fix(deps): update vulnfeeds-go (major) #4712
Open
+30
−9
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v1.9.2→v2.3.2v2.4.0→v3.0.1Release Notes
google/osv-scanner (github.com/google/osv-scanner)
v2.3.2Compare Source
This release includes performance improvements for local scanning, reducing memory usage and avoiding unnecessary advisory loading. It also fixes issues with MCP's get_vulnerability_details tool, git queries in
osv-scanner.json, and ignore entry tracking, along with documentation updates.Fixes:
Misc:
bun.lockas a supported lockfilev2.3.1Compare Source
Features:
packagedeprecationplugin via the new--experimental-flag-deprecated-packagesflag. The result is available in all output formats except SPDX.Fixes:
deps.devpackage names.Misc:
v2.3.0Compare Source
This release migrates to the new
osv.devandosv-schemaproto bindings for its internal data models (#2328). This is primarily an internal change and should not impact users.Features:
requirementsenhanceableextractor with transitive enricher.osduplicateannotators.Fixes:
--ignore-scriptsflag to npm lockfile generation.--all-packagesflag.v2.2.4Compare Source
Features:
osv-scanner experimental-mcp)osv-scalibrintegration, replacingbaseimagematchwith the base image enricher.Fixes:
.gitsuffix when checking if an advisory affects a git repository (fixes #2291).cmdloggerandosv-scalibrwhen set (fixes #2081).v2.2.3Compare Source
Features:
--experimental-pluginsflag additive by default, and introduce a new--experimental-no-default-pluginsflag.osv-scalibrto 0.3.4 for improved dependency extraction. See osv-scalibr changelog for additional information.Fixes:
input.Pathwas incorrectly constructed on Windows when using the-Lflag.v2.2.2Compare Source
Features:
osv-scanner-custom.jsonfiles asosv-scanner.jsoncustom lockfiles.Fixes:
v2.2.1Compare Source
Fixes
v2.2.0Compare Source
OSV-Scanner now supports all OSV-Scalibr features behind experimental flags (
--experimental-plugins, see details here)!Features:
Fixes:
API Changes:
v2.1.0Compare Source
Features:
--show-all-vulnsflag to show all.gems.lockedfiles used by Bundler.requirements.txtfiles.--sbomflag in favor of the existing-L/--lockfileflag for scanning SBOMs.Fixes:
:Pro,:LTS).v2.0.3Compare Source
Features:
osv-scanner ./scan-this-dir --format=vertical, by updating to cli/v3stabletag to container images for releases that follow semantic versioning.--experimental-extractorsand--experimental-disable-extractorsflags to allow for more granular control over which OSV-Scalibr dependency extractors are used.Fixes:
<dependency>elements.MatchVulnerabilitieswhen the API response is nil, particularly on timeout.Misc:
v2.0.2Compare Source
Fixes:
tooldirective (Go 1.24+) ingo.modfiles would fail. The scanner image has been updated to use a newer Go version.v2.0.1Compare Source
Features:
packages.configandpackages.lock.jsonfiles.Fixes:
Docs:
API Changes:
v2.0.0Compare Source
This release merges the improvements, features, and fixes from v2.0.0-rc1, v2.0.0-beta2, and v2.0.0-beta1.
Important: This release includes several breaking changes aimed at future-proofing OSV-Scanner. Please consult our comprehensive Migration Guide to ensure a smooth upgrade.
Features:
deps.dev.osv-scanner scan image <image-name>:<tag>osv-scanner scan --serve ...overrideremediation strategy.pom.xmland parent POM files.osv-scalibr:cabal.project.freeze,stack.yaml.lockdeps.jsonuv.locknode_modules, Python wheels, Java uber jars, Go binariesosv-scanner updatecommand for updating the local vulnerability database (formerly experimental).bun.locklockfiles.scan imagecommand.--serveusing the new--portflag.Breaking Changes:
--interactiveflag for interactive mode.--verbosity=verboseverbosity level.--licenseflag.reporterremoved; logging now usesslog, which can be overridden.lockfile(migrated toOSV-Scalibr).Improvements:
Fixes:
bom.xmlfilename.We encourage everyone to upgrade to OSV-Scanner v2.0.0 and experience these powerful new capabilities! As always, your feedback is invaluable, so please don't hesitate to share your thoughts and suggestions.
go-yaml/yaml (gopkg.in/yaml.v2)
v3.0.1Compare Source
v3.0.0Compare Source
Configuration
📅 Schedule: Branch creation - "before 6am on wednesday" in timezone Australia/Sydney, Automerge - At any time (no schedule defined).
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.