834d0
  • ghcr.io/openclarity/vmclarity-ui-backend-dev:pr1096-bce3e800f1f2f3df239bec2c443346fbb2d834d0
  • ghcr.io/openclarity/vmclarity-ui-dev:pr1096-bce3e800f1f2f3df239bec2c443346fbb2d834d0
  • ghcr.io/openclarity/vmclarity-cli-dev:pr1096-bce3e800f1f2f3df239bec2c443346fbb2d834d0

@paralta paralta removed the blocked label Feb 1, 2024
@paralta paralta added this pull request to the merge queue Feb 1, 2024
Merged via the queue into main with commit 51a7260 Feb 1, 2024
33 of 34 checks passed
@paralta paralta deleted the dependabot/go_modules/github.com/anchore/grype-0.74.0 branch February 1, 2024 15:53
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file go Pull requests that update Go code
Projects
Status: Done
Development

Successfully merging this pull request may close these issues.

2 participants