{"id":"openSUSE-SU-2026:20928-1","summary":"Security update for syft","details":"This update for syft fixes the following issues:\n\nChanges in syft:\n\n- Update to version 1.45.0:\n  * Added Features\n    - Add support for ZapAddOns as jar files [#4654 #4932\n      @douglasclarke]\n    - MySQL binary classifier should distinguish between MySQL\n      Cluster (ndb) and MySQL [#3297 #4907 @witchcraze]\n    - Catalog ingress-nginx binary [#4818 #4857 @witchcraze]\n  * Bug Fixes\n    - Support helm binary various versions [#4820 #4922\n      @witchcraze]\n    - Support julia binary various versions [#4867 #4945\n      @witchcraze]\n    - Support deno binary old versions [#4865 #4939 @witchcraze]\n    - Compressed kernel modules are not scanned by the\n      linux-kernel-cataloger [#4721 #4740 @will-bates11]\n    - Yarn Berry lockfile parser incorrectly deduplicates packages\n      with multiple resolutions [#4691 #4838 @calumleslie]\n    - Possible misdetection of AWS-LC as OpenSSL 1.1.1 [#4539 #4882\n      @witchcraze]\n    - Support elixir binary rc versions [#4819 #4851 @ChrisJr404]\n    - Exclude path ending with a slash are discarded [#4839 #4892\n      @ChrisJr404]\n    - Incorrect CPE for .NET Runtime [#4738 #4743 @PGrayCS]\n    - fix parsing of debian/copyright files [#4708 #4754 @Bahtya]\n    - Grype ignores python requirements in arbitrary equality (===)\n      format [#4834 #4835 @cyphercodes]\n    - valkey is detected as both of valkey and redis [#4591 #4619\n      @witchcraze]\n    - TypeByName missing \"nuget\" case causes UnknownPkg when\n      reading SPDX SBOMs [#4837 #4848 @ChrisJr404]\n  * Additional Changes\n    - hoist name normalization regexp to package level [#4926\n      @matiasinsaurralde]\n    - bump the actions-minor-patch group across 1 directory with 6\n      updates [#4946 @dependabot]\n    - bump the actions-minor-patch group across 2 directories with\n      2 updates [#4936 @dependabot]\n    - bump the actions-minor-patch group across 1 directory with 4\n      updates [#4927 @dependabot]\n    - bump the actions-minor-patch group across 1 directory with 2\n      updates [#4920 @dependabot]\n    - bump the actions-minor-patch group across 1 directory with 2\n      updates [#4897 @dependabot]\n    - update CPE dictionary index [#4831 @anchore-oss-update-bot]\n  * Dependencies\n    - chore(deps): bump github.com/containerd/containerd/v2 (#4935)\n    - chore(deps): update anchore dependencies (#4821)\n    - chore(deps): bump github.com/go-git/go-git/v5 from 5.19.0 to\n      5.19.1 (#4930)\n    - chore(deps): update CPE dictionary index (#4925)\n    - chore(deps): update CPE dictionary index (#4909)\n    - chore(deps): bump github.com/go-git/go-git/v5 from 5.18.0 to\n      5.19.0 (#4911)\n\n- Update to version 1.44.0:\n  * Added Features\n    - Add support for linux-riscv64 [#4757 @luhenry]\n  * Bug Fixes\n    - Yarn lockfile cataloguing does not handle aliases [#4833\n      #4836 @cyphercodes]\n    - Some snippet files are saved in the previous test directory\n      [#4829 #4830 @witchcraze]\n    - empty rockspec causes index out of range [#4824 #4827\n      @aki1770-del]\n    - PE cataloger shows asp.net core ref assemblies using\n      fileversion build stamp instead of productversion [#4813\n      #4814 @rezmoss]\n    - Syft safeCopy silently swallows archive decompression errors\n      [#4806 #4807 @SAY-5]\n\n- Update to version 1.43.0:\n  * Added Features\n    - added deno bin classifiers [#4677 @rezmoss]\n    - Support haskell old versions [#3237 #4793 @witchcraze]\n    - Add support for OpenLDAP binary detection [#4768 #4755\n      @nadimz]\n    - Support erlang ols versions [#3235 #4766 @witchcraze]\n  * Bug Fixes\n    - improve redhat-release parsing fallback for RHEL clones\n      [#4808 @westonsteimel]\n    - fix format string in search results struct [#4775\n      @willmurphyscode]\n    - prevent infinite recursion in Document.UnmarshalJSON with\n      encoding/json/v2 [#4748 @benja-M-1]\n    - Syft can not complete scanning golang image [#4686]\n    - javascript-package-cataloger drops entire package.json when\n      authors/contributors/maintainers is a single string [#4778\n      #4779 @yoav-orca]\n    - pnpm lock file cataloger produces unstable output [#4648\n      #4765 @lawrence3699]\n    - Linux Kernel bzImage and zImage not cataloged by\n      linux-kernel-cataloger [#4769 #4751 @nadimz]\n    - Support istio binary (pilot-discovery, pilot-agent)\n      alpha,beta,rc,dev version [#4546 #4645 @witchcraze]\n    - Scanning mounted ISO: duplicate entries [#4759]\n  * Additional Changes\n    - update CPE dictionary index [#4767 @anchore-oss-update-bot]\n  * Dependencies\n    - chore(deps): update anchore dependencies (#4797)\n    - chore(deps): restore Go version to 1.25.8 (#4804)\n    - chore(deps): bump the actions-minor-patch group across 1\n      directory with 2 updates (#4790)\n    - chore(deps): bump github.com/go-git/go-git/v5 from 5.17.0 to\n      5.18.0 (#4792)\n    - chore(deps): update Go version (#4798)\n    - chore(deps): update tools to latest versions (#4701)\n    - chore(deps): update Go version (#4773)\n    - chore(deps): bump github.com/aws/aws-sdk-go-v2/service/s3\n      (#4750)\n    - chore(deps): bump go.opentelemetry.io/otel/sdk from 1.40.0 to\n      1.43.0 (#4752)\n    - chore(deps): bump github.com/go-jose/go-jose/v4 from 4.1.3 to\n      4.1.4 (#4737)\n    - chore(deps): bump the actions-minor-patch group across 2\n      directories with 7 updates (#4763)\n    - chore(deps): bump github.com/hashicorp/go-getter from 1.8.5\n      to 1.8.6 (#4764)\n    - chore(deps): update CPE dictionary index (#4767)\n\n- Update to version 1.42.4:\n  * Bug Fixes\n    - Similar Packages Should Be Aggregated [#1162]\n    - Support arangodb binary recent version [#4571 #4662\n      @witchcraze]\n    - Support go binary various versions [#4687 #4694 @kzantow]\n  * Additional Changes\n    - update CPE dictionary index [#4745 @anchore-oss-update-bot]\n    - update CPE dictionary index [#4726 @anchore-oss-update-bot]\n    - Add a trust boundary section [#4716 @joshbressers]\n  * Dependencies\n    - chore(deps): update CPE dictionary index (#4745)\n    - chore(deps): update CPE dictionary index (#4726)\n    - chore(deps): update CPE dictionary index (#4715)\n    - chore(deps): update tool versions (#4706)\n    - chore(deps): bump slackapi/slack-github-action from 2.1.1 to\n      3.0.1 (#4684)\n    - chore(deps): bump marocchino/sticky-pull-request-comment\n      (#4685)\n    - chore(deps): bump the go-minor-patch group with 2 updates\n      (#4697)\n    - chore(deps): bump actions/create-github-app-token from 2.2.1\n      to 3.0.0 (#4699)\n    - chore(deps): update CPE dictionary index (#4689)\n    - chore(deps): ignore some dependabot deps (#4696)\n    - chore(deps): update tools to latest versions (#4690)\n\n- Update to version 1.42.3:\n  * Bug Fixes\n    - Missing secondary evidence for .NET dependency in\n      ghcr.io/open-telemetry/demo:2.0.0-accounting image [#4652]\n  * Additional Changes\n    - centralize temp files and prefer streaming IO [#4668\n      @willmurphyscode]\n    - chore(deps): update anchore dependencies (#4681)\n    - chore(deps): bump github.com/buger/jsonsparser to v1.1.2\n      (#4680)\n    - chore(deps): bump the go-minor-patch group with 2 updates\n      (#4678)\n    - chore(deps): bump google.golang.org/grpc from 1.78.0 to\n      1.79.3 (#4675)\n    - chore(deps): bump the go-minor-patch group with 2 updates\n      (#4674)\n    - chore(deps): update tools to latest versions (#4663)\n    - chore(deps): bump the go-minor-patch group with 3 updates\n      (#4669)\n    - chore(deps): bump github/codeql-action (#4670)\n    - chore(deps): bump docker/login-action from 3.7.0 to 4.0.0\n      (#4671)\n    - chore(deps): update CPE dictionary index (#4673)\n    - chore(tests): fix test fixture build on modern ARM Mac\n      (#4666)\n\n- Update to version 1.42.2:\n  * Bug Fixes\n    - [BUG] Incorrect Maven PURL generation: Automatic-Module-Name\n      should not be used as Maven groupId [#4611 #4642 @xnox]\n    - Checksum is 0 for spdx files [#2307 #4620 @ppalucha]\n    - Support grafana binary various versions [#4559 #4635\n      @witchcraze]\n  * Additional Changes\n    - migrate fixtures to testdata [#4651 @wagoodman]\n  * Dependencies\n    - chore(deps): update anchore dependencies (#4631)\n    - chore(deps): update tools to latest versions (#4630)\n    - chore(deps): update SPDX license list (#4637)\n    - chore(deps): bump actions/download-artifact from 7.0.0 to\n      8.0.0 (#4658)\n    - chore(deps): bump github.com/cloudflare/circl from 1.6.1 to\n      1.6.3 (#4638)\n    - chore(deps): bump the actions-minor-patch group across 2\n      directories with 2 updates (#4657)\n    - chore(deps): bump actions/upload-artifact from 6.0.0 to 7.0.0\n      (#4659)\n    - chore(deps): bump go.opentelemetry.io/otel/sdk from 1.39.0 to\n      1.40.0 (#4646)\n    - chore(deps): update CPE dictionary index (#4647)\n    - chore(deps): bump the go-minor-patch group across 1 directory\n      with 5 updates (#4661)\n    - chore(deps): update CPE dictionary index (#4636)\n    - chore(deps): bump github/codeql-action (#4634)\n    - chore(deps): bump github.com/charmbracelet/bubbles from\n      0.21.1 to 1.0.0 (#4633)\n    - chore(deps): bump the go-minor-patch group with 5 updates\n      (#4632)\n\n- Update to version 1.42.1:\n  * Bug Fixes\n    - Use redhat as namespace for hummingbird rpms [#4615 @scoheb]\n    - False Positive: Emacs snap package version CVE-2024-39331\n      [#4485]\n  * Additional Changes\n    - call cleanup on tmpfile and replace some io.ReadAlls with\n      streams [#4629 @willmurphyscode]\n    - bumps go mod version to 1.25; ci takes latest patch [#4628\n      @spiffcs]\n  * Dependencies\n    - chore(deps): update tools to latest versions (#4614)\n    - chore(deps): bump the actions-minor-patch group across 1\n      directory with 2 updates (#4622)\n    - chore(deps): bump the go-minor-patch group with 2 updates\n      (#4621)\n    - chore(deps): update CPE dictionary index (#4623)\n\n- Update to version 1.42.0:\n  * Added Features\n    - Add support for scanning GGUF models from OCI registries\n      [#4335 @spiffcs]\n    - yarn lockfile scan doesnt catch dev dependencies [#4548 #4549\n      @rezmoss]\n  * Additional Changes\n    - CPE detection for APK libavif to use aomedia vendor [#4597\n      @naag]\n  * Dependencies\n    - chore(deps): update anchore dependencies (#4613)\n    - chore(deps): bump github.com/go-git/go-git/v5 from 5.16.4 to\n      5.16.5 (#4612)\n    - chore(deps): update CPE dictionary index (#4610)\n    - chore(deps): bump github.com/bmatcuk/doublestar/v4 (#4606)\n    - chore(deps): bump the actions-minor-patch group across 2\n      directories with 2 updates (#4607)\n    - chore(deps): update CPE dictionary index (#4601)\n    - chore(deps): update tools to latest versions (#4594)\n\n- Update to version 1.41.2:\n  * Bug Fixes\n    - further improve go binary classifier, including windows\n      [#4593 @kzantow]\n    - Wrong format in license [#4233 #4588 @spiffcs]\n    - Cannot detect installation of Qt6 [#4467 #4550 @rezmoss]\n    - bug: Syft mis-identifies binary as deb inside a snap [#4486\n      #4500 @popey]\n  * Dependencies\n    - chore(deps): update tools to latest versions (#4589)\n    - chore(deps): bump the go-minor-patch group with 2 updates\n      (#4583)\n    - chore(deps): bump the actions-minor-patch group across 1\n      directory with 2 updates (#4584)\n\n- Update to version 1.41.1:\n  * Bug Fixes\n    - [Bug Report] Missing some dependencies on cyclonedx formatted\n      SBOM using syft [#4562 #4573 @spiffcs]\n  * Dependencies\n    - chore(deps): update tools to latest versions (#4577)\n\n- Update to version 1.41.0:\n  * Added Features\n    - detect Debian version from /etc/debian_version [#4569\n      @kzantow]\n  * Bug Fixes\n    - correctly report supporting evidence for binary packages\n      [#4558 @kzantow]\n  * Dependencies\n    - chore(deps): update anchore dependencies (#4575)\n    - chore(deps): update tools to latest versions (#4570)\n    - chore(deps): bump the actions-minor-patch group across 2\n      directories with 3 updates (#4568)\n    - chore(deps): bump the go-minor-patch group with 6 updates\n      (#4567)\n    - chore(deps): update tools to latest versions (#4565)\n    - chore(deps): bump github.com/spdx/tools-golang (#4557)\n\n- Update to version 1.40.1:\n  * Bug Fixes\n    - mongodb binary not detected manual/source install [#4540\n      #4541 @rezmoss]\n    - chore: sync generated file immediately (#4538)\n  * Dependencies\n    - chore(deps): update anchore dependencies (#4552)\n    - chore(deps): update tools to latest versions (#4551)\n    - chore(deps): update tools to latest versions (#4545)\n    - chore(deps): update tools to latest versions (#4542)\n    - chore(deps): bump the go-minor-patch group with 4 updates\n      (#4543)\n    - chore(deps): bump anchore/sbom-action (#4544)\n    - chore(deps): update tools to latest versions (#4537)\n\n- Update to version 1.40.0:\n  * Added Features\n    - Exclude development or test dependencies for PNPM Package\n      type [#4430 #4487 @rezmoss]\n    - Catalog istio binary (pilot-discovery, pilot-agent) [#4508\n      #4521 @witchcraze]\n    - Catalog envoy binary [#4506 #4530 @witchcraze]\n    - Catalog grafana binary [#4505 #4516 @witchcraze]\n    - Add a binary classifier for valkey [#3400 #4509 @witchcraze]\n  * Bug Fixes\n    - old bitnami images without spdx files arent getting picked up\n      correctly in the catalog [#4529 #4532 @rezmoss]\n    - wrong traefik rc versions at binary detection [#3535 #4499\n      @rezmoss]\n    - FromPOSIX() in internals\\windows\\path.go assumes that all\n      Windows root paths must have a colon terminator [#4070 #4075\n      @luissantosHCIT]\n    - binary cataloger is picking up the go version instead of the\n      actual binary version in traefik experimental images [#4498\n      #4499 @rezmoss]\n  * Dependencies\n    - chore(deps): update anchore dependencies (#4535)\n    - chore(deps): bump the go-minor-patch group with 3 updates\n      (#4524)\n    - chore(deps): bump the actions-minor-patch group across 1\n      directory with 2 updates (#4525)\n    - chore(deps): bump actions/download-artifact from 6.0.0 to\n      7.0.0 (#4526)\n    - chore(deps): bump actions/upload-artifact from 4.4.3 to 6.0.0\n      (#4527)\n    - chore(deps): bump modernc.org/sqlite from 1.41.0 to 1.42.2\n      (#4513)\n    - chore(deps): bump anchore/sbom-action from 0.20.11 to 0.21.0\n      (#4501)\n    - chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.7\n      to 6.7.8 (#4502)\n    - chore(deps): bump github.com/spdx/tools-golang from 0.5.5 to\n      0.5.6 (#4503)\n    - chore(deps): update tools to latest versions (#4504)\n    - chore(deps): bump github.com/hashicorp/go-getter from 1.8.3\n      to 1.8.4 (#4518)\n    - chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.18\n      to 0.5.19 (#4520)\n\n- Update to version 1.39.0:\n  * Added Features\n    - add support for Gemfile.next.lock [#4457 @HatiCode]\n    - Command output to give more information on what catalogers\n      look for and what they can find [#4155 #4317 @wagoodman]\n    - Support reading lzma compressed .go.buildinfo sections with\n      upx [#4411 #4480 @wagoodman]\n    - Specify specific snap revision to pull [#4389 #4439\n      @VictorHuu]\n    - Cannot detect embedded deps.json metadata in single-file .NET\n      binaries [#4344 #4375 @rezmoss]\n    - ELF note cataloger does not pick up OS field, but should\n      [#4384 #4438 @VictorHuu]\n  * Bug Fixes\n    - remove debug print statement in dependency parser [#4412\n      @cgreeno]\n    - dotnet-deps cataloger should skip project references with\n      type \"project\" when building the sbom [#4423 #4436 @rezmoss]\n    - File digests not computed when using --base-path [#4410 #4478\n      @wagoodman]\n    - Syft should not define subpaths by default in PURLs [#4394\n      #4395 @rezmoss]\n    - go: valid purl but incorrect name [#1737 #4395 @rezmoss]\n    - Incorrect Go module PURL generation when module path contains\n      /vN (e.g. /v5) [#4316 #4395 @rezmoss]\n    - Failing to convert npm repository information correctly to\n      SPDX [#4362 #4390 @kendrickm]\n  * Dependencies\n    - chore(deps): update tools to latest versions (#4491)\n    - chore(deps): bump modernc.org/sqlite from 1.40.1 to 1.41.0\n      (#4489)\n    - chore(deps): bump github/codeql-action from 4.31.8 to 4.31.9\n      (#4481)\n    - chore(deps): bump github.com/goccy/go-yaml from 1.19.0 to\n      1.19.1 (#4482)\n    - chore(deps): bump actions/cache from 5.0.0 to 5.0.1 (#4476)\n    - chore(deps): bump actions/cache in /.github/actions/bootstrap\n      (#4477)\n    - chore(deps): update tools to latest versions (#4473)\n    - chore(deps): update tools to latest versions (#4466)\n    - chore(deps): bump github/codeql-action from 4.31.7 to 4.31.8\n      (#4468)\n    - chore(deps): bump actions/cache from 4.3.0 to 5.0.0 (#4469)\n    - chore(deps): bump github.com/anchore/stereoscope from 0.1.14\n      to 0.1.16 (#4470)\n    - chore(deps): bump actions/cache in /.github/actions/bootstrap\n      (#4471)\n    - chore(deps): update tools to latest versions (#4462)\n    - chore(deps): update tools to latest versions (#4456)\n    - chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.5\n      to 6.7.7 (#4460)\n    - chore(deps): bump peter-evans/create-pull-request from 7.0.11\n      to 8.0.0 (#4459)\n    - chore(deps): bump anchore/sbom-action from 0.20.10 to 0.20.11\n      (#4458)\n\n- Update to version 1.38.2 (.1 was not released):\n  * Bug Fixes\n    - drop cpe from gguf [#4383 @spiffcs]\n    - emit lua rockspec dependencies in metadata [#4376\n      @willmurphyscode]\n    - Invalid SBOMs are created when GO replace directive is used\n      [#4415 #4419 @VictorHuu]\n    - Incorrect CPE for Vercel's Next js [#4443 #4450\n      @willmurphyscode]\n    - v1.38.0 generates empty sbom for tgz sources [#4416 #4421\n      @VictorHuu]\n    - Syft: The dependency graph does not include all Requires-Dist\n      relationships defined in the package's METADATA file [#4401\n      #4408 @willmurphyscode]\n  * Dependencies\n    - chore(deps): update anchore dependencies (#4440)\n    - chore(deps): update tools to latest versions (#4442)\n    - chore(deps): bump peter-evans/create-pull-request from 7.0.8\n      to 7.0.11 (#4447)\n    - chore(deps): bump actions/create-github-app-token from 2.1.4\n      to 2.2.1 (#4445)\n    - chore(deps): bump github.com/go-git/go-billy/v5 from 5.6.2 to\n      5.7.0 (#4448)\n    - chore(deps): bump github/codeql-action from 4.31.6 to 4.31.7\n      (#4446)\n    - chore(deps): bump golang.org/x/tools from 0.39.0 to 0.40.0\n      (#4453)\n    - chore(deps): bump github.com/github/go-spdx/v2 from 2.3.4 to\n      2.3.5 (#4434)\n    - chore(deps): bump github.com/spf13/cobra from 1.10.1 to\n      1.10.2 (#4435)\n    - chore(deps): bump actions/checkout from 6.0.0 to 6.0.1\n      (#4431)\n    - chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.17\n      to 0.5.18 (#4432)\n    - chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.15\n      to 0.5.17 (#4413)\n    - chore(deps): update tools to latest versions (#4420)\n    - chore(deps): bump github.com/olekukonko/tablewriter from\n      1.1.1 to 1.1.2 (#4427)\n    - chore(deps): bump github/codeql-action from 4.31.4 to 4.31.6\n      (#4424)\n    - chore(deps): bump github.com/goccy/go-yaml from 1.18.0 to\n      1.19.0 (#4426)\n    - chore(deps): bump anchore/sbom-action from 0.20.9 to 0.20.10\n      (#4381)\n    - chore(deps): bump modernc.org/sqlite from 1.40.0 to 1.40.1\n      (#4382)\n    - chore(deps): bump actions/checkout from 5.0.0 to 6.0.0\n      (#4396)\n    - chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.3\n      to 6.7.5 (#4397)\n    - chore(deps): update tools to latest versions (#4398)\n    - chore(deps): bump github.com/google/go-containerregistry\n      (#4409)\n    - chore(deps): bump github/codeql-action from 4.31.3 to 4.31.4\n      (#4386)\n    - chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.2\n      to 6.7.3 (#4387)\n    - chore(deps): bump golang.org/x/crypto from 0.44.0 to 0.45.0\n      (#4391)\n    - chore(deps): bump actions/setup-go from 6.0.0 to 6.1.0\n      (#4392)\n    - chore(deps): bump actions/setup-go in\n      /.github/actions/bootstrap (#4393)\n\n- Update to version 1.38.0:\n  * Added Features\n    - add support for cataloging GGUF models [#4184 #4279 @spiffcs]\n    - Support scanning a list of CPEs [#3890 #4207 @chovanecadam]\n    - Syft does not detect Elixir binary on system [#4333 #4334\n      @rezmoss]\n  * Bug Fixes\n    - Support extras statements in Python PDM cataloger [#4352\n      @wagoodman]\n    - Preserve --from argument order [#4350 @wagoodman]\n    - SBOM generated by Syft 1.28 contains license elements missing\n      id or name (causing CycloneDX parser error) [#4363]\n    - empty PURL output in dependency snapshot format breaks\n      sbom-action [#4311]\n    - Interface includes constraint elements, can only be used in\n      type parameters [#4346]\n    - Upgrade github.com/nwaples/rardecode@v1.1.3 to 2.2.1 [#4338]\n    - Upgrade to Golang 1.25.4 [#4341]\n  * Additional Changes\n    - migrate syft to use mholt/archives instead of anchore fork\n      [#4029 @Rupikz]\n    - Add license enrichment from pypi to python packages [#4295\n      @timols]\n    - license file search [#4327 @kzantow]\n  * Dependencies\n    - chore(deps): update anchore dependencies (#4374)\n    - chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.1\n      to 6.7.2 (#4372)\n    - chore(deps): bump golang.org/x/tools from 0.38.0 to 0.39.0\n      (#4364)\n    - chore(deps): update tools to latest versions (#4370)\n    - chore(deps): update tools to latest versions (#4365)\n    - chore(deps): bump github/codeql-action from 4.31.2 to 4.31.3\n      (#4366)\n    - chore(deps): update tools to latest versions (#4358)\n    - chore(deps): bump golang.org/x/mod from 0.29.0 to 0.30.0\n      (#4359)\n    - chore(deps): bump github.com/olekukonko/tablewriter from\n      1.0.9 to 1.1.1 (#4354)\n    - chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.7.0\n      to 6.7.1 (#4355)\n    - chore(deps): update tools to latest versions (#4347)\n    - chore(deps): bump github.com/opencontainers/selinux (#4349)\n    - chore(deps): bump golang.org/x/time from 0.12.0 to 0.14.0\n      (#4348)\n    - chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.9\n      to 6.7.0 (#4337)\n    - chore(deps): bump github.com/containerd/containerd from\n      1.7.28 to 1.7.29 (#4340)\n\n- Update to version 1.37.0:\n  * Added Features\n    - Refactor fileresolver to not require base path [#4298\n      @Rupikz]\n    - Describe cataloger capabilities via test observations [#4318\n      @wagoodman]\n    - Support Java resource adapter extension .far as a Java\n      archive [#4183 #4193 @kyounghunJang]\n    - Add Java resource adapter extension \".rar\" as supported Java\n      archive [#4136 #4137 @thomassui]\n  * Bug Fixes\n    - fix empty PURL Github format [#4312 @rezmoss]\n    - Canonicalize Ghostscript CPE/PURL for ghostscript packages\n      from PE Binaries [#4308 @kdt523]\n    - Respect \"rpmmod\" PURL qualifier [#4314 @willmurphyscode]\n    - fix dpkg packages that are in deinstalled state should not be\n      in SBOM [#3063 #4231 @rkirk-nos]\n  * Dependencies\n    - chore(deps): update anchore dependencies (#4330)\n    - chore(deps): bump github/codeql-action from 4.31.1 to 4.31.2\n      (#4325)\n    - chore(deps): bump github.com/hashicorp/go-getter from 1.8.2\n      to 1.8.3 (#4326)\n    - chore(deps): bump modernc.org/sqlite from 1.39.1 to 1.40.0\n      (#4329)\n    - chore(deps): bump github/codeql-action from 4.31.0 to 4.31.1\n      (#4321)\n    - chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.8\n      to 6.6.9 (#4315)\n    - chore(deps): bump github/codeql-action from 4.30.9 to 4.31.0\n      (#4310)\n    - chore(deps): bump anchore/sbom-action from 0.20.8 to 0.20.9\n      (#4305)\n    - chore(deps): update tools to latest versions (#4307)\n\n- Update to version 1.36.0 (1.35.0 was not released):\n  * Added Features\n    - Add the ability to fetch remote licenses for pnpm-lock.yaml\n      files [#4286 @timols]\n    - support universal (fat) mach-o binary files [#4278\n      @JoeyShapiro]\n    - pdm support [#2709 #4234 @paulslaby]\n  * Bug Fixes\n    - Remove duplicate image source providers [#4289 @Rupikz]\n    - syft can't extract go module information from executables on\n      Windows [#4271 #4285 @JoeyShapiro]\n  * Dependencies\n    - chore(deps): update tools to latest versions (#4302)\n    - chore(deps): bump github.com/github/go-spdx/v2 from 2.3.3 to\n      2.3.4 (#4301)\n    - chore(deps): bump github/codeql-action from 4.30.8 to 4.30.9\n      (#4299)\n    - chore(deps): bump sigstore/cosign-installer from 3.10.0 to\n      4.0.0 (#4296)\n    - chore(deps): bump anchore/sbom-action from 0.20.7 to 0.20.8\n      (#4297)\n    - chore(deps): bump anchore/sbom-action from 0.20.6 to 0.20.7\n      (#4293)\n\n- Update to version 1.34.2:\n  * Bug Fixes\n    - Extract zip archive with multiple entries [#4283 @Rupikz]\n    - panic while resolving maven properties in archive parser\n      [#4288 #4290 @kzantow]\n  * Dependencies\n    - chore(deps): update tools to latest versions (#4291)\n\n- Update to version 1.34.1 (1.34.0 was not released):\n  * Added Features\n    - feat: enhance setup.py parser to handle unquoted dependencies\n      [#4255 @HalaAli198]\n    - feat: support for identifying ffmpeg/libav libraries [#4227\n      @popey]\n    - feat: PNPM latest lockfile (version 9.0) [#3927 #4256\n      @bernardoamc]\n    - Add Windows ARM64 releases [#4179 #4237 @compnerd]\n  * Bug Fixes\n    - fix: SBOM CPE mismatch for Qt5 causes Grype to miss CVE\n      matches [#4036 #4093 @hawkaii]\n    - fix: use of manifest files present in Snap packages when\n      generating SBOMs [#4147 #4151 @popey]\n    - fix: Pom xml only archive parser [#4272 @douglasclarke]\n  * Dependencies\n    - chore(deps): bump actions/cache from 4.2.4 to 4.3.0 (#4240)\n    - chore(deps): bump actions/cache in /.github/actions/bootstrap\n      (#4241)\n    - chore(deps): bump anchore/sbom-action from 0.20.5 to 0.20.6\n      (#4222)\n    - chore(deps): bump github.com/CycloneDX/cyclonedx-go from\n      0.9.2 to 0.9.3 (#4251)\n    - chore(deps): bump github.com/charmbracelet/bubbletea (#4228)\n    - chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.14\n      to 0.5.15 (#4225)\n    - chore(deps): bump github.com/go-git/go-git/v5 from 5.16.2 to\n      5.16.3 (#4259)\n    - chore(deps): bump github.com/gohugoio/hashstructure from\n      0.5.0 to 0.6.0 (#4267)\n    - chore(deps): bump github.com/hashicorp/go-getter from 1.8.0\n      to 1.8.1 (#4229)\n    - chore(deps): bump github.com/hashicorp/go-getter from 1.8.1\n      to 1.8.2 (#4254)\n    - chore(deps): bump github.com/iancoleman/orderedmap (#4258)\n    - chore(deps): bump github.com/mholt/archives from 0.1.3 to\n      0.1.5 (#4280)\n    - chore(deps): bump github.com/quasilyte/go-ruleguard/dsl\n      (#4245)\n    - chore(deps): bump github/codeql-action from 3.30.3 to 3.30.4\n      (#4239)\n    - chore(deps): bump github/codeql-action from 3.30.4 to 3.30.5\n      (#4246)\n    - chore(deps): bump github/codeql-action from 3.30.5 to 3.30.6\n      (#4253)\n    - chore(deps): bump github/codeql-action from 3.30.6 to 4.30.7\n      (#4262)\n    - chore(deps): bump github/codeql-action from 4.30.7 to 4.30.8\n      (#4277)\n    - chore(deps): bump golang.org/x/mod from 0.28.0 to 0.29.0\n      (#4266)\n    - chore(deps): bump golang.org/x/net from 0.44.0 to 0.45.0\n      (#4263)\n    - chore(deps): bump golang.org/x/net from 0.45.0 to 0.46.0\n      (#4268)\n    - chore(deps): bump golang.org/x/tools from 0.37.0 to 0.38.0\n      (#4265)\n    - chore(deps): bump modernc.org/sqlite from 1.39.0 to 1.39.1\n      (#4276)\n    - chore(deps): update anchore dependencies (#4282)\n    - chore(deps): update tools to latest versions (#4221)\n    - chore(deps): update tools to latest versions (#4230)\n    - chore(deps): update tools to latest versions (#4236)\n    - chore(deps): update tools to latest versions (#4238)\n    - chore(deps): update tools to latest versions (#4248)\n    - chore(deps): update tools to latest versions (#4261)\n    - chore(deps): update tools to latest versions (#4274)\n    - chore: update ffmpeg tests (#4249)\n    - chore: update to use old configuration on new cosign (#4287)\n\n- Update to version 1.33.0:\n  * Added Features\n    - Modify RpmDBEntry to include modularityLabel for cyclonedx\n      [#4212 @sfc-gh-rmaj]\n    - Add locations onto packages read from Java native image SBOMs\n      [#4186 @rudsberg]\n  * Dependencies\n    - chore(deps): update anchore dependencies (#4220)\n    - chore(deps): update tools to latest versions (#4215)\n    - chore(deps): bump zizmorcore/zizmor-action from 0.1.2 to\n      0.2.0 (#4216)\n    - chore(deps): bump 8398a7/action-slack from 3.18.0 to 3.19.0\n      (#4217)\n    - chore(deps): bump sigstore/cosign-installer from 3.9.2 to\n      3.10.0 (#4218)\n    - chore(deps): bump modernc.org/sqlite from 1.38.2 to 1.39.0\n      (#4219)\n    - chore(deps): bump github.com/charmbracelet/bubbletea from\n      1.3.8 to 1.3.9 (#4214)\n    - chore(deps): bump github.com/spf13/afero from 1.14.0 to\n      1.15.0 (#4202)\n    - chore(deps): bump github.com/charmbracelet/bubbletea from\n      1.3.6 to 1.3.8 (#4203)\n    - chore(deps): bump github.com/vbatts/go-mtree from 0.5.4 to\n      0.6.0 (#4204)\n    - chore(deps): update tools to latest versions (#4200)\n    - chore(deps): bump github/codeql-action from 3.30.1 to 3.30.3\n      (#4210)\n    - chore(deps): bump golang.org/x/tools from 0.36.0 to 0.37.0\n      (#4211)\n    - chore(deps): update tools to latest versions (#4194)\n    - chore(deps): bump github.com/hashicorp/go-getter from 1.7.10\n      to 1.8.0 (#4197)\n    - chore(deps): bump golang.org/x/mod from 0.27.0 to 0.28.0\n      (#4198)\n    - chore(deps): bump github.com/spf13/cobra from 1.9.1 to 1.10.1\n      (#4182)\n    - chore(deps): bump actions/setup-go from 5.5.0 to 6.0.0\n      (#4188)\n    - chore(deps): bump actions/setup-go in\n      /.github/actions/bootstrap (#4189)\n    - chore(deps): bump github.com/hashicorp/go-getter from 1.7.9\n      to 1.7.10 (#4190)\n    - chore(deps): bump github/codeql-action from 3.30.0 to 3.30.1\n      (#4191)\n    - chore(deps): bump actions/github-script from 7 to 8 (#4192)\n    - chore(deps): bump github.com/stretchr/testify from 1.11.0 to\n      1.11.1 (#4173)\n    - chore(deps): update tools to latest versions (#4185)\n    - chore(deps): bump github.com/ulikunitz/xz from 0.5.12 to\n      0.5.14 (#4178)\n    - chore(deps): bump github.com/spf13/cobra from 1.9.1 to 1.10.0\n      (#4180)\n    - chore(deps): bump github/codeql-action from 3.29.11 to 3.30.0\n      (#4181)\n    - chore(deps): bump github.com/anchore/stereoscope (#4174)\n    - chore(deps): bump github.com/gookit/color from 1.5.4 to 1.6.0\n      (#4176)\n    - chore(deps): bump golang.org/x/tools from 0.35.0 to 0.36.0\n      (#4172)\n\n- Update to version 1.32.0:\n  * Added Features\n    - Catalog entire build list for Go projects, not just packages\n      listed in go.mod [#432 #4127 @spiffcs]\n    - package.json authors keyword parsing [#2250 #4003 @popey]\n    - Conda ecosystem support (basic) [#4002@SimeonStoykovQC]\n  * Bug Fixes\n    - When scanning the FFmpeg binary with Syft a new package is\n      now added [#3988 #3994 @popey]\n    - Warn loudly if SQLite driver is not present when needed\n      [#3234 #4150 @kzantow]\n  * Additional Changes\n    - Update dependencies to use go.yaml.in/yaml [#4157 @n-bes]\n    - chore(deps): update anchore dependencies (#4169)\n    - chore(deps): bump github.com/diskfs/go-diskfs (#4159)\n    - chore(deps): bump github.com/stretchr/testify from 1.10.0 to\n      1.11.0 (#4160)\n    - chore(deps): update tools to latest versions (#4154)\n    - chore(deps): bump github/codeql-action from 3.29.10 to\n      3.29.11 (#4149)\n    - chore(deps): bump github/codeql-action from 3.29.9 to 3.29.10\n      (#4145)\n    - chore(deps): update CPE dictionary index (#4143)\n    - chore(deps): bump github.com/hashicorp/go-getter from 1.7.8\n      to 1.7.9 (#4144)\n    - chore(deps): bump anchore/sbom-action from 0.20.4 to 0.20.5\n      (#4141)\n    - chore(deps): update tools to latest versions (#4139)\n\n- Update to version 1.31.0:\n  * Added Features\n    - Option to set PackageSupplier in root of SPDX document\n      generated by CLI [#3098 #4131 @spiffcs]\n  * Bug Fixes\n    - closed reader during java binary detection [#4129 @kzantow]\n    - support multiple letters in openssl patch version [#4106\n      @honigbot]\n    - Can not have license ID [#1964 #4132 @spiffcs]\n    - Syft sometimes reports URL for license value when scanning\n      JARs with a URL in Bundle-License field of manifest [#3186]\n  * Dependencies\n    - chore(deps): bump zizmorcore/zizmor-action from 0.1.1 to\n      0.1.2 (#4135)\n    - chore(deps): bump github/codeql-action from 3.29.8 to 3.29.9\n      (#4134)\n    - chore(deps): bump actions/checkout from 4.2.2 to 5.0.0\n      (#4130)\n    - chore(deps): update CPE dictionary index (#4126)\n\n- Update to version 1.30.0:\n  * Added Features\n    - add binary classifier for hashicorp vault [#4121\n      @willmurphyscode]\n  * Bug Fixes\n    - fix: update nondeterministic Java archive cataloging and\n      improve groupID [#3521 #4118 @kzantow]\n  * Dependencies\n    - chore(deps): bump golang.org/x/net from 0.42.0 to 0.43.0\n      (#4122)\n    - chore(deps): bump golang.org/x/mod from 0.26.0 to 0.27.0\n      (#4123)\n    - chore(deps): bump github/codeql-action from 3.29.7 to 3.29.8\n      (#4124)\n    - chore(deps): bump docker/login-action from 3.4.0 to 3.5.0\n      (#4115)\n    - chore(deps): bump actions/cache from 4.2.3 to 4.2.4 (#4119)\n    - chore(deps): bump actions/cache in /.github/actions/bootstrap\n      (#4120)\n    - chore(deps): update tools to latest versions (#4111)\n    - chore(deps): update CPE dictionary index (#4112)\n    - chore(deps): update tools to latest versions (#4108)\n    - chore(deps): bump github/codeql-action from 3.29.4 to 3.29.5\n      (#4096)\n\n- Update to version 1.29.1:\n  * Bug Fixes\n    - Missing license information for tzdata [#4102]\n    - Improve JVM Scan Accuracy for JDK and JRE Detection [#4071\n      #4046 @kzantow]\n    - Azul JDK classified as Oracle JRE [#3893 #4046 @kzantow]\n  * Dependencies\n    - chore(deps): update anchore dependencies (#4104)\n    - chore(deps): update anchore dependencies (#4098)\n    - chore(deps): bump github.com/anchore/stereoscope (#4091)\n    - chore(deps): bump github.com/docker/docker (#4092)\n    - chore(deps): bump modernc.org/sqlite from 1.38.1 to 1.38.2\n      (#4088)\n    - chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.13\n      to 0.5.14 (#4089)\n    - chore(deps): bump github.com/bmatcuk/doublestar/v4 from 4.9.0\n      to 4.9.1 (#4087)\n    - chore(deps): bump github.com/olekukonko/tablewriter from\n      1.0.8 to 1.0.9 (#4086)\n    - chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.7\n      to 6.6.8 (#4085)\n    - chore(deps): bump modernc.org/sqlite from 1.38.0 to 1.38.1\n      (#4084)\n    - chore(deps): update tools to latest versions (#4082)\n    - chore(deps): update CPE dictionary index (#4083)\n    - chore(deps): update tools to latest versions (#4079)\n    - chore(deps): bump github/codeql-action from 3.29.3 to 3.29.4\n      (#4080)\n    - chore(deps): update tools to latest versions (#4076)\n    - chore(deps): update tools to latest versions (#4072)\n    - chore(deps): bump github/codeql-action from 3.29.2 to 3.29.3\n      (#4074)\n    - chore(deps): bump anchore/sbom-action from 0.20.2 to 0.20.4\n      (#4073)\n\n- Update to version 1.29.0:\n  * Added Features\n    - Catalog python uv.lock files [#3268 #3763 @jkugler]\n  * Additional Changes\n    - Pkg Metadata type unmarshal bug [#4043 @houdini91]\n  * Dependencies\n    - chore(deps): update anchore dependencies (#4068)\n    - chore(deps): bump pygments (#4064)\n    - chore(deps): update tools to latest versions (#4065)\n    - chore(deps): bump sigstore/cosign-installer from 3.9.1 to\n      3.9.2 (#4066)\n    - chore(deps): update CPE dictionary index (#4067)\n    - chore(deps): bump marocchino/sticky-pull-request-comment\n      (#4063)\n    - chore(deps): update tools to latest versions (#4060)\n    - chore(deps): bump github.com/go-viper/mapstructure/v2 (#4061)\n    - chore(deps): bump github.com/bmatcuk/doublestar/v4 from 4.8.1\n      to 4.9.0 (#4059)\n    - chore(deps): bump golang.org/x/mod from 0.25.0 to 0.26.0\n      (#4054)\n    - chore(deps): update tools to latest versions (#4053)\n    - chore(deps): bump golang.org/x/net from 0.41.0 to 0.42.0\n      (#4056)\n    - chore(deps): update CPE dictionary index (#4058)\n    - chore(deps): bump github.com/olekukonko/tablewriter from\n      1.0.7 to 1.0.8 (#4049)\n    - chore(deps): update CPE dictionary index (#4050)\n    - chore(deps): bump github.com/hashicorp/hcl/v2 from 2.23.0 to\n      2.24.0 (#4051)\n    - chore(deps): bump github.com/charmbracelet/bubbletea from\n      1.3.5 to 1.3.6 (#4052)\n    - chore(deps): bump anchore/sbom-action from 0.20.1 to 0.20.2\n      (#4048)\n\n- Update to version 1.28.0:\n  * Added Features\n    - add native support for snap packages [#1088 #3929 @wagoodman]\n  * Additional Changes\n    - upgrade tablewriter dependency to use new API [#3990\n      @cpanato]\n  * Dependencies\n    - chore(deps): update anchore dependencies (#4047)\n    - chore(deps): update anchore dependencies (#4045)\n    - chore: upgrade tablewriter dependency to use new API (#3990)\n    - chore(deps): bump github.com/Masterminds/semver/v3 from 3.3.1\n      to 3.4.0 (#4040)\n    - chore: update tests to read from latest test-fixture-cache\n      and fix cache publish (#4042)\n    - chore(deps): bump github.com/mholt/archives from 0.1.2 to\n      0.1.3 (#4032)\n    - chore(deps): bump marocchino/sticky-pull-request-comment\n      (#4019)\n    - chore(deps): bump sigstore/cosign-installer from 3.9.0 to\n      3.9.1 (#4022)\n    - chore(deps): update tools to latest versions (#4035)\n    - chore(deps): update CPE dictionary index (#4037)\n    - chore(deps): bump github/codeql-action from 3.29.0 to 3.29.2\n      (#4039)\n    - chore(deps): update CPE dictionary index (#4021)\n    - chore(deps): update tools to latest versions (#4016)\n    - chore(deps): update tools to latest versions (#4012)\n    - chore(deps): bump github.com/go-viper/mapstructure/v2 (#4014)\n    - chore(deps): bump sigstore/cosign-installer from 3.8.2 to\n      3.9.0 (#4015)\n    - chore(deps): update CPE dictionary index (#4007)\n    - chore(deps): bump anchore/sbom-action from 0.20.0 to 0.20.1\n      (#4008)\n    - chore(deps): bump github.com/google/go-containerregistry\n      (#4009)\n    - chore(deps): update tools to latest versions (#3992)\n    - chore(deps): bump github/codeql-action from 3.28.19 to 3.29.0\n      (#4000)\n\n- Update to version 1.27.1:\n  * fix: provide separate nonroot image (#3998)\n  * account for non-import shapes (#3997)\n  * Allow decoding of anchorectl json files (#3973)\n  * chore(deps): bump github.com/anchore/stereoscope (#3991)\n\n- Update to version 1.27.0:\n  * Added Features\n    - add syft schema version to version command [#3949 @spiffcs]\n  * Bug Fixes\n    - Remove CPE product candidates for phf, prometheus, hyper and\n      Rust crates [#3967 @jayvdb]\n    - Remove CPE product candidates for opentelemetry and redis\n      Rust crates [#3962 @jayvdb]\n    - Harden Container Runtime with Non-Root User [#3941\n      @MikeTheCyberGuy]\n    - terraform provider lock entries should not require\n      constraints [#3934 @ghouscht]\n    - sbom cataloger returning upstream package [#3662 #3981\n      @kzantow]\n    - Syft missing md5 sums and list data for dpkg packages under\n      status.d/ [#3912]\n    - Failure to detect dependency relationships between Python\n      packages [#3958 #3965 @christoph-blessing]\n    - Heavy memory consumption when directory scanning deb source\n      [#3928 #3953 @kzantow]\n    - In versions 1.25.0 and later, graalvm-native-image-cataloger\n      adds 3-6 hours to Syft [#3942 #3944 @kzantow]\n    - Syft incorrectly reports multiple APKs as parents of\n      symlinked files [#3847 #3923 @luhring]\n  * Dependencies\n    - chore(deps): bump modernc.org/sqlite from 1.37.1 to 1.38.0\n      (#3979)\n    - chore(deps): bump github.com/go-git/go-git/v5 from 5.16.1 to\n      5.16.2 (#3978)\n    - chore(deps): update tools to latest versions (#3977)\n    - chore(deps): update CPE dictionary index (#3976)\n    - chore(deps): bump golang.org/x/net from 0.40.0 to 0.41.0\n      (#3970)\n    - chore(deps): bump github.com/sergi/go-diff (#3971)\n    - chore(deps): bump golang.org/x/mod from 0.24.0 to 0.25.0\n      (#3963)\n    - chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.12\n      to 0.5.13 (#3964)\n    - chore(deps): bump github.com/go-git/go-git/v5 from 5.16.0 to\n      5.16.1 (#3960)\n    - chore(deps): bump github/codeql-action from 3.28.18 to\n      3.28.19 (#3952)\n    - chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.11\n      to 0.5.12 (#3943)\n    - chore(deps): update tools to latest versions (#3945)\n    - chore(deps): update CPE dictionary index (#3947)\n    - chore(deps): bump github.com/google/go-containerregistry\n      (#3933)\n    - chore(deps): update CPE dictionary index (#3935)\n    - chore(deps): bump modernc.org/sqlite from 1.37.0 to 1.37.1\n      (#3926)\n\n- Update to version 1.26.1:\n  * fix(dotnet-deps-cataloger): avoid repeated dependency\n    resolution (#3930)\n  * chore(deps): update tools to latest versions (#3921)\n  * chore(deps): bump github.com/google/go-containerregistry\n    (#3925)\n\n- Update to version 1.26.0:\n  * Added Features\n    - Read version resources from non-.NET DLLs and executables\n      [#3842 #3911 @wagoodman]\n  * Bug Fixes\n    - pkg.JavaArchive.PomProperties is being populated even though\n      no pom.properties file was present for analysis [#3922\n      @wagoodman]\n    - syft 1.24.0 debug container - wget fails TLS [#3891 #3915\n      @spiffcs]\n  * Dependencies\n    - chore(deps): update CPE dictionary index (#3913)\n\n- Update to version 1.25.1:\n  * remove go-rpmdb replace directive [#3908 @wagoodman]\n\n- Update to version 1.25.0:\n  * Added Features\n    - Add PHP interpreter + extensions cataloger [#2585\n      @LaurentGoderre]\n  * Bug Fixes\n    - update license content filtering default case to be 'none'\n      for no content [#3903 @spiffcs]\n    - Distinguish openjdk vs jdk when using file source [#3895\n      @adammcclenaghan]\n    - Make it discoverable if Native Image contains no embedded\n      SBOM [#3731 #3805 @sathiya06]\n  * Dependencies\n    - chore(deps): bump github/codeql-action from 3.28.17 to\n      3.28.18 (#3905)\n    - chore(deps): bump github.com/mholt/archives from 0.1.1 to\n      0.1.2 (#3898)\n    - chore(deps): bump anchore/sbom-action from 0.19.0 to 0.20.0\n      (#3899)\n\n- Update to version 1.24.0:\n  https://github.com/anchore/syft/compare/v1.23.1...v1.24.0\n  * Added Features\n    - Add cataloger for Dart pubspec [#3292 @LaurentGoderre]\n    - Translate Portage license strings to SPDX expressions [#1763\n      @wagoodman]\n    - Use package ID from decoded SBOMs when provided [#1872\n      @jneate]\n    - Annotate visible/hidden paths when all-layers scope [#3855\n      @wagoodman]\n    - Add support for PHP Pear [#2775 @LaurentGoderre]\n    - Detect whether full license text or a license name has been\n      provided [#3088 #3876 @spiffcs #3450 @spiffcs]\n    - Add Cataloger for Homebrew on macOS [#3632 #3724 @rezmoss]\n    - Provide a way to get the LayerID the package was first found\n      in [#435 #3858 @wagoodman #3138 @tomersein]\n    - Go binaries that currently get (devel) as the version should\n      instead stub UNKNOWN based on the compliance policy [#3324\n      #3873 @wagoodman]\n    - Upgrade base Docker image to\n      gcr.io/distroless/static-debian12 [#3840 #3862 @bgoareguer]\n    - Return full license string instead of SHA256 hash when\n      license string exceeds 64 characters [#3780 #3844 @spiffcs]\n    - Detect nix dependencies [#3814 #3837 @wagoodman]\n  * Bug Fixes\n    - update license sort to be stable with contents field [#3860\n      @spiffcs]\n    - Improve detection of erlang binary in alpine Linux [#3839\n      @avodotiiets]\n    - Do not search for main module versions within binary contents\n      by default [#3874 @wagoodman]\n    - dpkg license improvement for non SPDX licenses [#3090 #3888\n      @spiffcs]\n    - CycloneDX group field not symmetrically handled by\n      encoder/decoders [#2981 #3853 @kzantow]\n    - Syft crash [signal SIGSEGV: segmentation violation code=0x80\n      addr=0x0 pc=0x123a0da] [#3872 #3875 @wagoodman]\n    - Syft 1.23.1 shows version (devel) for grafana 12.0.0 [#3864]\n    - .NET cataloger does not always pair up PE binaries and\n      deps.json packages, resulting in duplicate packages on some\n      runs [#3866 #3869 @wagoodman]\n    - Propagate error in FileSourceProvider instead of warn log\n      [#3831 #3845 @Rupikz]\n    - Update github.com/Masterminds/semver package [#3829 #3836\n      @popey]\n    - go-module-file-cataloger fails if symlinks in path [#3614\n      #3783 @VictorHuu]\n    - Support fluent-bit some versions of arm/s390x images [#3793\n      #3817 @VictorHuu]\n  * Additional Changes\n    - update rust test fixtures to latest [#3852 @spiffcs]\n\n- Update to version 1.23.1:\n  * chore(deps): update tools to latest versions (#3830)\n  * Resolve owned file paths when searching for overlaps (#3828)\n\n- Update to version 1.23.0:\n  * Added Features\n    - Support skipping archive extraction with file source [#3795\n      @adammcclenaghan]\n    - Use the R cataloger in directory scans [#3774 @spiffcs]\n    - Add support for detecting javascript assets in .NET projects\n      using libman [#3825 @wagoodman]\n    - Parse GitHub actions comments [#3776 @wagoodman]\n    - Support chrome binary detection [#3174 #3136 @lem-onade]\n    - Add support for detecting undeclared license files scanning\n      from python installations [#2624 #3779 @wagoodman]\n  * Bug Fixes\n    - .NET cataloger should consider compile target paths from\n      deps.json [#3821 @wagoodman]\n    - Skip license scanner injection [#3796 @adammcclenaghan]\n    - Delete collection name/type key entries when empty [#3797\n      @adammcclenaghan]\n    - Use module name over relative paths in go.mod replace\n      directives [#3812 @VictorHuu]\n    - Correct variable names for Conan lock parsing version\n      handling [#3802 @musangk]\n    - Consider DLL claims for dependencies of .NET packages from\n      deps.json [#3822 @wagoodman]\n    - Empty source during decoding an SBOM document should not be\n      fatal [#3791 @wagoodman]\n    - Dpkg are not detected when scanning a directory [#3726 #3820\n      @VictorHuu]\n    - Support golang tip image [#3681 #3757 @VictorHuu]\n    - syft cataloger list should flatten options [#3801 #3804\n      @kzantow]\n    - Unable to generate a correct SBOM for C++ project [#3755]\n  * Dependencies\n    - chore(deps): update anchore dependencies (#3827)\n    - chore(deps): update tools to latest versions (#3823)\n    - chore(deps): bump sigstore/cosign-installer from 3.8.1 to\n      3.8.2 (#3818)\n    - chore(deps): bump github/codeql-action from 3.28.15 to\n      3.28.16 (#3819)\n    - chore(deps): update tools to latest versions (#3815)\n    - chore(deps): update CPE dictionary index (#3813)\n    - chore(deps): update tools to latest versions (#3806)\n    - chore(deps): bump github.com/go-git/go-git/v5 from 5.15.0 to\n      5.16.0 (#3807)\n    - chore(deps): bump github.com/anchore/stereoscope from 0.1.2\n      to 0.1.3 (#3803)\n    - chore(deps): update tools to latest versions (#3798)\n    - chore(deps): update CPE dictionary index (#3799)\n    - chore(deps): bump github.com/mholt/archives from 0.1.0 to\n      0.1.1 (#3778)\n    - chore(deps): bump marocchino/sticky-pull-request-comment\n      (#3788)\n    - chore(deps): bump github.com/magiconair/properties from 1.8.9\n      to 1.8.10 (#3789)\n    - chore(deps): bump github.com/charmbracelet/bubbles from\n      0.20.0 to 0.21.0 (#3790)\n    - chore(deps): bump github.com/go-git/go-git/v5 from 5.14.0 to\n      5.15.0 (#3792)\n    - chore(deps): update tools to latest versions (#3785)\n    - chore(deps): bump github/codeql-action from 3.28.13 to\n      3.28.15 (#3786)\n    - chore(deps): bump golang.org/x/net from 0.38.0 to 0.39.0\n      (#3787)\n    - chore(deps): update CPE dictionary index (#3782)\n    - chore(deps): update tools to latest versions (#3775)\n\n- Update to version 1.22.0:\n  * Added Features\n    - Improve .NET package CPE generation [#3764 @wagoodman]\n    - Catalog deb archives directly [#3315 #3704 @popey]\n  * Bug Fixes\n    - Dotnet-Portable-Executable-Cataloger uses wrong component\n      version for dotnet runtime libraries [#3282 #3768 @wagoodman]\n    - Dotnet deps cataloger returns \"wrong\" dotnet-framework\n      dependencies and misses out on the runtime (for applications)\n      [#2347 #3768 @wagoodman]\n    - .NET deps.json should be considered as installation evidence\n      [#3570 #3563 @wagoodman]\n    - Dotnet PE binary cataloger is detecting false positives\n      [#3469 #3563 @wagoodman]\n    - Long Processing Time in dpkg-db-cataloger with all-layers\n      Option (Syft 1.20.0) [#3683 #3636 @kzantow]\n  * Dependencies\n    - chore(deps): update anchore dependencies (#3772)\n    - chore(deps): bump golang.org/x/net from 0.37.0 to 0.38.0\n      (#3766)\n    - chore(deps): bump 8398a7/action-slack from 3.16.2 to 3.18.0\n      (#3767)\n    - chore(deps): bump modernc.org/sqlite from 1.36.1 to 1.37.0\n      (#3771)\n    - chore(deps): update CPE dictionary index (#3769)\n    - chore(deps): bump github/codeql-action from 3.28.12 to\n      3.28.13 (#3758)\n    - chore(deps): update CPE dictionary index (#3756)\n    - chore(deps): update tools to latest versions (#3747)\n    - chore(deps): bump actions/upload-artifact from 4.6.1 to 4.6.2\n      (#3750)\n    - chore(deps): bump github.com/docker/docker (#3749)\n    - chore(deps): bump actions/cache from 4.2.2 to 4.2.3 (#3751)\n    - chore(deps): bump actions/cache in /.github/actions/bootstrap\n      (#3752)\n    - chore(deps): bump actions/setup-go in\n      /.github/actions/bootstrap (#3742)\n    - chore(deps): bump actions/setup-go from 5.3.0 to 5.4.0\n      (#3743)\n    - chore(deps): bump github/codeql-action from 3.28.11 to\n      3.28.12 (#3744)\n    - chore(deps): bump github.com/BurntSushi/toml from 1.4.0 to\n      1.5.0 (#3740)\n    - chore(deps): bump github.com/containerd/containerd from\n      1.7.26 to 1.7.27 (#3738)\n    - chore(deps): update tools to latest versions (#3739)\n\n- Update to version 1.21.0:\n  * chore(deps): update anchore dependencies (#3727)\n  * chore(deps): update CPE dictionary index (#3735)\n  * chore(deps): update tools to latest versions (#3722)\n  * chore(deps): bump github.com/spf13/afero from 1.12.0 to 1.14.0\n    (#3736)\n  * chore(deps): bump modernc.org/sqlite from 1.36.0 to 1.36.1\n    (#3737)\n  * chore(deps): bump github.com/charmbracelet/lipgloss from 1.0.0\n    to 1.1.0 (#3732)\n  * chore(deps): bump docker/login-action from 3.3.0 to 3.4.0\n    (#3733)\n  * fix(performance): reduce memory allocation in containsPath\n    (#3730)\n  * chore: upload individual binaries as artifacts (#3714)\n  * fix: fetch Dart package versions from sdk entries (#3572)\n  * chore(deps): update tools to latest versions (#3713)\n  * chore(deps): update CPE dictionary index (#3715)\n  * Add set ID to dotnet packages (#3719)\n  * chore(deps): bump github/codeql-action from 3.28.10 to 3.28.11\n    (#3716)\n  * Location order on packages should consider evidence annotations\n    when sorting (#3720)\n  * chore: fix some function names in comment (#3717)\n  * fix: improve fluent-bit binary detection regex pattern (#3701)\n  * chore: updates for go 1.24.1 (#3712)\n  * chore(deps): bump golang.org/x/mod from 0.23.0 to 0.24.0\n    (#3708)\n  * Update rustaudit module name (#3689)\n  * chore(deps): bump golang.org/x/net from 0.35.0 to 0.37.0\n    (#3711)\n  * chore(deps): bump github.com/charmbracelet/bubbletea from 1.2.4\n    to 1.3.4 (#3690)\n  * Add downloadLocation URI validation (#3697)\n  * Native Image SBOM: support extracting symbols in .dynsym\n    section for ELF files (#3647)\n  * chore(deps): bump github.com/google/go-cmp from 0.6.0 to 0.7.0\n    (#3687)\n  * chore(deps): bump modernc.org/sqlite from 1.35.0 to 1.36.0\n    (#3692)\n  * chore(deps): bump github.com/go-git/go-git/v5 from 5.13.2 to\n    5.14.0 (#3693)\n  * chore(deps): bump github.com/docker/docker (#3694)\n  * chore(deps): bump actions/cache from 4.2.1 to 4.2.2 (#3698)\n  * chore(deps): bump actions/cache in /.github/actions/bootstrap\n    (#3699)\n  * chore(deps): update CPE dictionary index (#3702)\n  * chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.6 to\n    6.6.7 (#3703)\n  * chore(deps): bump golang.org/x/net from 0.35.0 to 0.36.0\n    (#3709)\n  * chore(deps): bump peter-evans/create-pull-request from 7.0.7 to\n    7.0.8 (#3706)\n  * suppress file already closed errors (#3695)\n  * Fix /etc/redhat-release file parsing when resolving distro\n    details (#3688)\n  * chore(deps): bump sigstore/cosign-installer from 3.8.0 to 3.8.1\n    (#3675)\n  * chore: disable line wrapping glow output (#3679)\n  * chore(deps): update CPE dictionary index (#3682)\n  * chore(deps): bump peter-evans/create-pull-request from 7.0.6 to\n    7.0.7 (#3684)\n  * chore(deps): bump github/codeql-action from 3.28.9 to 3.28.10\n    (#3685)\n  * chore(deps): bump actions/upload-artifact from 4.6.0 to 4.6.1\n    (#3686)\n\n- Update to version 1.20.0:\n  * Added Features\n    - Add file catalogers to selection configuration [#3505\n      @wagoodman]\n    - Configuration for including license contents in SBOM [#3626\n      #3631 @spiffcs]\n    - Support Bitnami embedded SBOMs [#3065 #3341 @juan131]\n  * Bug Fixes\n    - Version parse caused by line breaks on different platforms\n      [#3672 @idhyt]\n    - find bitnami files even when no relationships [#3676\n      @willmurphyscode]\n    - License files which do not match an SPDX expression are\n      erroneously handled as 'unlicensed' [#3412 #3366\n      @HeyeOpenSource]\n    - Incorrect URL encoding of package url (purl) [#3533 #3678\n      @kzantow]\n    - syft should not warn on known bad package.json [#3470 #3645\n      @kzantow]\n    - Scanning a project with many DLLs is slow [#3455 #3677\n      @rogueai]\n    - cyclone-dx presenter drops files, includes only packages\n      [#3435 #3539 @spiffcs]\n    - \"syft config\" output swaps comments for\n      search-indexed-archives / search-unindexed-archives [#3624\n      #3630 @spiffcs]\n    - dpkg license improvement for non SPDX licenses [#3090 #3366\n      @HeyeOpenSource]\n    - RPM-based PURLs sometimes have incorrect namespace\n      (specifically OpenSUSE) [#3534 #3615 @mprpic]\n  * Additional Changes\n    - update to go 1.24.x [#3660 @westonsteimel]\n    - replace all shorthand tags of mapstruct -\u003e mapstructure\n      [#3633 @spiffcs]\n\n- Update to version 1.19.0:\n  * chore(deps): update tools to latest versions (#3602)\n  * chore(deps): bump github/codeql-action from 3.28.1 to 3.28.2\n    (#3604)\n  * chore(deps): bump github.com/hashicorp/hcl/v2 from 2.22.0 to\n    2.23.0 (#3605)\n  * chore(deps): bump github.com/aquasecurity/go-pep440-version\n    (#3606)\n  * chore: bump stereoscope to v0.0.13 (#3601)\n  * feat(cataloger): add a terraform provider cataloger (#3378)\n  * chore(deps): update tools to latest versions (#3597)\n  * chore(deps): update CPE dictionary index (#3599)\n  * chore(deps): bump actions/setup-go from 5.2.0 to 5.3.0 (#3600)\n  * feat(golang): add license parsing from vendor dirs (#3522)\n  * chore: bump packageurl-go with new parsing rules (#3596)\n  * chore(deps): bump marocchino/sticky-pull-request-comment\n    (#3595)\n  * feat: add cataloger for NuGet packages (#3484)\n  * allow disabling all package catalogers (#3468)\n  * chore(deps): bump github.com/google/go-containerregistry\n    (#3592)\n  * chore(deps): bump modernc.org/sqlite from 1.34.4 to 1.34.5\n    (#3593)\n  * chore(deps): update tools to latest versions (#3582)\n  * chore: update README.md's link to Nixpkgs (#3578)\n  * chore(deps): bump github.com/sanity-io/litter from 1.5.5 to\n    1.5.6 (#3579)\n  * chore(deps): bump github.com/spf13/afero from 1.11.0 to 1.12.0\n    (#3580)\n  * chore(deps): bump actions/upload-artifact from 4.5.0 to 4.6.0\n    (#3581)\n  * chore(deps): update CPE dictionary index (#3583)\n  * chore(deps): bump github/codeql-action from 3.28.0 to 3.28.1\n    (#3584)\n  * chore(deps): bump github.com/go-git/go-billy/v5 from 5.6.1 to\n    5.6.2 (#3585)\n  * chore(deps): bump github.com/bmatcuk/doublestar/v4 from 4.7.1\n    to 4.8.0 (#3586)\n  * chore(deps): bump github.com/docker/docker (#3587)\n  * chore(deps): update anchore dependencies (#3571)\n  * chore(deps): update tools to latest versions (#3567)\n  * chore(deps): bump golang.org/x/net from 0.33.0 to 0.34.0\n    (#3568)\n  * fix: golang remote license search not executing when error\n    reading local mod dir (#3549)\n  * chore(deps): update tools to latest versions (#3564)\n  * chore(deps): update CPE dictionary index (#3565)\n  * chore(deps): bump github.com/gkampitakis/go-snaps from 0.5.7 to\n    0.5.8 (#3548)\n  * chore(deps): update tools to latest versions (#3560)\n  * chore(deps): bump github.com/go-git/go-git/v5 from 5.13.0 to\n    5.13.1 (#3561)\n  * Use reader when scanning for package versions over reading\n    entire binary into memory (#3558)\n  * chore(deps): bump github.com/go-git/go-billy/v5 from 5.6.0 to\n    5.6.1 (#3551)\n  * chore(deps): update tools to latest versions (#3556)\n  * test: removes latest license list test (#3559)\n  * chore(deps): bump peter-evans/create-pull-request from 7.0.5 to\n    7.0.6 (#3547)\n  * chore(deps): update CPE dictionary index (#3550)\n  * chore(deps): bump github.com/go-git/go-git/v5 from 5.12.0 to\n    5.13.0 (#3552)\n  * chore(deps): update tools to latest versions (#3543)\n  * chore(deps): update CPE dictionary index (#3544)\n  * chore(deps): bump modernc.org/sqlite from 1.34.3 to 1.34.4\n    (#3545)\n  * chore(deps): bump github/codeql-action from 3.27.9 to 3.28.0\n    (#3546)\n  * chore(deps): bump golang.org/x/net from 0.32.0 to 0.33.0\n    (#3541)\n  * chore(deps): bump modernc.org/sqlite from 1.34.2 to 1.34.3\n    (#3542)\n  * chore(deps): bump actions/upload-artifact from 4.4.3 to 4.5.0\n    (#3537)\n  * chore(deps): bump github.com/docker/docker (#3538)\n  * chore(deps): update CPE dictionary index (#3526)\n  * chore(deps): bump github.com/CycloneDX/cyclonedx-go from 0.9.1\n    to 0.9.2 (#3530)\n  * chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.4 to\n    6.6.5 (#3531)\n  * chore(deps): bump anchore/sbom-action from 0.17.8 to 0.17.9\n    (#3532)\n\n- Update to version 1.18.1:\n  * chore(deps): update anchore dependencies (#3525)\n  * chore(deps): bump github/codeql-action from 3.27.7 to 3.27.9\n    (#3524)\n  * chore(deps): bump golang.org/x/crypto from 0.30.0 to 0.31.0\n    (#3523)\n  * chore(deps): bump actions/setup-go from 5.1.0 to 5.2.0 (#3519)\n  * chore(deps): bump actions/checkout from 4.2.1 to 4.2.2 (#3518)\n  * chore: make fixes field in PR template match auto-close regex\n    (#3520)\n  * fix: stop omitting redundantly parenthesized licenses in CDX\n    formatter (#3517)\n  * chore: migrate syft to use the anchore fork of archiver without\n    replace (#3516)\n  * Make pre-release integration PRs (#3370)\n  * chore(deps): bump github.com/docker/docker (#3512)\n  * chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.3 to\n    6.6.4 (#3513)\n  * chore(deps): bump github/codeql-action from 3.27.6 to 3.27.7\n    (#3514)\n\n- Update to version 1.18.0:\n  * chore(deps): update anchore dependencies (#3510)\n  * fix: convert file paths for spdx formats from absolute to\n    relative (#3509)\n  * chore(deps): update CPE dictionary index (#3507)\n  * chore(deps): update tools to latest versions (#3506)\n  * chore(deps): bump github.com/magiconair/properties from 1.8.7\n    to 1.8.9 (#3508)\n  * chore(deps): bump actions/cache from 4.1.2 to 4.2.0 (#3503)\n  * Add relationships for rust audit binary packages (#3500)\n  * fix order of rust dependencies and support git sources in\n    Cargo.lock dependencies (#3502)\n  * chore(deps): update tools to latest versions (#3501)\n  * chore(deps): bump golang.org/x/net from 0.31.0 to 0.32.0\n    (#3499)\n  * chore: add and document target for updating unit snapshots\n    (#3498)\n  * fix: emit NOASSERTION for copyright text to fix SPDX 2.2\n    validation failure (#3495)\n  * chore(deps): update tools to latest versions (#3496)\n  * chore(deps): update tools to latest versions (#3487)\n  * chore(deps): bump github/codeql-action from 3.27.5 to 3.27.6\n    (#3494)\n  * chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.2 to\n    6.6.3 (#3489)\n  * feat: set max layer size (#3464)\n  * chore(deps): update CPE dictionary index (#3491)\n  * chore(deps): bump modernc.org/sqlite from 1.34.1 to 1.34.2\n    (#3492)\n  * chore(deps): bump github.com/saferwall/pe from 1.5.5 to 1.5.6\n    (#3493)\n  * chore(deps): update tools to latest versions (#3478)\n  * chore(deps): update CPE dictionary index (#3479)\n  * chore(deps): bump github.com/stretchr/testify from 1.9.0 to\n    1.10.0 (#3480)\n  * chore(deps): bump github.com/charmbracelet/bubbletea from 1.2.3\n    to 1.2.4 (#3482)\n  * chore(deps): update stereoscope to\n    be5deed44b7c03fcbfa6f1f42fb67202d31636a9 (#3483)\n  * fix: dart classifier for 2.x and ARM (#3475)\n  * Use file indexer directly when scanning with file source\n    (#3333)\n  * chore(deps): bump anchore/sbom-action from 0.17.7 to 0.17.8\n    (#3476)\n  * chore(deps): bump github/codeql-action from 3.27.4 to 3.27.5\n    (#3473)\n\n- Update to version 1.17.0:\n  * chore(deps): update stereoscope to\n    aa3a3ef4efe8d8759c9aa87261b405cc003bfc9a (#3472)\n  * chore(deps): bump github.com/charmbracelet/bubbletea from 1.2.2\n    to 1.2.3 (#3467)\n  * fix: bump clio to pull in logging fix (#3466)\n  * 3122 valid license url characters (#3449)\n  * 3030 license declared spdx correction (#3461)\n  * chore(deps): update tools to latest versions (#3463)\n  * chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.1 to\n    6.6.2 (#3465)\n  * chore(deps): bump modernc.org/sqlite from 1.33.1 to 1.34.1\n    (#3460)\n  * chore(deps): update CPE dictionary index (#3453)\n  * chore(deps): update tools to latest versions (#3454)\n  * chore(deps): update tools to latest versions (#3448)\n  * chore(deps): update tools to latest versions (#3444)\n  * chore(deps): bump github/codeql-action from 3.27.3 to 3.27.4\n    (#3446)\n  * feat: emit dependency relationships found in Cargo.lock (#3443)\n  * chore(deps): update stereoscope to\n    aa3a3ef4efe8d8759c9aa87261b405cc003bfc9a (#3442)\n  * chore(deps): bump github/codeql-action from 3.27.2 to 3.27.3\n    (#3438)\n  * chore(deps): bump github.com/charmbracelet/bubbletea from 1.2.1\n    to 1.2.2 (#3439)\n  * chore(deps): bump github.com/saferwall/pe from 1.5.4 to 1.5.5\n    (#3440)\n  * chore(deps): update tools to latest versions (#3413)\n  * chore(deps): bump github/codeql-action from 3.27.1 to 3.27.2\n    (#3436)\n  * chore(deps): bump golang.org/x/mod from 0.21.0 to 0.22.0\n    (#3426)\n  * update node classifier (#3419)\n  * chore(deps): update stereoscope to\n    120d9ea511e2f7a9887b443c52e66cd19bb80b43 (#3424)\n  * chore(deps): update CPE dictionary index (#3429)\n  * chore(deps): bump github/codeql-action from 3.27.0 to 3.27.1\n    (#3431)\n  * chore(deps): bump golang.org/x/net from 0.30.0 to 0.31.0\n    (#3432)\n  * chore(deps): bump github.com/charmbracelet/bubbletea from 1.1.2\n    to 1.2.1 (#3433)\n  * restore log on ui teardown (#3427)\n  * doc: Add official Syft logo license information (#3421)\n  * chore(deps): bump anchore/sbom-action from 0.17.6 to 0.17.7\n    (#3418)\n  * chore: build release sbom from go.mod (#3417)\n\n- Update to version 1.16.0:\n  * chore: prevent file resolver from bubbling errors in binary\n    cataloger (#3410)\n  * chore(deps): update stereoscope to\n    cbd43fb4e5d348fe680066ee6329385fd6a4f827 (#3411)\n  * chore(deps): update CPE dictionary index (#3414)\n  * chore(deps): bump github.com/adrg/xdg from 0.5.2 to 0.5.3\n    (#3408)\n  * chore(deps): bump github.com/charmbracelet/lipgloss from 0.13.1\n    to 1.0.0 (#3409)\n  * chore(deps): update stereoscope to\n    2ce1e520983b1c21d5150d7fae2b39e8e5ab9063 (#3405)\n  * Issue #3143 - fixed format conversion docs link (#3407)\n  * feat: support dependencies and purl for Native Image SBOMs\n    (#3399)\n  * chore(deps): update stereoscope to\n    9c92fe30492ffeba14ed2e23ad1fd923341dda4f (#3398)\n  * feat: exclude devDependencies from package-lock.json parsing\n    (#3371)\n  * chore(deps): bump github.com/adrg/xdg from 0.5.1 to 0.5.2\n    (#3394)\n  * chore(deps): bump anchore/sbom-action from 0.17.5 to 0.17.6\n    (#3393)\n  * fix: stack overflow in spyingIoReadCloser (#3392)\n  * fix: bad pom files may cause infinite loop (#3391)\n\n- Update to version 1.15.0:\n  * chore(deps): update stereoscope to\n    bcc40c6817524718277256d6b774ce643f98640a (#3388)\n  * chore(deps): bump actions/setup-go from 5.0.2 to 5.1.0 (#3384)\n  * chore(deps): bump github.com/charmbracelet/bubbletea from 1.1.1\n    to 1.1.2 (#3385)\n  * chore(deps): update tools to latest versions (#3383)\n  * chore(deps): update CPE dictionary index (#3387)\n  * chore(deps): bump actions/checkout from 4.2.1 to 4.2.2 (#3380)\n  * feat: multi-level configuration and profiles (#3337)\n  * feat: Java dependency graph information (#3363)\n  * Expanded dpkg cataloger globs (#3373)\n  * Enable cargo-auditable-binary-cataloger for files/directories\n    (#3376)\n  * chore(deps): bump github/codeql-action from 3.26.13 to 3.27.0\n    (#3374)\n  * chore(deps): bump github.com/charmbracelet/lipgloss (#3375)\n  * chore(deps): update stereoscope to\n    6db3c175f1f836e552b01ee70e5d5528cc04bce4 (#3362)\n  * chore(deps): bump actions/cache from 4.1.1 to 4.1.2 (#3364)\n  * chore(deps): bump anchore/sbom-action from 0.17.4 to 0.17.5\n    (#3365)\n  * chore(deps): bump github.com/go-git/go-billy/v5 from 5.5.0 to\n    5.6.0 (#3367)\n\n- Update to version 1.14.2:\n  * Create single license scanner for all catalogers (#3348)\n  * chore(deps): update stereoscope to\n    a38c93517fc7d67ca1af826ac529a06c05b571d2 (#3357)\n  * chore(deps): update CPE dictionary index (#3358)\n  * chore(deps): bump github.com/jedib0t/go-pretty/v6 from 6.6.0 to\n    6.6.1 (#3361)\n  * update to latest packageurl-go (#3347)\n  * chore(deps): update tools to latest versions (#3342)\n  * chore(deps): update stereoscope to\n    9e57bce5efeb0ffe27770dd0b8eb2eef8b38512f (#3338)\n  * chore(deps): bump github.com/adrg/xdg from 0.5.0 to 0.5.1\n    (#3344)\n  * fix: use official CPE for linux kernel (#3343)\n  * chore(deps): bump anchore/sbom-action from 0.17.3 to 0.17.4\n    (#3340)\n  * fix: improve mariadb binary classifer to detect older versions\n    (#3339)\n","modified":"2026-06-10T18:24:22.977340544Z","published":"2026-06-08T17:34:13Z","related":["CVE-2024-39331"],"upstream":["CVE-2024-39331"],"references":[{"type":"ADVISORY"},{"type":"WEB","url":"https://www.suse.com/security/cve/CVE-2024-39331"}],"affected":[{"package":{"name":"syft","ecosystem":"openSUSE:Leap 16.0","purl":"pkg:rpm/opensuse/syft&distro=openSUSE%20Leap%2016.0"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"1.45.0-bp160.1.1"}]}],"ecosystem_specific":{"binaries":[{"syft-fish-completion":"1.45.0-bp160.1.1","syft-zsh-completion":"1.45.0-bp160.1.1","syft":"1.45.0-bp160.1.1","syft-bash-completion":"1.45.0-bp160.1.1"}]},"database_specific":{"source":"https://ftp.suse.com/pub/projects/security/osv/openSUSE-SU-2026:20928-1.json"}}],"schema_version":"1.7.5"}