G

Grype

G
Grype Security v0.116.1

v0.116.1

Bug Fixes Ensure channel parsing is consistent [PR #3603 @wagoodman] Scope Go GHSA twins by shared CVE [PR #3592 @wagoodman] do not cache a comparator that failed to build [PR #3567 @arpitjain099] Add fix date to rhel minor records created from rhsa [PR #3585 @wagoodman] grype reporting CVE-64091 as critical - redhat says it is not affected [Issue #3591] panic: index out of range in distro.parseVe…

G
Grype Security v0.116.0

v0.116.0

Added Features duplicate RHSAs to all applicable RHEL minor versions [PR #3542 @willmurphyscode] add chainguard osv transformer [PR #3474 @crosleyzack] populate package architecture for matching [PR #3504 @willmurphyscode] lightweight reachability analysis to reduce Golang false positives [Issue #2960] [PR #3509 @spiffcs] Deduplicate Go matches that are aliases of each other (same CVE reported und…

G
Grype Security v0.115.0

v0.115.0

Added Features emit golang.org/x/net vulns from govlundb [PR #3534 @willmurphyscode] Merge Go vuln matches with GHSA matches [Issue #3515] Bug Fixes only emit records for stdlib [PR #3527 @willmurphyscode] mark hummingbird distro as rolling [PR #3521 @willmurphyscode] disable go stdlib CPE matching by default [PR #3517 @willmurphyscode] merge in custom ranges when applicable [PR #3514 @willmurphys…

G
Grype Security v0.114.0

v0.114.0

Added Features Add ability to scan zarf packages [#3329 #3366 @brandtkeller] Additional Changes respect withdrawn status of Go Vuln DB OSV records [#3495 @willmurphyscode] Govulndb OSV transformer [#3485 @willmurphyscode] (Full Changelog)

G
Grype Security v0.113.0

v0.113.0

Added Features Include Ubuntu 26.04 "resolute" in distro codenames [#3397 @anchore-oss-update-bot] source RPM filtering on Hummingbird [#3410 @willmurphyscode] Bug Fixes use relatedVulnerabilities description as fallback in SARIF output [#3271 @axidex] improve platform CPE determination logic [#3470 @westonsteimel] normalize uppercase V in semantic version comparison [#3461 @immanuwell] purl handl…

G
Grype Security v0.112.0

v0.112.0

Added Features Expand ignore rules to owned sub packages of distro packages [#3368 #3326 @kzantow] Additional Changes update anchore dependencies [#3391 @anchore-oss-update-bot] (Full Changelog)

G
Grype Security v0.111.1

v0.111.1

Bug Fixes apply overlap by ownership removal to dynamically created relationships [#3363 @kzantow] compare mismatched package / db versions [#3372 @kzantow] Grype doesn't recognize debian component when "group" : "debian" is specified [#2967] HelpURI missing information in SARIF output [#2874 #3351 @will-bates11] (Full Changelog)

G
Grype Security v0.111.0

v0.111.0

Added Features db diff for v6 [#3277 @kzantow] add ProvideFromReader for in-memory SBOM processing [#3344 @jspilman] match on hummingbird [#3331 @willmurphyscode] CSAF vex transformer [#3349 @willmurphyscode] curated mapping of known CPE to grype package specifiers [#3332 @westonsteimel] templates/html.tmpl - Add Grype version and vulnerability DB version [#2877 #3345 @kenvez] Bug Fixes normalise…

G
Grype Security v0.110.0

v0.110.0

Added Features suppress GHSA matches on language packages in fixed APKs [#3282 @willmurphyscode] Bug Fixes use Syft for decoding CPEs [#3058 @chovanecadam] Additional Changes bump github.com/buger/jsonparser to v1.1.2 [#3297 @willmurphyscode] update quality gate labels [#3293 @westonsteimel] (Full Changelog)

G
Grype Security v0.109.1

v0.109.1

Bug Fixes CVE-2025-12183 is not detected even if vulnerable jar is present [#3205] Additional Changes migrate fixtures to testdata [#3263 @wagoodman] (Full Changelog)

G
Grype Security v0.109.0

v0.109.0

Added Features Strip v prefix from apk versions [#3239 @wagoodman] Bug Fixes missing EPSS/KEV should not be fatal error [#3224 @willmurphyscode] Additional Changes update build flag to use provenance=false [#3243 @spiffcs] update to check-latest golang for ci [#3238 @spiffcs] enable fedora OS transformer [#3232 @willmurphyscode] Port grype-db lib to grype [#3149 @wagoodman] (Full Changelog)

G
Grype Security v0.108.0

v0.108.0

Added Features enable disabling EOL warnings [#3204 @willmurphyscode] Bug Fixes fix fallback on major only distro [#3213 @willmurphyscode] VEX Documents still not working with syft sbom [#3167] VEX: minimal OpenVEX Example not working [#3212] Additional Changes support more accurate scanning for postmarketos [#3182 @westonsteimel] charmbracelet/bubbletea erases grype ui status line [#3214 @spiffcs…