Script 'mail_helper' called by obssrc
Hello community,

here is the log from the commit of package grype for openSUSE:Factory checked 
in at 2026-09-18 22:06:43
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Comparing /work/SRC/openSUSE:Factory/grype (Old)
 and      /work/SRC/openSUSE:Factory/.grype.new.383539 (New)
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Package is "grype"

Fri Sep 18 22:06:43 2026 rev:129 rq:1378716 version:0.119.0

Changes:
--------
--- /work/SRC/openSUSE:Factory/grype/grype.changes      2026-08-28 
19:52:01.544714766 +0200
+++ /work/SRC/openSUSE:Factory/.grype.new.383539/grype.changes  2026-09-18 
22:07:36.511284013 +0200
@@ -1,0 +2,103 @@
+Fri Sep 18 05:06:33 UTC 2026 - Johannes Kastl 
<[email protected]>
+
+- Update to version 0.119.0:
+  * Added Features
+    - Expose distro-fixed dropped matches via ignoredMatches so
+      --show-suppressed can surface them [Issue #3450] [PR #3705]
+    - Licensing: copyright owner missing, needed for Debian
+      packaging [Issue #3501]
+  * Bug Fixes
+    - fixes typo in cpe example input for cpe-direct scan [PR
+      #3679]
+    - --by-cve: which advisory record survives the merge varies
+      between runs [Issue #3630]
+  * Additional Changes
+    - OpenVEX transformer drops the namespace from Go module PURLs
+      [Issue #3680] [PR #3683]
+    - Docs missing for include-aliases [Issue #3663] [PR #3671]
+  * Dependencies
+    54 dependency changes (54 updated). 6 vulnerabilities
+    remediated.
+    - Remediated (6)
+      - GHSA-2v4p-qf9q-27wj (High) — google.golang.org/grpc
+      - GHSA-7jxh-36q5-gcqv (Medium) —
+        github.com/containerd/containerd/v2
+      - GHSA-qc2q-p7wx-3px3 (Medium) — google.golang.org/grpc
+      - GHSA-vp52-pcj8-j9qc (High) — google.golang.org/grpc
+      - GO-2026-6354 (High) — golang.org/x/crypto
+      - GO-2026-6355 (High) — golang.org/x/crypto
+    - Updated (54 packages)
+      - cloud.google.com/go/auth v0.22.0 → v0.23.2
+      - cloud.google.com/go/iam v1.11.0 → v1.12.0
+      - cloud.google.com/go/logging v1.18.0 → v1.19.0
+      - cloud.google.com/go/monitoring v1.29.0 → v1.30.0
+      - cloud.google.com/go/storage v1.64.0 → v1.65.1
+      - github.com/CycloneDX/cyclonedx-go v0.11.0 → v0.12.0
+      - github.com/anchore/go-sync v0.1.1 → v0.1.2
+      - github.com/anchore/stereoscope v0.3.1 → v0.3.2
+      - github.com/anchore/syft v1.51.1 → v1.52.0
+      - github.com/aws/aws-sdk-go-v2 v1.43.4 → v1.44.0
+      - github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream
+        v1.7.16 → v1.7.20
+      - github.com/aws/aws-sdk-go-v2/config v1.32.35 → v1.32.40
+      - github.com/aws/aws-sdk-go-v2/credentials v1.19.34 →
+        v1.19.39
+      - github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.35 →
+        v1.18.40
+      - github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.35
+        → v1.4.40
+      - github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.35
+        → v2.7.40
+      - github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.36 → v1.4.41
+      - github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding
+        v1.13.15 → v1.13.19
+      - github.com/aws/aws-sdk-go-v2/service/internal/checksum
+        v1.9.28 → v1.10.0
+      - github.com/aws/aws-sdk-go-v2/service/internal/presigned-url
+        v1.13.35 → v1.13.40
+      - github.com/aws/aws-sdk-go-v2/service/internal/s3shared
+        v1.19.36 → v1.19.41
+      - github.com/aws/aws-sdk-go-v2/service/s3 v1.106.5 → v1.108.0
+      - github.com/aws/aws-sdk-go-v2/service/signin v1.5.4 → v1.6.0
+      - github.com/aws/aws-sdk-go-v2/service/sso v1.33.4 → v1.34.0
+      - github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.4 →
+        v1.39.0
+      - github.com/aws/aws-sdk-go-v2/service/sts v1.45.4 → v1.46.0
+      - github.com/aws/smithy-go v1.27.6 → v1.28.1
+      - github.com/containerd/containerd/v2 v2.3.4 → v2.3.5
+        (remediated GHSA-7jxh-36q5-gcqv)
+      - github.com/docker/cli v29.7.2+incompatible →
+        v29.8.0+incompatible
+      - github.com/google/go-containerregistry v0.21.9 → v0.22.1
+      - github.com/googleapis/enterprise-certificate-proxy v0.3.19
+        → v0.3.20
+      - github.com/googleapis/gax-go/v2 v2.23.0 → v2.24.0
+      - github.com/gpustack/gguf-parser-go v0.25.0 → v0.26.3
+      - github.com/hashicorp/go-getter v1.8.8 → v1.8.9
+      - github.com/klauspost/compress v1.19.2 → v1.20.0
+      - github.com/moby/moby/api v1.55.0 → v1.56.0
+      - github.com/moby/moby/client v0.5.1 → v0.6.0
+      - github.com/pandatix/go-cvss v0.6.2 → v0.6.4
+      - github.com/terminalstatic/go-xsd-validate v0.1.6 → v0.1.8
+      - golang.org/x/crypto v0.55.0 → v0.56.0 (remediated
+        GO-2026-6354, GO-2026-6355)
+      - golang.org/x/mod v0.40.0 → v0.41.0
+      - golang.org/x/time v0.15.0 → v0.16.0
+      - google.golang.org/api v0.292.0 → v0.294.0
+      - google.golang.org/genproto v0.0.0-aa98bba → v0.0.0-e75dac1
+      - google.golang.org/genproto/googleapis/api v0.0.0-925bb5d →
+        v0.0.0-e75dac1
+      - google.golang.org/genproto/googleapis/rpc v0.0.0-6ac0973 →
+        v0.0.0-08b0e42
+      - google.golang.org/grpc v1.83.0 → v1.83.2 (remediated
+        GHSA-2v4p-qf9q-27wj, GHSA-qc2q-p7wx-3px3,
+        GHSA-vp52-pcj8-j9qc)
+      - google.golang.org/protobuf v1.36.12-0.f2248ac → v1.36.12
+      - modernc.org/cc/v4 v4.29.1 → v4.29.2
+      - modernc.org/ccgo/v4 v4.34.6 → v4.35.0
+      - modernc.org/gc/v3 v3.1.4 → v3.1.5
+      - modernc.org/libc v1.74.4 → v1.75.6
+      - modernc.org/memory v1.11.0 → v1.12.1
+      - modernc.org/sqlite v1.56.0 → v1.58.0
+
+-------------------------------------------------------------------

Old:
----
  grype-0.118.0.obscpio

New:
----
  grype-0.119.0.obscpio

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++

Other differences:
------------------
++++++ grype.spec ++++++
--- /var/tmp/diff_new_pack.8dHCDm/_old  2026-09-18 22:07:38.054348683 +0200
+++ /var/tmp/diff_new_pack.8dHCDm/_new  2026-09-18 22:07:38.057348808 +0200
@@ -17,7 +17,7 @@
 
 
 Name:           grype
-Version:        0.118.0
+Version:        0.119.0
 Release:        0
 Summary:        A vulnerability scanner for container images and filesystems
 License:        Apache-2.0

++++++ _service ++++++
--- /var/tmp/diff_new_pack.8dHCDm/_old  2026-09-18 22:07:38.114351197 +0200
+++ /var/tmp/diff_new_pack.8dHCDm/_new  2026-09-18 22:07:38.118351365 +0200
@@ -3,7 +3,7 @@
     <param name="url">https://github.com/anchore/grype.git</param>
     <param name="scm">git</param>
     <param name="exclude">.git</param>
-    <param name="revision">refs/tags/v0.118.0</param>
+    <param name="revision">refs/tags/v0.119.0</param>
     <param name="match-tag">v*</param>
     <param name="versionformat">@PARENT_TAG@</param>
     <param name="versionrewrite-pattern">v(.*)</param>

++++++ _servicedata ++++++
--- /var/tmp/diff_new_pack.8dHCDm/_old  2026-09-18 22:07:38.159353083 +0200
+++ /var/tmp/diff_new_pack.8dHCDm/_new  2026-09-18 22:07:38.165353335 +0200
@@ -3,6 +3,6 @@
                 <param name="url">https://github.com/anchore/grype</param>
               <param 
name="changesrevision">fa8b7e2a528cf1f8b098123f256c61db9e5df69c</param></service><service
 name="tar_scm">
                 <param name="url">https://github.com/anchore/grype.git</param>
-              <param 
name="changesrevision">756eb9a24f7beeafb6871a24e943e8a3ae210695</param></service></servicedata>
+              <param 
name="changesrevision">b6f5194537747ee7f705f4113069ac9eb269919f</param></service></servicedata>
 (No newline at EOF)
 

++++++ grype-0.118.0.obscpio -> grype-0.119.0.obscpio ++++++
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/grype-0.118.0/cmd/grype/cli/commands/root.go 
new/grype-0.119.0/cmd/grype/cli/commands/root.go
--- old/grype-0.118.0/cmd/grype/cli/commands/root.go    2026-08-27 
20:40:29.000000000 +0200
+++ new/grype-0.119.0/cmd/grype/cli/commands/root.go    2026-09-17 
17:25:25.000000000 +0200
@@ -73,7 +73,7 @@
     {{.appName}} purl:path/to/purl/file                 read a newline 
separated file of package URLs from a path on disk
     {{.appName}} PURL                                   read a single package 
PURL directly (e.g. pkg:apk/[email protected]?distro=alpine-3.20.3)
     {{.appName}} cpes:path/to/cpes/file                 read a newline 
separated file of package CPEs from a path on disk
-    {{.appName}} CPE                                    read a single CPE 
directly (e.g. cpe:2.3:a:openssl:openssl:3.0.14:*:*:*:*:*)
+    {{.appName}} CPE                                    read a single CPE 
directly (e.g. cpe:2.3:a:openssl:openssl:3.0.14:*:*:*:*:*:*:* or 
cpe:/a:openssl:openssl:3.0.14)
     {{.appName}} zarf:path/to/package.tar.zst           scan all SBOMs within 
a Zarf package archive
 
 You can also pipe in Syft JSON directly:
@@ -234,6 +234,7 @@
                Alerts: grype.AlertsConfig{
                        EnableEOLDistroWarnings: 
opts.Alerts.EnableEOLDistroWarnings,
                },
+               IncludeMatcherSuppressions: opts.IncludeMatcherSuppressions,
        }
 
        remainingMatches, ignoredMatches, err := 
vulnMatcher.FindMatchesContext(ctx, packages, pkgContext)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/grype-0.118.0/cmd/grype/cli/options/grype.go 
new/grype-0.119.0/cmd/grype/cli/options/grype.go
--- old/grype-0.118.0/cmd/grype/cli/options/grype.go    2026-08-27 
20:40:29.000000000 +0200
+++ new/grype-0.119.0/cmd/grype/cli/options/grype.go    2026-09-17 
17:25:25.000000000 +0200
@@ -31,7 +31,8 @@
        FailOn                     string             `yaml:"fail-on-severity" 
json:"fail-on-severity" mapstructure:"fail-on-severity"`
        Registry                   registry           `yaml:"registry" 
json:"registry" mapstructure:"registry"`
        ShowSuppressed             bool               `yaml:"show-suppressed" 
json:"show-suppressed" mapstructure:"show-suppressed"`
-       ByCVE                      bool               `yaml:"by-cve" 
json:"by-cve" mapstructure:"by-cve"` // --by-cve, indicates if the original 
match vulnerability IDs should be preserved or the CVE should be used instead
+       IncludeMatcherSuppressions bool               
`yaml:"include-matcher-suppressions" json:"include-matcher-suppressions" 
mapstructure:"include-matcher-suppressions"` // include matches suppressed 
internally by matchers (distro fixed/NAK records, built-in false-positive list) 
in the ignored matches output, default=false
+       ByCVE                      bool               `yaml:"by-cve" 
json:"by-cve" mapstructure:"by-cve"`                                            
                       // --by-cve, indicates if the original match 
vulnerability IDs should be preserved or the CVE should be used instead
        SortBy                     SortBy             `yaml:",inline" 
json:",inline" mapstructure:",squash"`
        Name                       string             `yaml:"name" json:"name" 
mapstructure:"name"`
        DefaultImagePullSource     string             
`yaml:"default-image-pull-source" json:"default-image-pull-source" 
mapstructure:"default-image-pull-source"`
@@ -71,6 +72,7 @@
                CheckForAppUpdate:          true,
                VexAdd:                     []string{},
                MatchUpstreamKernelHeaders: false,
+               IncludeMatcherSuppressions: false,
                SortBy:                     defaultSortBy(),
                Timestamp:                  true,
                Alerts:                     defaultAlerts(),
@@ -196,22 +198,29 @@
        descriptions.Add(&o.Pretty, `pretty-print output`)
        descriptions.Add(&o.FailOn, `upon scanning, if a severity is found at 
or above the given severity then the return code will be 1
 default is unset which will skip this validation (options: negligible, low, 
medium, high, critical)`)
-       descriptions.Add(&o.Ignore, `A list of vulnerability ignore rules, one 
or more property may be specified and all matching vulnerabilities will be 
ignored.
+       descriptions.Add(&o.Ignore, `a list of vulnerability ignore rules; a 
match must meet ALL criteria specified in a rule to be ignored.
 This is the full set of supported rule fields:
-  - vulnerability: CVE-2008-4318
-    fix-state: unknown
+  - vulnerability: CVE-2008-4318        # match by vulnerability ID (required 
if no other criteria are given)
+    namespace: nvd:cpe                   # match by vulnerability namespace 
(e.g. nvd:cpe, github:language:go)
+    fix-state: unknown                   # match by fix state; options: fixed, 
not-fixed, wont-fix, unknown
+    match-type: exact-direct-match       # match by how the vulnerability was 
found; options: exact-direct-match, exact-indirect-match, cpe-match
+    reason: "tolerated by policy"        # optional human-readable note 
recorded on the ignored match (does not affect matching)
+    include-aliases: true                # also apply the vulnerability ID 
match to aliases/related CVEs (default: false)
     package:
-      name: libcurl
-      version: 1.5.1
-      type: npm
-      location: "/usr/local/lib/node_modules/**"
+      name: libcurl                      # match by package name (supports 
regular expressions)
+      version: 1.5.1                     # match by package version
+      language: python                   # match by package language (e.g. 
python, javascript, java, go, …)
+      type: npm                          # match by package type (e.g. rpm, 
deb, apk, gem, npm, go-module, …)
+      location: "/usr/local/lib/node_modules/**"  # match by package location 
(supports glob patterns)
+      upstream-name: curl                # match by upstream package name 
(supports regular expressions)
 
-VEX fields apply when Grype reads vex data:
+VEX fields apply when Grype reads VEX data:
   - vex-status: not_affected
     vex-justification: vulnerable_code_not_present
 `)
        descriptions.Add(&o.VexAdd, `VEX statuses to consider as ignored rules`)
        descriptions.Add(&o.MatchUpstreamKernelHeaders, `match kernel-header 
packages with upstream kernel as kernel vulnerabilities`)
+       descriptions.Add(&o.IncludeMatcherSuppressions, `include matches 
suppressed internally by matchers (e.g. distro fixed/NAK records, the built-in 
false-positive list) in the ignored matches output`)
 }
 
 func (o Grype) FailOnSeverity() *vulnerability.Severity {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/grype-0.118.0/go.mod new/grype-0.119.0/go.mod
--- old/grype-0.118.0/go.mod    2026-08-27 20:40:29.000000000 +0200
+++ new/grype-0.119.0/go.mod    2026-09-17 17:25:25.000000000 +0200
@@ -3,7 +3,7 @@
 go 1.26.3
 
 require (
-       github.com/CycloneDX/cyclonedx-go v0.11.0
+       github.com/CycloneDX/cyclonedx-go v0.12.0
        github.com/Masterminds/semver/v3 v3.5.0
        github.com/Masterminds/sprig/v3 v3.3.0
        github.com/OneOfOne/xxhash v1.2.8
@@ -17,7 +17,7 @@
        github.com/anchore/go-logger v0.1.1
        github.com/anchore/go-version v1.2.2-0.20210903204242-51efa5b487c4
        github.com/anchore/packageurl-go v0.2.0
-       github.com/anchore/stereoscope v0.3.1
+       github.com/anchore/stereoscope v0.3.2
        github.com/aquasecurity/go-pep440-version v0.0.1
        github.com/araddon/dateparse v0.0.0-20210429162001-6b43995a97de
        github.com/bitnami/go-version v0.0.0-20250505154626-452e8c5ee607
@@ -36,18 +36,18 @@
        github.com/gocsaf/csaf/v3 v3.5.1
        github.com/gohugoio/hashstructure v0.6.0
        github.com/google/go-cmp v0.7.0
-       github.com/google/go-containerregistry v0.21.9
+       github.com/google/go-containerregistry v0.22.1
        github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510
        github.com/google/uuid v1.6.0
        github.com/gookit/color v1.6.1
        github.com/hako/durafmt v0.0.0-20210608085754-5c1018a4e16b
        github.com/hashicorp/go-cleanhttp v0.5.2
-       github.com/hashicorp/go-getter v1.8.8
+       github.com/hashicorp/go-getter v1.8.9
        github.com/hashicorp/go-multierror v1.1.1
        github.com/iancoleman/strcase v0.3.0
        github.com/invopop/jsonschema v0.14.0
        github.com/jinzhu/copier v0.4.0
-       github.com/klauspost/compress v1.19.2
+       github.com/klauspost/compress v1.20.0
        github.com/knqyf263/go-apk-version v0.0.0-20200609155635-041fdbb8563f
        github.com/knqyf263/go-deb-version v0.0.0-20241115132648-6f4aee6ccd23
        github.com/masahiro331/go-mvn-version v0.0.0-20250131095131-f4974fa13b8a
@@ -56,7 +56,7 @@
        github.com/olekukonko/tablewriter v1.1.4
        github.com/openvex/go-vex v0.2.8
        github.com/owenrumney/go-sarif v1.1.2-0.20231003122901-1000f5e05554
-       github.com/pandatix/go-cvss v0.6.2
+       github.com/pandatix/go-cvss v0.6.4
        // pinned to pull in 386 arch fix: 
https://github.com/scylladb/go-set/commit/cc7b2070d91ebf40d233207b633e28f5bd8f03a5
        github.com/scylladb/go-set v1.0.3-0.20200225121959-cc7b2070d91e
        github.com/sergi/go-diff v1.4.0
@@ -71,14 +71,14 @@
        github.com/xi2/xz v0.0.0-20171230120015-48954b6210f8
        golang.org/x/exp v0.0.0-20260410095643-746e56fc9e2f
        golang.org/x/text v0.41.0
-       golang.org/x/time v0.15.0
+       golang.org/x/time v0.16.0
        golang.org/x/tools v0.49.0
        gopkg.in/yaml.v3 v3.0.1
        gorm.io/gorm v1.31.2
 )
 
 require (
-       github.com/anchore/syft v1.51.1
+       github.com/anchore/syft v1.52.0
        github.com/bmatcuk/doublestar/v4 v4.10.0
        github.com/santhosh-tekuri/jsonschema/v6 v6.0.3
 )
@@ -86,12 +86,12 @@
 require (
        cel.dev/expr v0.25.2 // indirect
        cloud.google.com/go v0.123.0 // indirect
-       cloud.google.com/go/auth v0.22.0 // indirect
+       cloud.google.com/go/auth v0.23.2 // indirect
        cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect
        cloud.google.com/go/compute/metadata v0.9.0 // indirect
-       cloud.google.com/go/iam v1.11.0 // indirect
-       cloud.google.com/go/monitoring v1.29.0 // indirect
-       cloud.google.com/go/storage v1.64.0 // indirect
+       cloud.google.com/go/iam v1.12.0 // indirect
+       cloud.google.com/go/monitoring v1.30.0 // indirect
+       cloud.google.com/go/storage v1.65.1 // indirect
        dario.cat/mergo v1.0.2 // indirect
        github.com/BurntSushi/toml v1.6.0 // indirect
        github.com/DataDog/zstd v1.5.7 // indirect
@@ -111,28 +111,28 @@
        github.com/anchore/go-macholibre v0.1.1 // indirect
        github.com/anchore/go-rpmdb v0.2.0 // indirect
        github.com/anchore/go-struct-converter v0.2.0-rc2 // indirect
-       github.com/anchore/go-sync v0.1.1 // indirect
+       github.com/anchore/go-sync v0.1.2 // indirect
        github.com/andybalholm/brotli v1.2.0 // indirect
        github.com/apparentlymart/go-textseg/v15 v15.0.0 // indirect
        github.com/aquasecurity/go-version v0.0.1 // indirect
-       github.com/aws/aws-sdk-go-v2 v1.43.4 // indirect
-       github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.16 // 
indirect
-       github.com/aws/aws-sdk-go-v2/config v1.32.35 // indirect
-       github.com/aws/aws-sdk-go-v2/credentials v1.19.34 // indirect
-       github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.35 // indirect
-       github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.35 // indirect
-       github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.35 // indirect
-       github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.36 // indirect
-       github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.15 
// indirect
-       github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.28 // 
indirect
-       github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.35 // 
indirect
-       github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.36 // 
indirect
-       github.com/aws/aws-sdk-go-v2/service/s3 v1.106.5 // indirect
-       github.com/aws/aws-sdk-go-v2/service/signin v1.5.4 // indirect
-       github.com/aws/aws-sdk-go-v2/service/sso v1.33.4 // indirect
-       github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.4 // indirect
-       github.com/aws/aws-sdk-go-v2/service/sts v1.45.4 // indirect
-       github.com/aws/smithy-go v1.27.6 // indirect
+       github.com/aws/aws-sdk-go-v2 v1.44.0 // indirect
+       github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.20 // 
indirect
+       github.com/aws/aws-sdk-go-v2/config v1.32.40 // indirect
+       github.com/aws/aws-sdk-go-v2/credentials v1.19.39 // indirect
+       github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.40 // indirect
+       github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.40 // indirect
+       github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.40 // indirect
+       github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.41 // indirect
+       github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.19 
// indirect
+       github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.10.0 // 
indirect
+       github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.40 // 
indirect
+       github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.41 // 
indirect
+       github.com/aws/aws-sdk-go-v2/service/s3 v1.108.0 // indirect
+       github.com/aws/aws-sdk-go-v2/service/signin v1.6.0 // indirect
+       github.com/aws/aws-sdk-go-v2/service/sso v1.34.0 // indirect
+       github.com/aws/aws-sdk-go-v2/service/ssooidc v1.39.0 // indirect
+       github.com/aws/aws-sdk-go-v2/service/sts v1.46.0 // indirect
+       github.com/aws/smithy-go v1.28.1 // indirect
        github.com/aymanbagabas/go-osc52/v2 v2.0.1 // indirect
        github.com/bahlo/generic-list-go v0.2.0 // indirect
        github.com/becheran/wildmatch-go v1.0.0 // indirect
@@ -155,7 +155,7 @@
        github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2 // indirect
        github.com/containerd/cgroups/v3 v3.1.3 // indirect
        github.com/containerd/containerd/api v1.11.1 // indirect
-       github.com/containerd/containerd/v2 v2.3.4 // indirect
+       github.com/containerd/containerd/v2 v2.3.5 // indirect
        github.com/containerd/continuity v0.5.0 // indirect
        github.com/containerd/errdefs v1.0.0 // indirect
        github.com/containerd/errdefs/pkg v0.3.0 // indirect
@@ -169,7 +169,7 @@
        github.com/deitch/magic v0.0.0-20240306090643-c67ab88f10cb // indirect
        github.com/diskfs/go-diskfs v1.9.4 // indirect
        github.com/distribution/reference v0.6.0 // indirect
-       github.com/docker/cli v29.7.2+incompatible // indirect
+       github.com/docker/cli v29.8.0+incompatible // indirect
        github.com/docker/docker-credential-helpers v0.9.5 // indirect
        github.com/docker/go-connections v0.8.1 // indirect
        github.com/docker/go-units v0.5.0 // indirect
@@ -199,9 +199,9 @@
        github.com/google/licensecheck v0.3.1 // indirect
        github.com/google/pprof v0.0.0-20260802141513-ef3492d7dac3 // indirect
        github.com/google/s2a-go v0.1.9 // indirect
-       github.com/googleapis/enterprise-certificate-proxy v0.3.19 // indirect
-       github.com/googleapis/gax-go/v2 v2.23.0 // indirect
-       github.com/gpustack/gguf-parser-go v0.25.0 // indirect
+       github.com/googleapis/enterprise-certificate-proxy v0.3.20 // indirect
+       github.com/googleapis/gax-go/v2 v2.24.0 // indirect
+       github.com/gpustack/gguf-parser-go v0.26.3 // indirect
        github.com/hashicorp/aws-sdk-go-base/v2 v2.0.0-beta.74 // indirect
        github.com/hashicorp/errwrap v1.1.0 // indirect
        github.com/hashicorp/go-version v1.9.0 // indirect
@@ -236,8 +236,8 @@
        github.com/mitchellh/reflectwalk v1.0.2 // indirect
        github.com/moby/docker-image-spec v1.3.1 // indirect
        github.com/moby/locker v1.0.1 // indirect
-       github.com/moby/moby/api v1.55.0 // indirect
-       github.com/moby/moby/client v0.5.1 // indirect
+       github.com/moby/moby/api v1.56.0 // indirect
+       github.com/moby/moby/client v0.6.0 // indirect
        github.com/moby/sys/atomicwriter v0.1.0 // indirect
        github.com/moby/sys/mountinfo v0.7.2 // indirect
        github.com/moby/sys/sequential v0.6.0 // indirect
@@ -320,8 +320,8 @@
        go.yaml.in/yaml/v3 v3.0.5 // indirect
        go.yaml.in/yaml/v4 v4.0.0-rc.2 // indirect
        go4.org v0.0.0-20230225012048-214862532bf5 // indirect
-       golang.org/x/crypto v0.55.0 // indirect
-       golang.org/x/mod v0.40.0 // indirect
+       golang.org/x/crypto v0.56.0 // indirect
+       golang.org/x/mod v0.41.0 // indirect
        golang.org/x/net v0.58.0 // indirect
        golang.org/x/oauth2 v0.36.0 // indirect
        golang.org/x/sync v0.22.0 // indirect
@@ -329,16 +329,16 @@
        golang.org/x/term v0.45.0 // indirect
        golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect
        gonum.org/v1/gonum v0.17.0 // indirect
-       google.golang.org/api v0.292.0 // indirect
-       google.golang.org/genproto v0.0.0-20260519071638-aa98bba5eb94 // 
indirect
-       google.golang.org/genproto/googleapis/api 
v0.0.0-20260630182238-925bb5da69e7 // indirect
-       google.golang.org/genproto/googleapis/rpc 
v0.0.0-20260803160001-6ac0973c030d // indirect
-       google.golang.org/grpc v1.83.0 // indirect
-       google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af // 
indirect
+       google.golang.org/api v0.294.0 // indirect
+       google.golang.org/genproto v0.0.0-20260715232425-e75dac1f907d // 
indirect
+       google.golang.org/genproto/googleapis/api 
v0.0.0-20260715232425-e75dac1f907d // indirect
+       google.golang.org/genproto/googleapis/rpc 
v0.0.0-20260819154853-08b0e4226688 // indirect
+       google.golang.org/grpc v1.83.2 // indirect
+       google.golang.org/protobuf v1.36.12 // indirect
        gopkg.in/warnings.v0 v0.1.2 // indirect
        howett.net/plist v1.0.1 // indirect
-       modernc.org/libc v1.74.4 // indirect
+       modernc.org/libc v1.75.6 // indirect
        modernc.org/mathutil v1.7.1 // indirect
-       modernc.org/memory v1.11.0 // indirect
-       modernc.org/sqlite v1.56.0 // indirect
+       modernc.org/memory v1.12.1 // indirect
+       modernc.org/sqlite v1.58.0 // indirect
 )
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/grype-0.118.0/go.sum new/grype-0.119.0/go.sum
--- old/grype-0.118.0/go.sum    2026-08-27 20:40:29.000000000 +0200
+++ new/grype-0.119.0/go.sum    2026-09-17 17:25:25.000000000 +0200
@@ -31,8 +31,8 @@
 cloud.google.com/go v0.99.0/go.mod 
h1:w0Xx2nLzqWJPuozYQX+hFfCSI8WioryfRDzkoI/Y2ZA=
 cloud.google.com/go v0.123.0 h1:2NAUJwPR47q+E35uaJeYoNhuNEM9kM8SjgRgdeOJUSE=
 cloud.google.com/go v0.123.0/go.mod 
h1:xBoMV08QcqUGuPW65Qfm1o9Y4zKZBpGS+7bImXLTAZU=
-cloud.google.com/go/auth v0.22.0 
h1:Xp9wAKkLoeaYb5pYZZoQGz4E9sdPxIbzS3gywZE3ciQ=
-cloud.google.com/go/auth v0.22.0/go.mod 
h1:M9o2Oz+YI2jAfxewJgb1vyI3vceHF+eohmxyzmrl+9s=
+cloud.google.com/go/auth v0.23.2 
h1:pxSCpfiji41hpzpPdMCftEUCezpgpqmmDdYiAjCKXxo=
+cloud.google.com/go/auth v0.23.2/go.mod 
h1:4DhBRcqvtljQN3dJ57qtqbib5ZGCYE5f2crfiiC2EM0=
 cloud.google.com/go/auth/oauth2adapt v0.2.8 
h1:keo8NaayQZ6wimpNSmW5OPc283g65QNIiLpZnkHRbnc=
 cloud.google.com/go/auth/oauth2adapt v0.2.8/go.mod 
h1:XQ9y31RkqZCcwJWNSx2Xvric3RrU88hAYYbjDWYDL+c=
 cloud.google.com/go/bigquery v1.0.1/go.mod 
h1:i/xbL2UlR5RvWAURpBYZTtm/cXjCha9lbfbpx4poX+o=
@@ -46,14 +46,14 @@
 cloud.google.com/go/datastore v1.0.0/go.mod 
h1:LXYbyblFSglQ5pkeyhO+Qmw7ukd3C+pD7TKLgZqpHYE=
 cloud.google.com/go/datastore v1.1.0/go.mod 
h1:umbIZjpQpHh4hmRpGhH4tLFup+FVzqBi1b3c64qFpCk=
 cloud.google.com/go/firestore v1.6.1/go.mod 
h1:asNXNOzBdyVQmEU+ggO8UPodTkEVFW5Qx+rwHnAz+EY=
-cloud.google.com/go/iam v1.11.0 h1:KieQ9Pb+LLPak1O3Rv3GgCxhnmkYf7Xyh0P5HfF1jFM=
-cloud.google.com/go/iam v1.11.0/go.mod 
h1:KP+nKGugNJW4LcLx1uEZcq1ok5sQHFaQehQNl4QDgV4=
-cloud.google.com/go/logging v1.18.0 
h1:KhzZq+1cSkPH9YUaKLLhLtQxIHitVayBmk0sGfoM9+k=
-cloud.google.com/go/logging v1.18.0/go.mod 
h1:ZGKnpBaURITh+g/uom2VhbiFoFWvejcrHPDhxFtU/gI=
+cloud.google.com/go/iam v1.12.0 h1:Aki3bX9aHUDKPHfnRJfDcTdVedvy6quGBQcTqx3DRXk=
+cloud.google.com/go/iam v1.12.0/go.mod 
h1:FEZ4lXpADAC2AIpQY7LANNjjwyQ2jK439CI2VaD+sLY=
+cloud.google.com/go/logging v1.19.0 
h1:NCqhdVUg3wQ8Cobdf16FDSuTGi3+6+hdSBHrY5TsR6Q=
+cloud.google.com/go/logging v1.19.0/go.mod 
h1:i40NZCHC9Gqvod4yE+yQfDWwlgwW/SrshkkGibCHxcA=
 cloud.google.com/go/longrunning v1.2.0 
h1:WjYH3YHBGCxGJP9M4dWGHBfXr/cFIjMkNgWcJj7/iMM=
 cloud.google.com/go/longrunning v1.2.0/go.mod 
h1:5KMQALFGOCtFoi2xSOA1u3H7WKlhmckgiyFw7+LGQp0=
-cloud.google.com/go/monitoring v1.29.0 
h1:AHhDsFaSax1/4k+qlIDX/SDGe6hggnfXJ9dkgD9qBPY=
-cloud.google.com/go/monitoring v1.29.0/go.mod 
h1:72NOVjJXHY/HBfoLT0+qlCZBT059+9VXLeAnL2PeeVM=
+cloud.google.com/go/monitoring v1.30.0 
h1:r/d+JUbyKmJ8b07iznuKfzVzrIXTWxHQ3lBRm3x2LlY=
+cloud.google.com/go/monitoring v1.30.0/go.mod 
h1:htlUR0QWVMrjFzZmN4LGnMAve9xB/eduwjmINxVZ8RM=
 cloud.google.com/go/pubsub v1.0.1/go.mod 
h1:R0Gpsv3s54REJCy4fxDixWD93lHJMoZTyQ2kNxGRt3I=
 cloud.google.com/go/pubsub v1.1.0/go.mod 
h1:EwwdRX2sKPjnvnqCa270oGRyludottCI76h+R3AArQw=
 cloud.google.com/go/pubsub v1.2.0/go.mod 
h1:jhfEVHT8odbXTkndysNHCcx0awwzvfOlguIAii9o8iA=
@@ -63,8 +63,8 @@
 cloud.google.com/go/storage v1.6.0/go.mod 
h1:N7U0C8pVQ/+NIKOBQyamJIeKQKkZ+mxpohlUTyfDhBk=
 cloud.google.com/go/storage v1.8.0/go.mod 
h1:Wv1Oy7z6Yz3DshWRJFhqM/UCfaWIRTdp0RXyy7KQOVs=
 cloud.google.com/go/storage v1.10.0/go.mod 
h1:FLPqc6j+Ki4BU591ie1oL6qBQGu2Bl/tZ9ullr3+Kg0=
-cloud.google.com/go/storage v1.64.0 
h1:KLpxI/oX9LxeRsNqn877d2WyeT3ryiEwnGt8pwcSPZg=
-cloud.google.com/go/storage v1.64.0/go.mod 
h1:lWyAtwvDZHdL3k68WVKbESP6bmWaV23ZJJ/JEVw/ZaQ=
+cloud.google.com/go/storage v1.65.1 
h1:LRRpBJUTf+OXDPX9jZUKZ3mSLIsz3htG+qUpeNZovyA=
+cloud.google.com/go/storage v1.65.1/go.mod 
h1:UsS9OgFg/XHOSYakQ8ZtLWWeyGkk1WnmD/GsGfN0BHM=
 cloud.google.com/go/trace v1.16.0 
h1:GmQovzFc5F0CNfl0VLgL64aoTtu7xsM0YajW2GlG9+E=
 cloud.google.com/go/trace v1.16.0/go.mod 
h1:r+bdAn16dKLSV1G2D5v3e58IlQlizfxWrUfjx7kM7X0=
 dario.cat/mergo v1.0.2 h1:85+piFYR1tMbRrLcDwR18y4UKJ3aH1Tbzi24VRW1TK8=
@@ -79,8 +79,8 @@
 github.com/BurntSushi/toml v1.6.0 
h1:dRaEfpa2VI55EwlIW72hMRHdWouJeRF7TPYhI+AUQjk=
 github.com/BurntSushi/toml v1.6.0/go.mod 
h1:ukJfTF/6rtPPRCnwkur4qwRxa8vTRFBF0uk2lLoLwho=
 github.com/BurntSushi/xgb v0.0.0-20160522181843-27f122750802/go.mod 
h1:IVnqGOEym/WlBOVXweHU+Q+/VP0lqqI8lqeDx9IjBqo=
-github.com/CycloneDX/cyclonedx-go v0.11.0 
h1:GokP8FiRC+foiuwWhSSLpSD5H4hSWtGnR3wo7apkBFI=
-github.com/CycloneDX/cyclonedx-go v0.11.0/go.mod 
h1:vUvbCXQsEm48OI6oOlanxstwNByXjCZ2wuleUlwGEO8=
+github.com/CycloneDX/cyclonedx-go v0.12.0 
h1:/7Jum36UA6V043tQZ/fE3jf+Nf9gn/qxUFfd7QReMy8=
+github.com/CycloneDX/cyclonedx-go v0.12.0/go.mod 
h1:V2577HhxDDCDLYfkm55WJrz16nHTfyQZwcWUBSG7Z28=
 github.com/DataDog/datadog-go v3.2.0+incompatible/go.mod 
h1:LButxg5PwREeZtORoXG3tL4fMGNddJ+vMq1mwgfaqoQ=
 github.com/DataDog/zstd v1.5.7 h1:ybO8RBeh29qrxIhCA9E8gKY6xfONU9T6G6aP9DTKfLE=
 github.com/DataDog/zstd v1.5.7/go.mod 
h1:g4AWEaM3yOg3HYfnJ3YIawPnVdXJh9QME85blwSAmyw=
@@ -146,16 +146,16 @@
 github.com/anchore/go-rpmdb v0.2.0/go.mod 
h1:ATsRlpCXstnoYfzqBfhwGw0U2dolx1BBQ9rAU8jWBAw=
 github.com/anchore/go-struct-converter v0.2.0-rc2 
h1:q+859fW2/jbHJHB2etbNfRlFwYpknyvbqqk1hUdamQ4=
 github.com/anchore/go-struct-converter v0.2.0-rc2/go.mod 
h1:cDBA5vhcR62nXWo8QH9/Kk2807o65ISaHPNPX66L+Uw=
-github.com/anchore/go-sync v0.1.1 
h1:91SZ+YqUIIHmf2jPAYZPuHqM/ZqnK1pVJDWtET6+AJE=
-github.com/anchore/go-sync v0.1.1/go.mod 
h1:3haGsk2BnaoVhsfqae8Kd0FKIAILE1Hw69P4Xo5iVBw=
+github.com/anchore/go-sync v0.1.2 
h1:RDD5RCanrWqhbtBulqPSZpERadUlgcYjpybYzYd3Uk8=
+github.com/anchore/go-sync v0.1.2/go.mod 
h1:grjZH059bCHM6f6jh+Y7VYvX/q8YcjkDJqG6nplHGkE=
 github.com/anchore/go-version v1.2.2-0.20210903204242-51efa5b487c4 
h1:rmZG77uXgE+o2gozGEBoUMpX27lsku+xrMwlmBZJtbg=
 github.com/anchore/go-version v1.2.2-0.20210903204242-51efa5b487c4/go.mod 
h1:Bkc+JYWjMCF8OyZ340IMSIi2Ebf3uwByOk6ho4wne1E=
 github.com/anchore/packageurl-go v0.2.0 
h1:CkrM4RMUwrEGAiE1OVlxaZNzWj0TuHRey7o4T/EAErk=
 github.com/anchore/packageurl-go v0.2.0/go.mod 
h1:2JCgOQMIsqZ7TmliXG4PnUthPJAKE3mWQbsW2XHjAOE=
-github.com/anchore/stereoscope v0.3.1 
h1:SFLeRyi+3L0fVDTcd4sjT6Xalvi9pju7DegeUMmxna8=
-github.com/anchore/stereoscope v0.3.1/go.mod 
h1:KHLeUz03/lpsxM8jvs7gFSWRHCXB9MLnxpusCIPe3ME=
-github.com/anchore/syft v1.51.1 h1:H/a0/Cw5Y3Nsa8/XFupCMcrLsF/5KnMYw/gzGVPRgmM=
-github.com/anchore/syft v1.51.1/go.mod 
h1:pv0fzHqh1+8hKecHHE68KXiGiZQ0i/UHyH3+4lZ+vPU=
+github.com/anchore/stereoscope v0.3.2 
h1:A2FDMSU56m3rErO1e0CtWAVcDS8tc2iX4UXTw1hyPnI=
+github.com/anchore/stereoscope v0.3.2/go.mod 
h1:/IUDVDka+4gufc8kDw+JO3gFl9PkpCjJ2r3bd9UWouM=
+github.com/anchore/syft v1.52.0 h1:BelCbd0Q3grSbtoLgNJ0cx/r/Gd1Jj7t11dp91eXd1Y=
+github.com/anchore/syft v1.52.0/go.mod 
h1:N9d70RgFm2/yVtA/EZTaeKQ/qw9oOrmfRXnFy/QV+VE=
 github.com/andreyvit/diff v0.0.0-20170406064948-c7f18ee00883/go.mod 
h1:rCTlJbsFo29Kk6CurOXKm700vrz8f0KW0JNfpkRJY/8=
 github.com/andybalholm/brotli v1.2.0 
h1:ukwgCxwYrmACq68yiUqwIWnGY0cTPox/M94sVwToPjQ=
 github.com/andybalholm/brotli v1.2.0/go.mod 
h1:rzTDkvFWvIrjDXZHkuS16NPggd91W3kUSvPlQ1pLaKY=
@@ -179,42 +179,42 @@
 github.com/armon/go-socks5 v0.0.0-20160902184237-e75332964ef5/go.mod 
h1:wHh0iHkYZB8zMSxRWpUBQtwG5a7fFgvEO+odwuTv2gs=
 github.com/atotto/clipboard v0.1.4 
h1:EH0zSVneZPSuFR11BlR9YppQTVDbh5+16AmcJi4g1z4=
 github.com/atotto/clipboard v0.1.4/go.mod 
h1:ZY9tmq7sm5xIbd9bOK4onWV4S6X0u6GY7Vn0Yu86PYI=
-github.com/aws/aws-sdk-go-v2 v1.43.4 
h1:b9FTvbRwy+JCsfp2Wp6wV/KbOx3Aj7nkoFb2cRX0IhE=
-github.com/aws/aws-sdk-go-v2 v1.43.4/go.mod 
h1:70vwSy16txshwG+g55WkpgPKDIByzHI8ccBsOteo3bQ=
-github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.16 
h1:aiuaKlDweRC5qExJondpWjOgyzMHpofpwspGXUtwn4c=
-github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.16/go.mod 
h1:nG/LOlmox9BDe9HvQnXWzgcK8uKbgBMZ/Hp5pVt/21I=
-github.com/aws/aws-sdk-go-v2/config v1.32.35 
h1:UEzXuET8E42lxBPijuACu/tEK7v5lFPlk0Q+GT5WD9E=
-github.com/aws/aws-sdk-go-v2/config v1.32.35/go.mod 
h1:KaMtJpFa2JlL2BStjjHQVwQpzZEmw+ND/EgVrfFoo2g=
-github.com/aws/aws-sdk-go-v2/credentials v1.19.34 
h1:y6GkSmcv5myd1ngrYbGmiLlwQqB6TQhOuN/tbSSuWDY=
-github.com/aws/aws-sdk-go-v2/credentials v1.19.34/go.mod 
h1:w3dTcnDVoQIewjo7JG45hduAToikiIFLC4FIO7fndvw=
-github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.35 
h1:+S7kbJoLDDQ5tE+lHrUBgMkzC8NLgsaioS2F3dVoFAE=
-github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.35/go.mod 
h1:Ak7xXviIARfFdNUJ9Etb0bdVDt/KAvKjMGJVLWXDzik=
-github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.35 
h1:kzVuGlatQtYinwBJEEyLAbggepCoavosiaHHX9+fD+c=
-github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.35/go.mod 
h1:0yLx0yEI+SfqeJMPvOtIEFoZbiQYXMGszBueiutQyaI=
-github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.35 
h1:WK6CjihTuLisCjSKKbildJ79sGZZgbBz3iNa7VsKIhU=
-github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.35/go.mod 
h1:KYleN57luLoe97R7vTnx8PMcVrr9gAcRECtOjl91DNg=
-github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.36 
h1:jbGY4CXLzZElOXgGsexlC3Hi+3YM0rSmk4opFXKqg/k=
-github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.36/go.mod 
h1:uBu/9aKsS/UQGc72RAt3y54kjgYQxmhut8ZD2dXCDNE=
-github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.15 
h1:JJLBQxwY+AFwuPAi5ivGc1ChnTdUt4cXMv7e76m2c/Y=
-github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.15/go.mod 
h1:lQknBIe78MVL0cQOQDlag8KGflMbMEVFx9mB6O8ENvk=
-github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.28 
h1:Q1TF1J9jVD+vFo0LzNnmNdQ9EAt52TS+MQlq9Ir+Yxo=
-github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.28/go.mod 
h1:4KqXXC/p1hrotmouDFbrRoWaLy962b9PMUReCG6+uWo=
-github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.35 
h1:BBEElKh4a+rKshvjrfpajTe9CbpZvrbb4Jkg2PB7RzA=
-github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.35/go.mod 
h1:zaZk983w//8beSruBVec/mr4CmDwgZitW/qzGhAAX0g=
-github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.36 
h1:EUIwBoN+q7UmhAejxgD27APiRjh1vwCFo53gSqdT0BM=
-github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.36/go.mod 
h1:6u00gmlTGR6W0b2k9NBrld7MnOEmf1Spqx0VVt6AqyE=
-github.com/aws/aws-sdk-go-v2/service/s3 v1.106.5 
h1:HpN6GgZ3T8pSvRp81ZsgumNjlvRsa+9M0ZL2o6W4uLY=
-github.com/aws/aws-sdk-go-v2/service/s3 v1.106.5/go.mod 
h1:5FTZoQxhmLEiCAtYVk6V+t0iS/B5yGZVLZ3Wq5FDJZI=
-github.com/aws/aws-sdk-go-v2/service/signin v1.5.4 
h1:cOJELVNrq5Q3Udry2GLuHUM7MhwpeaQRdYaoa6GI/yI=
-github.com/aws/aws-sdk-go-v2/service/signin v1.5.4/go.mod 
h1:f4LxzKBtaTxD7xh3PiVg3CE1tchQemfmghaJr+NbK2c=
-github.com/aws/aws-sdk-go-v2/service/sso v1.33.4 
h1:AMW7a7S8iQaHjBYZdU3PCq4GKRPijTPRAc7e6XtEThY=
-github.com/aws/aws-sdk-go-v2/service/sso v1.33.4/go.mod 
h1:QQNsFV1DVXoXcZt18FS8lI8rtUrlDyAuWZLQ5shunv4=
-github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.4 
h1:AsbZcJAQPRmHDJG8K1N0pof/1zPWjVT8TFlTWuGLSvo=
-github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.4/go.mod 
h1:6imqztH0//t0mKbl6yWl7swSEl7F/w32oAmqB3vP1ag=
-github.com/aws/aws-sdk-go-v2/service/sts v1.45.4 
h1:w/AryDYMjSUANSQ2uoZxJovUsMTwWJNTv3IMex30Y+4=
-github.com/aws/aws-sdk-go-v2/service/sts v1.45.4/go.mod 
h1:WeBiAa67azG7Su9Vf+ChGDBLiAozJCXzdjXiPBUwtbc=
-github.com/aws/smithy-go v1.27.6 
h1:0zjT8jgK3jbrTT7JJ3EE6JsMhX8JTrZ+f1sEndYDXrA=
-github.com/aws/smithy-go v1.27.6/go.mod 
h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc=
+github.com/aws/aws-sdk-go-v2 v1.44.0 
h1:4IbaHhtzy+4h37z4JQyO9a2QsiCml3CNYHtq5hIHigo=
+github.com/aws/aws-sdk-go-v2 v1.44.0/go.mod 
h1:bttEH6JqnUL8LepvDVfdrds/fZ5bCIxzpe3abyUrhDU=
+github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.20 
h1:GPRlPwz40I2B2VrBEASOA3Bi77NyeqejNLkifosX0rs=
+github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.20/go.mod 
h1:g7PNzKcsOKWb4fkSRBA7BZVAS6Y8IcxzN+nRohhQ1Q8=
+github.com/aws/aws-sdk-go-v2/config v1.32.40 
h1:lAVC9gMmKusmqDRe32dPtgKl/BWvJmMJoWELKHCAObw=
+github.com/aws/aws-sdk-go-v2/config v1.32.40/go.mod 
h1:8xOJLbe/hOj1g4PVsfJYV7O2byq+UGET1onDdUgbwqc=
+github.com/aws/aws-sdk-go-v2/credentials v1.19.39 
h1:XOg8LC3Kgnsa3WiPQjc7Bi8k5IBN92cPYfIV9XMFss0=
+github.com/aws/aws-sdk-go-v2/credentials v1.19.39/go.mod 
h1:GonTDBQ+mTpCVNwaHjj0PagspfrYYMEqOx7FehoEP/I=
+github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.40 
h1:r5aGipEVgI9aT/tAGjdrPbDQvIAKdTrS3rUPQtG4Rmo=
+github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.40/go.mod 
h1:vOD3CnPxAdkL6MWZeROkZsTlskklMFfgVFkHzx/oZpY=
+github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.40 
h1:UIXlbijuB2XK1Kr57fo8iIxCuaSHJzwZ1uo+2tbEYIk=
+github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.40/go.mod 
h1:wcEsL6jscjZjVUinb0Q5qD/GXOG1yT3GNfmT9HuDwzU=
+github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.40 
h1:xLQVRDs2NddDmK9BEyh5KSlJ1Gpy5/GIJXrV6WcVGAE=
+github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.40/go.mod 
h1:XRXnpFVFGLaEVK+olDdFIM1vNa04ETW452oFGEPUxAo=
+github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.41 
h1:nv/ILuCY0yXACzMQwvtt/HbqDDjemZiI0AeDbxGQlnU=
+github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.41/go.mod 
h1:dzvOSpxaPqQ3j0xS6Lc1vyVuWW0RBj7s/QqYpzu3Q/0=
+github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.19 
h1:bAdDl/HkGCcGPoe25ToSHEw23VIxt6CT5fLcg111BKg=
+github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.19/go.mod 
h1:KaUzbLxv4CeSxh6ZCl9B4m7CuFenS8kUEaDs+f/DQr4=
+github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.10.0 
h1:U8/A0RRBaEspzH1uul3JHLbypXwEGUkRkvoT9f0ATcM=
+github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.10.0/go.mod 
h1:UELStX5KwtJNtQxa+UuF8dc3z4UYc40e8yHYJSozNwY=
+github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.40 
h1:gr3Fw1cxZXNCdeo/lQ7isHEHzvHVM7z75qb2zW9aMjw=
+github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.40/go.mod 
h1:8z/9CmfnQhiuXD7Ykbcg4a/whSWsniE0ODSx9uwVzfk=
+github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.41 
h1:Q9DIKDuJix/oJnQxFpQ26L0EwVa/YNo4k2kbktrjQjE=
+github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.41/go.mod 
h1:x+TuqkOIG1SZS0+yN54sExGA9ZpjhPO6vPdYnpTFX1M=
+github.com/aws/aws-sdk-go-v2/service/s3 v1.108.0 
h1:Yp+x5PKXEmoqHsgP/pAkBy5Tyq1UlXAzM0OInh0vxWw=
+github.com/aws/aws-sdk-go-v2/service/s3 v1.108.0/go.mod 
h1:locV6DtXyp7Xzr2BG6jtsbeBi3YAWJ/CY4xUThYmIwQ=
+github.com/aws/aws-sdk-go-v2/service/signin v1.6.0 
h1:agcr0j8YeFEzdXNo17Rg9MbbjLRjrimabwNtji4e+lU=
+github.com/aws/aws-sdk-go-v2/service/signin v1.6.0/go.mod 
h1:qU5PxgQ4JiUOOMotzfO3+5oUda5W+8JDVKyLQqlrJik=
+github.com/aws/aws-sdk-go-v2/service/sso v1.34.0 
h1:FxaN8/sn61DTXNI6Gt678tFJUY8iUsCchm6Y/F/RjaA=
+github.com/aws/aws-sdk-go-v2/service/sso v1.34.0/go.mod 
h1:vu4OY6s8LJtT8BtYG2LD6BGSZMptkYn3o5hvCPB22jc=
+github.com/aws/aws-sdk-go-v2/service/ssooidc v1.39.0 
h1:crWKPeGYTBTuBxQ3p73kjfJvt4brUIsr+Fuypko8FxY=
+github.com/aws/aws-sdk-go-v2/service/ssooidc v1.39.0/go.mod 
h1:HjjZVhaBz0JBR/kbWKThmNDhFKS7y6EURuk493tJk9Y=
+github.com/aws/aws-sdk-go-v2/service/sts v1.46.0 
h1:IZ63JdogSNNjex/jsODNv7jGDcO/xJYd9FsgyfCsp1g=
+github.com/aws/aws-sdk-go-v2/service/sts v1.46.0/go.mod 
h1:I+rwAf3spG5dITBaAo3xXRowk8kiOhtU1kYxfvCTC44=
+github.com/aws/smithy-go v1.28.1 
h1:R/nXH00c8qcfCzQVELtRw+eLQWtzv+VAIEFJ1/xxXlQ=
+github.com/aws/smithy-go v1.28.1/go.mod 
h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc=
 github.com/aymanbagabas/go-osc52/v2 v2.0.1 
h1:HwpRHbFMcZLEVr42D4p7XBqjyuxQH5SMiErDT4WkJ2k=
 github.com/aymanbagabas/go-osc52/v2 v2.0.1/go.mod 
h1:uYgXzlJ7ZpABp8OJ+exZzJJhRNQ2ASbcXHWsFqH8hp8=
 github.com/bahlo/generic-list-go v0.2.0 
h1:5sz/EEAK+ls5wF+NeqDpk5+iNdMDXrh3z3nPnH1Wvgk=
@@ -304,8 +304,8 @@
 github.com/containerd/cgroups/v3 v3.1.3/go.mod 
h1:PKZ2AcWmSBsY/tJUVhtS/rluX0b1uq1GmPO1ElCmbOw=
 github.com/containerd/containerd/api v1.11.1 
h1:h8nfoDW9+fNsC/9TwiAHj8B1GzXKtR4eFtkhi/X5RLU=
 github.com/containerd/containerd/api v1.11.1/go.mod 
h1:CaQFRu+N1MtbgL6JDOJLUB1hCKESU1lD6MuTJhgtdlw=
-github.com/containerd/containerd/v2 v2.3.4 
h1:c2PJo/9UGVdiiw8SwrxuLxWGY+9b3jQ6Xp9zntneIvI=
-github.com/containerd/containerd/v2 v2.3.4/go.mod 
h1:a30D8fWZJ1Uzx/2WpjLbLsxBkq9He41pe8ENW+QZ3LY=
+github.com/containerd/containerd/v2 v2.3.5 
h1:9MYlI81gUcOZ0WsCkSMtvOU7rTR3hqAoa2eCzhoLlkA=
+github.com/containerd/containerd/v2 v2.3.5/go.mod 
h1:RXDyLPaI3zoO7dFdAW9/54W4cix+z3A6larieufC9mg=
 github.com/containerd/continuity v0.5.0 
h1:7a85HZpCSs+1Zps0Ee3DPSuAWY+0SJM1JNM51nlEVDg=
 github.com/containerd/continuity v0.5.0/go.mod 
h1:/lNJvtJKUQStBzpVQ1+rasXO1LAWtUQssk28EZvJ3nE=
 github.com/containerd/errdefs v1.0.0 
h1:tg5yIfIlQIrxYtu9ajqY42W3lpS19XqdxRQeEwYG8PI=
@@ -348,8 +348,8 @@
 github.com/djherbis/times v1.6.0/go.mod 
h1:gOHeRAz2h+VJNZ5Gmc/o7iD9k4wW7NMVqieYCY99oc0=
 github.com/dlclark/regexp2 v1.11.0 
h1:G/nrcoOa7ZXlpoa/91N3X7mM3r8eIlMBBJZvsz/mxKI=
 github.com/dlclark/regexp2 v1.11.0/go.mod 
h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8=
-github.com/docker/cli v29.7.2+incompatible 
h1:dlkwallR8XqfeVnA2ELEhdwvb4lsSwuB4IgsG8Q9cLY=
-github.com/docker/cli v29.7.2+incompatible/go.mod 
h1:JLrzqnKDaYBop7H2jaqPtU4hHvMKP+vjCwu2uszcLI8=
+github.com/docker/cli v29.8.0+incompatible 
h1:ih0c2jq/nN7QfES8zIfwSzIhRScjs4ehER+kZ60aeSk=
+github.com/docker/cli v29.8.0+incompatible/go.mod 
h1:JLrzqnKDaYBop7H2jaqPtU4hHvMKP+vjCwu2uszcLI8=
 github.com/docker/docker v28.5.2+incompatible 
h1:DBX0Y0zAjZbSrm1uzOkdr1onVghKaftjlSWt4AFexzM=
 github.com/docker/docker v28.5.2+incompatible/go.mod 
h1:eEKB0N0r5NX/I1kEveEz05bcu8tLC/8azJZsviup8Sk=
 github.com/docker/docker-credential-helpers v0.9.5 
h1:EFNN8DHvaiK8zVqFA2DT6BjXE0GzfLOZ38ggPTKePkY=
@@ -525,8 +525,8 @@
 github.com/google/go-cmp v0.5.9/go.mod 
h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeNGIjoY=
 github.com/google/go-cmp v0.7.0 h1:wk8382ETsv4JYUZwIsn6YpYiWiBsYLSJiTsyBybVuN8=
 github.com/google/go-cmp v0.7.0/go.mod 
h1:pXiqmnSA92OHEEa9HXL2W4E7lf9JzCmGVUdgjX3N/iU=
-github.com/google/go-containerregistry v0.21.9 
h1:F+D4uZ3iA3DLMJLfhaqMdHJbzeqm/216WGQq2dokuLs=
-github.com/google/go-containerregistry v0.21.9/go.mod 
h1:dP5XNKcL7kMFF/TB3LfvWmVhAcv7iqkHb3oDK8aauTo=
+github.com/google/go-containerregistry v0.22.1 
h1:RZuuSYhTvlDvtsK+NkutoCZ//C0X2ebLK8X8l3ULs84=
+github.com/google/go-containerregistry v0.22.1/go.mod 
h1:bJR35SK8XgisYmhg/FMQ/5RK0S/XrOAqLBV5/LR2XE0=
 github.com/google/gofuzz v1.0.0/go.mod 
h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg=
 github.com/google/licensecheck v0.3.1 
h1:QoxgoDkaeC4nFrtGN1jV7IPmDCHFNIVh54e5hSt6sPs=
 github.com/google/licensecheck v0.3.1/go.mod 
h1:ORkR35t/JjW+emNKtfJDII0zlciG9JgbT7SmsohlHmY=
@@ -563,21 +563,21 @@
 github.com/google/uuid v1.1.2/go.mod 
h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
 github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0=
 github.com/google/uuid v1.6.0/go.mod 
h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo=
-github.com/googleapis/enterprise-certificate-proxy v0.3.19 
h1:mMOE7DN2+p76/EdIrmAy9B9bH+yC4563vmnJ34QR8i4=
-github.com/googleapis/enterprise-certificate-proxy v0.3.19/go.mod 
h1:rSEsBUemEBZEexP2y6jPp16LUmUbjmSbcPMQizR0o4k=
+github.com/googleapis/enterprise-certificate-proxy v0.3.20 
h1:t/xL64VUoN69MuMRQuJETqYGOw4Z9mSRJK9epIEtwFk=
+github.com/googleapis/enterprise-certificate-proxy v0.3.20/go.mod 
h1:L3D/IQExI6LqEjBdXcZQ1WluSgigQmSwBboFstVPM4w=
 github.com/googleapis/gax-go/v2 v2.0.4/go.mod 
h1:0Wqv26UfaUD9n4G6kQubkQ+KchISgw+vpHVxEJEs9eg=
 github.com/googleapis/gax-go/v2 v2.0.5/go.mod 
h1:DWXyrwAJ9X0FpwwEdw+IPEYBICEFu5mhpdKc/us6bOk=
 github.com/googleapis/gax-go/v2 v2.1.0/go.mod 
h1:Q3nei7sK6ybPYH7twZdmQpAd1MKb7pfu6SK+H1/DsU0=
 github.com/googleapis/gax-go/v2 v2.1.1/go.mod 
h1:hddJymUZASv3XPyGkUpKj8pPO47Rmb0eJc8R6ouapiM=
-github.com/googleapis/gax-go/v2 v2.23.0 
h1:Tchl7qkvE7Ip3y+ztvNufYFvkfqTe7NfLTYGIdJRLuE=
-github.com/googleapis/gax-go/v2 v2.23.0/go.mod 
h1:rBQKOVJCdb8IFEzg+FCwlt1LP/xMDGuqUXhUG+XMXEg=
+github.com/googleapis/gax-go/v2 v2.24.0 
h1:myMaPYyF9MecEmvQqMqomIwn9t/4KCZN9qnwsS76wlg=
+github.com/googleapis/gax-go/v2 v2.24.0/go.mod 
h1:IaTHBDd7NHxSCiu0vEs8pQZu4dGZrWwuSoxCnk16OFM=
 github.com/gookit/assert v0.1.1 h1:lh3GcawXe/p+cU7ESTZ5Ui3Sm/x8JWpIis4/1aF0mY0=
 github.com/gookit/assert v0.1.1/go.mod 
h1:jS5bmIVQZTIwk42uXl4lyj4iaaxx32tqH16CFj0VX2E=
 github.com/gookit/color v1.2.5/go.mod 
h1:AhIE+pS6D4Ql0SQWbBeXPHw7gY0/sjHoA4s/n1KB7xg=
 github.com/gookit/color v1.6.1 h1:KoTnDxJPRgrL0SoX0f8rCFg2zI0t4E3GZZBMo2nN8LU=
 github.com/gookit/color v1.6.1/go.mod 
h1:9ACFc7/1IpHGBW8RwuDm/0YEnhg3dwwXpoMsmtyHfjs=
-github.com/gpustack/gguf-parser-go v0.25.0 
h1:1AMBhMKtI24nTtn588Bq53FqNiOvEw1x9Nb4HbRrThs=
-github.com/gpustack/gguf-parser-go v0.25.0/go.mod 
h1:y4TwTtDqFWTK+xvprOjRUh+dowgU2TKCX37vRKvGiZ0=
+github.com/gpustack/gguf-parser-go v0.26.3 
h1:F63PlUPIW56HGU5k4Crv0JAG9ojtz/TuwzgMYlb82Ec=
+github.com/gpustack/gguf-parser-go v0.26.3/go.mod 
h1:y4TwTtDqFWTK+xvprOjRUh+dowgU2TKCX37vRKvGiZ0=
 github.com/grpc-ecosystem/grpc-gateway v1.16.0 
h1:gmcG1KaJ57LophUzW0Hy8NmPhnMZb4M0+kPpLofRdBo=
 github.com/grpc-ecosystem/grpc-gateway v1.16.0/go.mod 
h1:BDjrQk3hbvj6Nolgz8mAMFbcEtjT1g+wF4CSlocrBnw=
 github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 
h1:HWRh5R2+9EifMyIHV7ZV+MIZqgz+PMpZ14Jynv3O2Zs=
@@ -595,8 +595,8 @@
 github.com/hashicorp/go-cleanhttp v0.5.1/go.mod 
h1:JpRdi6/HCYpAwUzNwuwqhbovhLtngrth3wmdIIUrZ80=
 github.com/hashicorp/go-cleanhttp v0.5.2 
h1:035FKYIWjmULyFRBKPs8TBQoi0x6d9G4xc9neXJWAZQ=
 github.com/hashicorp/go-cleanhttp v0.5.2/go.mod 
h1:kO/YDlP8L1346E6Sodw+PrpBSV4/SoxCXGY6BqNFT48=
-github.com/hashicorp/go-getter v1.8.8 
h1:sRakhf+EH6s0LZLO2IgBwZ6hAFp+fZOZMNREwVELV80=
-github.com/hashicorp/go-getter v1.8.8/go.mod 
h1:fqFlibKpwfns/s4oljLB3upJspyfFLQhS7031PlfUDc=
+github.com/hashicorp/go-getter v1.8.9 
h1:1AOTMUmz/S/GuqOTE6+bg6nwPXTEbKr3Tc/T/lVS7is=
+github.com/hashicorp/go-getter v1.8.9/go.mod 
h1:qI7vH/m552bXutKe4UkWptOJl4bo2KeO/CSOoh4s0ps=
 github.com/hashicorp/go-hclog v0.12.0/go.mod 
h1:whpDNt7SSdeAju8AWKIWsul05p54N/39EeqMAyrmvFQ=
 github.com/hashicorp/go-hclog v1.0.0/go.mod 
h1:whpDNt7SSdeAju8AWKIWsul05p54N/39EeqMAyrmvFQ=
 github.com/hashicorp/go-immutable-radix v1.0.0/go.mod 
h1:0y9vanUI8NX6FsYoO3zeMjhV/C5i9g4Q3DwcSNZ4P60=
@@ -672,8 +672,8 @@
 github.com/kisielk/errcheck v1.5.0/go.mod 
h1:pFxgyoBC7bSaBwPgfKdkLd5X25qrDl4LWUI2bnpBCr8=
 github.com/kisielk/gotool v1.0.0/go.mod 
h1:XhKaO+MFFWcvkIS/tQcRk01m1F5IRFswLeQ+oQHNcck=
 github.com/klauspost/compress v1.4.1/go.mod 
h1:RyIbtBH6LamlWaDj8nUwkbUhJ87Yi3uG0guNDohfE1A=
-github.com/klauspost/compress v1.19.2 
h1:hMRETovs/pu/dVWN7zIT1PGG8t509MwT6bO7XSi26R8=
-github.com/klauspost/compress v1.19.2/go.mod 
h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ=
+github.com/klauspost/compress v1.20.0 
h1:a3C1ke2ohxFymNlb2HWAHjDeKCI90scRskErZkR0ezA=
+github.com/klauspost/compress v1.20.0/go.mod 
h1:LUdAzn7YLVvxLpc7y3V1m40wESHTgc1422pwwBSKYuI=
 github.com/klauspost/cpuid v1.2.0/go.mod 
h1:Pj4uuM528wm8OyEC2QMXAi2YiTZ96dNQPGgoMS4s3ek=
 github.com/klauspost/cpuid/v2 v2.3.0 
h1:S4CRMLnYUhGeDFDqkGriYKdfoFlDnMtqTiI/sFzhA9Y=
 github.com/klauspost/cpuid/v2 v2.3.0/go.mod 
h1:hqwkgyIinND0mEev00jJYCxPNVRVXFQeu1XKlok6oO0=
@@ -757,10 +757,10 @@
 github.com/moby/docker-image-spec v1.3.1/go.mod 
h1:eKmb5VW8vQEh/BAr2yvVNvuiJuY6UIocYsFu/DxxRpo=
 github.com/moby/locker v1.0.1 h1:fOXqR41zeveg4fFODix+1Ch4mj/gT0NE1XJbp/epuBg=
 github.com/moby/locker v1.0.1/go.mod 
h1:S7SDdo5zpBK84bzzVlKr2V0hz+7x9hWbYC/kq7oQppc=
-github.com/moby/moby/api v1.55.0 
h1:2/sexvQyqIWS8pRSCFddBfpW2qE7vR7FCL+vN8pxwMc=
-github.com/moby/moby/api v1.55.0/go.mod 
h1:+RQ6wluLwtYaTd1WnPLykIDPekkuyD/ROWQClE83pzs=
-github.com/moby/moby/client v0.5.1 
h1:tYNaJno4c0HXz12y5BiqEDy0rVTYkWzI26lGvnTMiJw=
-github.com/moby/moby/client v0.5.1/go.mod 
h1:odLstlZ6uSnfvAgVxMpvgmb8SUdd+siH2T0GBuxVAlM=
+github.com/moby/moby/api v1.56.0 
h1:GQzua3NA599ASSIICx0iFgiJeO9YkdDARvQsm23ZZuQ=
+github.com/moby/moby/api v1.56.0/go.mod 
h1:sZ+THbVWkjOmBPPfbnzdD/G1LuIexWhqlSHHPTDQ1Uk=
+github.com/moby/moby/client v0.6.0 
h1:AJjEB21QPbXSXjDsZorFBoDZPhMrfbpaPLgSMAW9Bgs=
+github.com/moby/moby/client v0.6.0/go.mod 
h1:OCo00wNRyA3m4lmJ228W3JbyCN4ZNNYjpOXiJydBdcQ=
 github.com/moby/sys/atomicwriter v0.1.0 
h1:kw5D/EqkBwsBFi0ss9v1VG3wIkVhzGvLklJ+w3A14Sw=
 github.com/moby/sys/atomicwriter v0.1.0/go.mod 
h1:Ul8oqv2ZMNHOceF643P6FKPXeCmYtlQMvpizfsSoaWs=
 github.com/moby/sys/mountinfo v0.7.2 
h1:1shs6aH5s4o5H2zQLn796ADW1wMrIwHsyJ2v9KouLrg=
@@ -823,8 +823,8 @@
 github.com/owenrumney/go-sarif v1.1.2-0.20231003122901-1000f5e05554/go.mod 
h1:n73K/hcuJ50MiVznXyN4rde6fZY7naGKWBXOLFTyc94=
 github.com/package-url/packageurl-go v0.1.5 
h1:O4efRXja2XQ5CtiiYiCZ22k/m7i5ugLiAghgcC+eDgk=
 github.com/package-url/packageurl-go v0.1.5/go.mod 
h1:nKAWB8E6uk1MHqiS/lQb9pYBGH2+mdJ2PJc2s50dQY0=
-github.com/pandatix/go-cvss v0.6.2 
h1:TFiHlzUkT67s6UkelHmK6s1INKVUG7nlKYiWWDTITGI=
-github.com/pandatix/go-cvss v0.6.2/go.mod 
h1:jDXYlQBZrc8nvrMUVVvTG8PhmuShOnKrxP53nOFkt8Q=
+github.com/pandatix/go-cvss v0.6.4 
h1:9w2RCO/Q4UTiJyEgpCHRiVc6CfrsFEnkoX+OtATqKio=
+github.com/pandatix/go-cvss v0.6.4/go.mod 
h1:/ukvQnYlrKl3o/DVp7/GO2UZyZheuo/maOK0U1nBEhQ=
 github.com/pascaldekloe/goe v0.0.0-20180627143212-57f6aae5913c/go.mod 
h1:lzWF7FIEvWOWxwDKqyGYQf6ZUaNfKdP144TG7ZOy1lc=
 github.com/pascaldekloe/goe v0.1.0/go.mod 
h1:lzWF7FIEvWOWxwDKqyGYQf6ZUaNfKdP144TG7ZOy1lc=
 github.com/pb33f/ordered-map/v2 v2.3.1 
h1:5319HDO0aw4DA4gzi+zv4FXU9UlSs3xGZ40wcP1nBjY=
@@ -981,8 +981,8 @@
 github.com/sylabs/squashfs v1.0.6/go.mod 
h1:DlDeUawVXLWAsSRa085Eo0ZenGzAB32JdAUFaB0LZfE=
 github.com/tailscale/hujson v0.0.0-20260302212456-ecc657c15afd 
h1:Rf9uhF1+VJ7ZHqxrG8pJ6YacmHvVCmByDmGbAWCc/gA=
 github.com/tailscale/hujson v0.0.0-20260302212456-ecc657c15afd/go.mod 
h1:EbW0wDK/qEUYI0A5bqq0C2kF8JTQwWONmGDBbzsxxHo=
-github.com/terminalstatic/go-xsd-validate v0.1.6 
h1:TenYeQ3eY631qNi1/cTmLH/s2slHPRKTTHT+XSHkepo=
-github.com/terminalstatic/go-xsd-validate v0.1.6/go.mod 
h1:18lsvYFofBflqCrvo1umpABZ99+GneNTw2kEEc8UPJw=
+github.com/terminalstatic/go-xsd-validate v0.1.8 
h1:UVrTCy1j3DhwaYTTUF+QYO/Nan13S0tf+Jwi+p45Bf0=
+github.com/terminalstatic/go-xsd-validate v0.1.8/go.mod 
h1:1kb47fi2c6onlf+B7UrrQ9VYraOhcYwFm3iG+J6F4Zo=
 github.com/therootcompany/xz v1.0.1 
h1:CmOtsn1CbtmyYiusbfmhmkpAAETj0wBIH6kCYaX+xzw=
 github.com/therootcompany/xz v1.0.1/go.mod 
h1:3K3UH1yCKgBneZYhuQUvJ9HPD19UEXEI0BWbMn8qNMY=
 github.com/tidwall/gjson v1.14.2/go.mod 
h1:/wbyibRr2FHMks5tjHJ5F8dMZh3AcwJEMf5vlfC0lxk=
@@ -1107,8 +1107,8 @@
 golang.org/x/crypto v0.0.0-20210817164053-32db794688a5/go.mod 
h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc=
 golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod 
h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc=
 golang.org/x/crypto v0.0.0-20220622213112-05595931fe9d/go.mod 
h1:IxCIyHEi3zRg3s0A5j5BB6A9Jmi73HwBIUl50j+osU4=
-golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M=
-golang.org/x/crypto v0.55.0/go.mod 
h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis=
+golang.org/x/crypto v0.56.0 h1:GUh5Ii4J5jtcseSMiRqr1jXCNHoxjeV9Fmekc2oLy6Y=
+golang.org/x/crypto v0.56.0/go.mod 
h1:OMW5y6CY9l38uPLmxU6l6pwcXp1obtLo3e6gT7gQR2I=
 golang.org/x/exp v0.0.0-20190121172915-509febef88a4/go.mod 
h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA=
 golang.org/x/exp v0.0.0-20190306152737-a1d7652674e8/go.mod 
h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA=
 golang.org/x/exp v0.0.0-20190510132918-efd6b22b2522/go.mod 
h1:ZjyILWgesfNpC6sMxTJOJm9Kp84zZh5NQWvqDGG3Qr8=
@@ -1149,8 +1149,8 @@
 golang.org/x/mod v0.5.0/go.mod h1:5OXOZSfqPIIbmVBIIKWRFfZjPR0E5r58TLhUjH0a2Ro=
 golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod 
h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4=
 golang.org/x/mod v0.8.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs=
-golang.org/x/mod v0.40.0 h1:hUv+3cXcdRHz08UmSiOob7sadHig73uo5bkXxQ/tvUs=
-golang.org/x/mod v0.40.0/go.mod h1:0/weTWkPWGBikyTWAX3dkjVztMmBA5hM0DH6BElSupE=
+golang.org/x/mod v0.41.0 h1:qJmnOUb4YB+FsEuM3HcWucdZASCPGhsX6uljO6pog0c=
+golang.org/x/mod v0.41.0/go.mod h1:Ek9pY8RKWXwsWvd3rQiHYtMqkjSUV+s1Rj7j4H5Ur6o=
 golang.org/x/net v0.0.0-20180724234803-3673e40ba225/go.mod 
h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
 golang.org/x/net v0.0.0-20180826012351-8a410e7b638d/go.mod 
h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
 golang.org/x/net v0.0.0-20181023162649-9b4f9f5ad519/go.mod 
h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4=
@@ -1329,8 +1329,8 @@
 golang.org/x/time v0.0.0-20181108054448-85acf8d2951c/go.mod 
h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ=
 golang.org/x/time v0.0.0-20190308202827-9d24e82272b4/go.mod 
h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ=
 golang.org/x/time v0.0.0-20191024005414-555d28b269f0/go.mod 
h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ=
-golang.org/x/time v0.15.0 h1:bbrp8t3bGUeFOx08pvsMYRTCVSMk89u4tKbNOZbp88U=
-golang.org/x/time v0.15.0/go.mod 
h1:Y4YMaQmXwGQZoFaVFk4YpCt4FLQMYKZe9oeV/f4MSno=
+golang.org/x/time v0.16.0 h1:vMb6ptszcQMkcwiRTAuNNU50gom6++Q/6gY2hDM6VDE=
+golang.org/x/time v0.16.0/go.mod 
h1:rVKOqvZeKvrDKTQiAHJ7wmwP0RzleSphoEA9RcdLA0s=
 golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod 
h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
 golang.org/x/tools v0.0.0-20190114222345-bf090417da8b/go.mod 
h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ=
 golang.org/x/tools v0.0.0-20190226205152-f727befe758c/go.mod 
h1:9Yl7xja0Znq3iFh3HoIrodX9oNMXvdceNzlUR8zjMvY=
@@ -1429,8 +1429,8 @@
 google.golang.org/api v0.59.0/go.mod 
h1:sT2boj7M9YJxZzgeZqXogmhfmRWDtPzT31xkieUbuZU=
 google.golang.org/api v0.61.0/go.mod 
h1:xQRti5UdCmoCEqFxcz93fTl338AVqDgyaDRuOZ3hg9I=
 google.golang.org/api v0.62.0/go.mod 
h1:dKmwPCydfsad4qCH08MSdgWjfHOyfpd4VtDGgRFdavw=
-google.golang.org/api v0.292.0 h1:Ewiwo/GTtiaPZSNAZQUcWLh8AYDEoPmIXyJfeoTSMHU=
-google.golang.org/api v0.292.0/go.mod 
h1:07kjmMnFGm2RQuCza2EZM/5N68G/fVvFb1xKjWqoFA0=
+google.golang.org/api v0.294.0 h1:8gASjJxdtcIieB3OqbkLcF0FfbXVNqKtU5iozD1ssvA=
+google.golang.org/api v0.294.0/go.mod 
h1:02qB8+Ox1ZFzcaKFMguy1nQLJmSIyvV6Ff4txJEXtl4=
 google.golang.org/appengine v1.1.0/go.mod 
h1:EbEs0AVv82hx2wNQdGPgUI5lhzA/G0D9YwlJXL52JkM=
 google.golang.org/appengine v1.4.0/go.mod 
h1:xpcJRLb0r/rnEns0DIKYYv+WjYCduHsrkT7/EB5XEv4=
 google.golang.org/appengine v1.5.0/go.mod 
h1:xpcJRLb0r/rnEns0DIKYYv+WjYCduHsrkT7/EB5XEv4=
@@ -1501,12 +1501,12 @@
 google.golang.org/genproto v0.0.0-20211203200212-54befc351ae9/go.mod 
h1:5CzLGKJ67TSI2B9POpiiyGha0AjJvZIUgRMt1dSmuhc=
 google.golang.org/genproto v0.0.0-20211206160659-862468c7d6e0/go.mod 
h1:5CzLGKJ67TSI2B9POpiiyGha0AjJvZIUgRMt1dSmuhc=
 google.golang.org/genproto v0.0.0-20211208223120-3a66f561d7aa/go.mod 
h1:5CzLGKJ67TSI2B9POpiiyGha0AjJvZIUgRMt1dSmuhc=
-google.golang.org/genproto v0.0.0-20260519071638-aa98bba5eb94 
h1:YJjbgu+dkp5kUJLfpMyCLfBIWZb/FcJyuLeo1gVBOuo=
-google.golang.org/genproto v0.0.0-20260519071638-aa98bba5eb94/go.mod 
h1:RRHjglSYABVCWpQ7USCpdfhcd9t4PkajvVwyynZizTc=
-google.golang.org/genproto/googleapis/api v0.0.0-20260630182238-925bb5da69e7 
h1:jQ9p21COKWjP3VwuFrNRiiOTMh3mPpN45R7SLrH/HUU=
-google.golang.org/genproto/googleapis/api 
v0.0.0-20260630182238-925bb5da69e7/go.mod 
h1:KqHwBx2upmfa1XSi1WuRvC+2VGCLtooKkfmyvRbUmqA=
-google.golang.org/genproto/googleapis/rpc v0.0.0-20260803160001-6ac0973c030d 
h1:IL4hdHzcUv2l/gcg98/Rj3FbtE6axwqslOW8SW0C+S0=
-google.golang.org/genproto/googleapis/rpc 
v0.0.0-20260803160001-6ac0973c030d/go.mod 
h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8=
+google.golang.org/genproto v0.0.0-20260715232425-e75dac1f907d 
h1:C9v1o0/4quuhOAfmRXA2j+we0PqZIp8traLdeogF3Ms=
+google.golang.org/genproto v0.0.0-20260715232425-e75dac1f907d/go.mod 
h1:Wz2wFJntZFmLGo7pLDXZ3wYk5hyc0Mb+SkHhDDXT+lU=
+google.golang.org/genproto/googleapis/api v0.0.0-20260715232425-e75dac1f907d 
h1:QwnJwPte4XXAkhPu26LTDIahnsMSUV0kK8HkxbC+Pc4=
+google.golang.org/genproto/googleapis/api 
v0.0.0-20260715232425-e75dac1f907d/go.mod 
h1:WRrQ7/7N19PypuT0fxLOL5Lq0waoiRri4FbtHDEKrGE=
+google.golang.org/genproto/googleapis/rpc v0.0.0-20260819154853-08b0e4226688 
h1:cYNAzI2sUwhmCcoj9TxvihSrqsxt6uIkj3rDRhSDmW4=
+google.golang.org/genproto/googleapis/rpc 
v0.0.0-20260819154853-08b0e4226688/go.mod 
h1:DjtHYE8FKJLivXcBEjGwndXfIC23G0VpXiXKqG179uA=
 google.golang.org/grpc v1.19.0/go.mod 
h1:mqu4LbDTu4XGKhr4mRzUsmM4RtVoemTSY81AxZiDr8c=
 google.golang.org/grpc v1.20.1/go.mod 
h1:10oTOabMzJvdu6/UiuZezV6QK5dSlG84ov/aaiqXj38=
 google.golang.org/grpc v1.21.1/go.mod 
h1:oYelfM1adQP15Ek0mdvEgi9Df8B9CZIaU1084ijfRaM=
@@ -1534,8 +1534,8 @@
 google.golang.org/grpc v1.40.0/go.mod 
h1:ogyxbiOoUXAkP+4+xa6PZSE9DZgIHtSpzjDTB9KAK34=
 google.golang.org/grpc v1.40.1/go.mod 
h1:ogyxbiOoUXAkP+4+xa6PZSE9DZgIHtSpzjDTB9KAK34=
 google.golang.org/grpc v1.42.0/go.mod 
h1:k+4IHHFw41K8+bbowsex27ge2rCb65oeWqe4jJ590SU=
-google.golang.org/grpc v1.83.0 h1:JeNZEKJFbQxArAMl+hiytHauacDNqJUllNfmIMmpqnQ=
-google.golang.org/grpc v1.83.0/go.mod 
h1:kDyl6SKsiHKt0uylY5gtn5cEjkrIOhQOGDgIc4JGwzQ=
+google.golang.org/grpc v1.83.2 h1:EManeRomTObA0BU7I8vXgg/78uE5MJ9M8B39EX2WscU=
+google.golang.org/grpc v1.83.2/go.mod 
h1:YPI1hK3kDked6iHvgX3tR0y+nX/qpMFKhPgFsokw1S8=
 google.golang.org/grpc/cmd/protoc-gen-go-grpc v1.1.0/go.mod 
h1:6Kw0yEErY5E/yWrBtf03jp27GLLJujG4z/JK95pnjjw=
 google.golang.org/protobuf v0.0.0-20200109180630-ec00e32a8dfd/go.mod 
h1:DFci5gLYBciE7Vtevhsrf46CRTquxDuWsQurQQe4oz8=
 google.golang.org/protobuf v0.0.0-20200221191635-4d8936d0db64/go.mod 
h1:kwYJMbMJ01Woi6D6+Kah6886xMZcty6N08ah7+eCXa0=
@@ -1550,8 +1550,8 @@
 google.golang.org/protobuf v1.26.0-rc.1/go.mod 
h1:jlhhOSvTdKEhbULTjvd4ARK9grFBp09yW+WbY/TyQbw=
 google.golang.org/protobuf v1.26.0/go.mod 
h1:9q0QmTI4eRPtz6boOQmLYwt+qCgq0jsYwAQnmE0givc=
 google.golang.org/protobuf v1.27.1/go.mod 
h1:9q0QmTI4eRPtz6boOQmLYwt+qCgq0jsYwAQnmE0givc=
-google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af 
h1:+5/Sw3GsDNlEmu7TfklWKPdQ0Ykja5VEmq2i817+jbI=
-google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af/go.mod 
h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco=
+google.golang.org/protobuf v1.36.12 
h1:pJOKDDOyeXErUroCihFAd5LQuwXBSpVnKGrj5o/fwxc=
+google.golang.org/protobuf v1.36.12/go.mod 
h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco=
 gopkg.in/alecthomas/kingpin.v2 v2.2.6/go.mod 
h1:FMv+mEhP44yOT+4EoQTLFTRgOQ1FBLkstjWtayDeSgw=
 gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod 
h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
 gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127/go.mod 
h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0=
@@ -1589,30 +1589,30 @@
 honnef.co/go/tools v0.0.1-2020.1.4/go.mod 
h1:X/FiERA/W4tHapMX5mGpAtMSVEeEUOyHaw9vFzvIQ3k=
 howett.net/plist v1.0.1 h1:37GdZ8tP09Q35o9ych3ehygcsL+HqKSwzctveSlarvM=
 howett.net/plist v1.0.1/go.mod h1:lqaXoTrLY4hg8tnEzNru53gicrbv7rrk+2xJA/7hw9g=
-modernc.org/cc/v4 v4.29.1 h1:MKgdCV3WykTSPqpVrnxdEDS0HEd2FHpKZDzxzU5LyeI=
-modernc.org/cc/v4 v4.29.1/go.mod 
h1:OnovgIhbbMXMu1aISnJ0wvVD1KnW+cAUJkIrAWh+kVI=
-modernc.org/ccgo/v4 v4.34.6 h1:sBgfIwyN0TQ9C5hwIeuqyeAKyMWnbvj2fvpF4L11uzU=
-modernc.org/ccgo/v4 v4.34.6/go.mod 
h1:SZ8YcN9NG7XVsQYdm6jYBvi8PQP1qi+kqB6OhjqI3Fk=
+modernc.org/cc/v4 v4.29.2 h1:h6+9ciCnPKutf4I03CvheAvDLX7+IHlqR6Iy6J+cgd8=
+modernc.org/cc/v4 v4.29.2/go.mod 
h1:OnovgIhbbMXMu1aISnJ0wvVD1KnW+cAUJkIrAWh+kVI=
+modernc.org/ccgo/v4 v4.35.0 h1:F+TUsmw09QxLzmi3aeYYGxjAXarmZaKgj3mKQHNaA8w=
+modernc.org/ccgo/v4 v4.35.0/go.mod 
h1:qrVGs9S3Sr2Ztcg9ve+kTAYMp5a3YvWjo+SoN06kJ5I=
 modernc.org/fileutil v1.4.0 h1:j6ZzNTftVS054gi281TyLjHPp6CPHr2KCxEXjEbD6SM=
 modernc.org/fileutil v1.4.0/go.mod 
h1:EqdKFDxiByqxLk8ozOxObDSfcVOv/54xDs/DUHdvCUU=
 modernc.org/gc/v2 v2.6.5 h1:nyqdV8q46KvTpZlsw66kWqwXRHdjIlJOhG6kxiV/9xI=
 modernc.org/gc/v2 v2.6.5/go.mod h1:YgIahr1ypgfe7chRuJi2gD7DBQiKSLMPgBQe9oIiito=
-modernc.org/gc/v3 v3.1.4 h1:2g65LGVSmFQrXeITAw97x7hCRvZFcyE1uDP+7Vng7JI=
-modernc.org/gc/v3 v3.1.4/go.mod h1:HFK/6AGESC7Ex+EZJhJ2Gni6cTaYpSMmU/cT9RmlfYY=
+modernc.org/gc/v3 v3.1.5 h1:21ldfPfRYE31Tb7B3mwAK8gy1AxP4+dKjrOQPfqakoc=
+modernc.org/gc/v3 v3.1.5/go.mod h1:HFK/6AGESC7Ex+EZJhJ2Gni6cTaYpSMmU/cT9RmlfYY=
 modernc.org/goabi0 v0.2.0 h1:HvEowk7LxcPd0eq6mVOAEMai46V+i7Jrj13t4AzuNks=
 modernc.org/goabi0 v0.2.0/go.mod 
h1:CEFRnnJhKvWT1c1JTI3Avm+tgOWbkOu5oPA8eH8LnMI=
-modernc.org/libc v1.74.4 h1:fX1Omw4o2/1C2iRkkIsrQTasJQldLhRmuPreXLoWs9k=
-modernc.org/libc v1.74.4/go.mod h1:eeQAS9W3sZeKYMFubydxJpII9ybHWshk+7or7bLG9co=
+modernc.org/libc v1.75.6 h1:yKk8qo+Di4gkmvRboK8ocCqH22FiUCR6jRy2OwtCRus=
+modernc.org/libc v1.75.6/go.mod h1:bO5o2ztHxBb2rjz0PgdHN0sSMw57CgxGFLZ3Qd/QpVQ=
 modernc.org/mathutil v1.7.1 h1:GCZVGXdaN8gTqB1Mf/usp1Y/hSqgI2vAGGP4jZMCxOU=
 modernc.org/mathutil v1.7.1/go.mod 
h1:4p5IwJITfppl0G4sUEDtCr4DthTaT47/N3aT6MhfgJg=
-modernc.org/memory v1.11.0 h1:o4QC8aMQzmcwCK3t3Ux/ZHmwFPzE6hf2Y5LbkRs+hbI=
-modernc.org/memory v1.11.0/go.mod 
h1:/JP4VbVC+K5sU2wZi9bHoq2MAkCnrt2r98UGeSK7Mjw=
+modernc.org/memory v1.12.1 h1:nFMiWrpStgZczNl6XI9GnIk/rWhYIyHGUaR04pGbp9g=
+modernc.org/memory v1.12.1/go.mod 
h1:/JP4VbVC+K5sU2wZi9bHoq2MAkCnrt2r98UGeSK7Mjw=
 modernc.org/opt v0.2.0 h1:tGyef5ApycA7FSEOMraay9SaTk5zmbx7Tu+cJs4QKZg=
 modernc.org/opt v0.2.0/go.mod h1:03fq9lsNfvkYSfxrfUhZCWPk1lm4cq4N+Bh//bEtgns=
 modernc.org/sortutil v1.2.1 h1:+xyoGf15mM3NMlPDnFqrteY07klSFxLElE2PVuWIJ7w=
 modernc.org/sortutil v1.2.1/go.mod 
h1:7ZI3a3REbai7gzCLcotuw9AC4VZVpYMjDzETGsSMqJE=
-modernc.org/sqlite v1.56.0 h1:/D8e2RfFqoy/Zc6PuC76U28zFwmI/sYx1Kjm4yEn9e0=
-modernc.org/sqlite v1.56.0/go.mod 
h1:yCJ2cmAaIkHQ25oXWrF8H4O1lIfPYPR26yCEDj2P3pQ=
+modernc.org/sqlite v1.58.0 h1:38u40/bwkfM7f0Myhosl+SEMltSDxnGdQf8o6Kjmys0=
+modernc.org/sqlite v1.58.0/go.mod 
h1:rsD2CckafgObKC4DhBlGBf+RiHxkc3hINGt1Xw32tVY=
 modernc.org/strutil v1.2.1 h1:UneZBkQA+DX2Rp35KcM69cSsNES9ly8mQWD71HKlOA0=
 modernc.org/strutil v1.2.1/go.mod 
h1:EHkiggD70koQxjVdSBM3JKM7k6L0FbGE5eymy9i3B9A=
 modernc.org/token v1.1.0 h1:Xl7Ap9dKaEs5kLoOQeQmPWevfnk/DM5qcLcYlA8ys6Y=
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/grype-0.118.0/grype/db/v6/build/transformers/openvex/transform.go 
new/grype-0.119.0/grype/db/v6/build/transformers/openvex/transform.go
--- old/grype-0.118.0/grype/db/v6/build/transformers/openvex/transform.go       
2026-08-27 20:40:29.000000000 +0200
+++ new/grype-0.119.0/grype/db/v6/build/transformers/openvex/transform.go       
2026-09-17 17:25:25.000000000 +0200
@@ -158,7 +158,13 @@
        switch purl.Type {
        case packageurl.TypeMaven:
                return purl.Namespace + ":" + purl.Name
-       case packageurl.TypeNPM:
+       case packageurl.TypeNPM, packageurl.TypeGolang:
+               // For Go the namespace is not metadata, it is the leading part 
of the
+               // module path: pkg:golang/github.com/gin-gonic/gin splits into
+               // Namespace="github.com/gin-gonic" and Name="gin", and the 
module is
+               // only identified by the two joined. Dropping it would file the
+               // statement under "gin". A module with no namespace, such as
+               // pkg:golang/stdlib, is returned unchanged by the check above.
                return purl.Namespace + "/" + purl.Name
        }
        return purl.Name
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/grype-0.118.0/grype/db/v6/build/transformers/openvex/transform_test.go 
new/grype-0.119.0/grype/db/v6/build/transformers/openvex/transform_test.go
--- old/grype-0.118.0/grype/db/v6/build/transformers/openvex/transform_test.go  
2026-08-27 20:40:29.000000000 +0200
+++ new/grype-0.119.0/grype/db/v6/build/transformers/openvex/transform_test.go  
2026-09-17 17:25:25.000000000 +0200
@@ -8,6 +8,8 @@
        govex "github.com/openvex/go-vex/pkg/vex"
        "github.com/stretchr/testify/require"
 
+       "github.com/anchore/packageurl-go"
+
        "github.com/anchore/grype/grype/db/internal/provider/unmarshal"
        "github.com/anchore/grype/grype/db/provider"
        db "github.com/anchore/grype/grype/db/v6"
@@ -621,3 +623,67 @@
                })
        }
 }
+
+func Test_packageNameFromPURL(t *testing.T) {
+       tests := []struct {
+               name string
+               purl string
+               want string
+       }{
+               {
+                       // A Go module is identified by its full path; the 
namespace is the
+                       // leading part of it rather than metadata, so dropping 
it filed the
+                       // statement under a different package than the 
advisory and matcher
+                       // paths use.
+                       name: "golang module keeps its namespace",
+                       purl: "pkg:golang/github.com/gin-gonic/[email protected]",
+                       want: "github.com/gin-gonic/gin",
+               },
+               {
+                       name: "golang module on a vanity host",
+                       purl: "pkg:golang/k8s.io/[email protected]",
+                       want: "k8s.io/client-go",
+               },
+               {
+                       name: "golang module with a version suffix in the name",
+                       purl: "pkg:golang/gopkg.in/[email protected]",
+                       want: "gopkg.in/yaml.v3",
+               },
+               {
+                       name: "golang module with no namespace is unchanged",
+                       purl: "pkg:golang/[email protected]",
+                       want: "stdlib",
+               },
+               {
+                       name: "maven keeps the groupId separator",
+                       purl: 
"pkg:maven/org.apache.commons/[email protected]",
+                       want: "org.apache.commons:commons-lang3",
+               },
+               {
+                       name: "npm scoped name is rejoined",
+                       purl: "pkg:npm/%40angular/[email protected]",
+                       want: "@angular/core",
+               },
+               {
+                       // An ecosystem whose namespace is metadata rather than 
identity is
+                       // left alone, so this change does not widen beyond Go.
+                       name: "namespace that is not part of the name is 
dropped",
+                       purl: "pkg:deb/debian/[email protected]",
+                       want: "curl",
+               },
+               {
+                       name: "flat ecosystem is unchanged",
+                       purl: "pkg:pypi/[email protected]",
+                       want: "urllib3",
+               },
+       }
+
+       for _, tt := range tests {
+               t.Run(tt.name, func(t *testing.T) {
+                       purl, err := packageurl.FromString(tt.purl)
+                       require.NoError(t, err)
+
+                       require.Equal(t, tt.want, packageNameFromPURL(&purl))
+               })
+       }
+}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/grype-0.118.0/grype/internal/ignorereasons/ignore_reasons.go 
new/grype-0.119.0/grype/internal/ignorereasons/ignore_reasons.go
--- old/grype-0.118.0/grype/internal/ignorereasons/ignore_reasons.go    
1970-01-01 01:00:00.000000000 +0100
+++ new/grype-0.119.0/grype/internal/ignorereasons/ignore_reasons.go    
2026-09-17 17:25:25.000000000 +0200
@@ -0,0 +1,15 @@
+// Package ignorereasons holds the reason values grype writes on the ignore
+// rules created by its own internal suppressions. These become visible to
+// consumers via VulnerabilityMatcher.IncludeMatcherSuppressions; the string
+// values in output are the interface, not these symbols.
+package ignorereasons
+
+const (
+       // DistroFixed is the reason recorded when a distro fix record for an
+       // owning package suppresses a match on an owned package.
+       DistroFixed = "distro-fixed"
+
+       // DistroNAK is the reason recorded when a distro record declaring a
+       // package not vulnerable suppresses a match.
+       DistroNAK = "distro-nak"
+)
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/grype-0.118.0/grype/match/ignore_test.go 
new/grype-0.119.0/grype/match/ignore_test.go
--- old/grype-0.118.0/grype/match/ignore_test.go        2026-08-27 
20:40:29.000000000 +0200
+++ new/grype-0.119.0/grype/match/ignore_test.go        2026-09-17 
17:25:25.000000000 +0200
@@ -6,6 +6,7 @@
        "github.com/google/uuid"
        "github.com/stretchr/testify/assert"
 
+       "github.com/anchore/grype/grype/internal/ignorereasons"
        "github.com/anchore/grype/grype/pkg"
        "github.com/anchore/grype/grype/vulnerability"
        "github.com/anchore/syft/syft/artifact"
@@ -1181,7 +1182,7 @@
        }
 
        filter := IgnoreRelatedPackage{
-               Reason:           "Explicit APK NAK by Ownership",
+               Reason:           ignorereasons.DistroNAK,
                RelationshipType: artifact.OwnershipByFileOverlapRelationship,
                VulnerabilityID:  "GHSA-xjjg-vmw6-c2p9",
                RelatedPackageID: ownerPkgID,
@@ -1241,6 +1242,7 @@
                                assert.NotEmpty(t, rules, "expected match to be 
ignored")
                                assert.Equal(t, filter.VulnerabilityID, 
rules[0].Vulnerability)
                                assert.Equal(t, filter.Reason, rules[0].Reason)
+                               assert.True(t, rules[0].IncludeAliases, 
"emitted rule should include aliases")
                        } else {
                                assert.Empty(t, rules, "expected match to NOT 
be ignored")
                        }
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/grype-0.118.0/grype/matcher/apk/matcher.go 
new/grype-0.119.0/grype/matcher/apk/matcher.go
--- old/grype-0.118.0/grype/matcher/apk/matcher.go      2026-08-27 
20:40:29.000000000 +0200
+++ new/grype-0.119.0/grype/matcher/apk/matcher.go      2026-09-17 
17:25:25.000000000 +0200
@@ -5,6 +5,7 @@
        "fmt"
        "slices"
 
+       "github.com/anchore/grype/grype/internal/ignorereasons"
        "github.com/anchore/grype/grype/match"
        "github.com/anchore/grype/grype/matcher/internal"
        "github.com/anchore/grype/grype/matcher/internal/result"
@@ -15,11 +16,6 @@
        syftPkg "github.com/anchore/syft/syft/pkg"
 )
 
-const (
-       ignoreReasonDistroFixed = "DistroPackageFixed"
-       ignoreReasonExplicitNAK = "Explicit APK NAK"
-)
-
 var (
        nakVersionString = version.MustGetConstraint("< 0", 
version.ApkFormat).String()
 
@@ -75,7 +71,7 @@
        ignores := slices.Concat(
                cpeIgnores,
                nakIgnores,
-               internal.OwnershipIgnores(p, ignoreReasonDistroFixed, 
allFixed.Vulnerabilities()...),
+               internal.OwnershipIgnores(p, ignorereasons.DistroFixed, 
allFixed.Vulnerabilities()...),
        )
 
        return vulnerable.ToMatches(), ignores, nil
@@ -138,7 +134,7 @@
                naks = naks.Merge(upstreamNaks)
        }
 
-       return internal.OwnershipIgnores(p, ignoreReasonExplicitNAK, 
naks.Vulnerabilities()...), nil
+       return internal.OwnershipIgnores(p, ignorereasons.DistroNAK, 
naks.Vulnerabilities()...), nil
 }
 
 // cpeResults finds NVD (CPE-indexed) results for the package itself and for 
each of its
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/grype-0.118.0/grype/matcher/apk/matcher_test.go 
new/grype-0.119.0/grype/matcher/apk/matcher_test.go
--- old/grype-0.118.0/grype/matcher/apk/matcher_test.go 2026-08-27 
20:40:29.000000000 +0200
+++ new/grype-0.119.0/grype/matcher/apk/matcher_test.go 2026-09-17 
17:25:25.000000000 +0200
@@ -5,6 +5,7 @@
 
        "github.com/stretchr/testify/require"
 
+       "github.com/anchore/grype/grype/internal/ignorereasons"
        "github.com/anchore/grype/grype/match"
        "github.com/anchore/grype/grype/pkg"
        "github.com/anchore/grype/grype/version"
@@ -14,16 +15,6 @@
        syftPkg "github.com/anchore/syft/syft/pkg"
 )
 
-// reasonDistroPackageFixed is the IgnoreRelatedPackage reason emitted by the
-// shared internal/MatchPackageByDistro path for vulns the secdb considers
-// fixed (or unaffected/NAK) for the package.
-const reasonDistroPackageFixed = "DistroPackageFixed"
-
-// reasonExplicitApkNak is the IgnoreRelatedPackage reason emitted by the
-// apk-specific findNaksForPackage path for secdb entries with the apk
-// "< 0" sentinel constraint.
-const reasonExplicitApkNak = "Explicit APK NAK"
-
 // reasonCPENotVulnerable is the IgnoreRelatedPackage reason emitted by
 // MatchPackageByCPEs for CPE matches that resolved a vulnerability record
 // for the package's CPE but whose version constraint is not satisfied by
@@ -107,7 +98,7 @@
                })
 }
 
-// === fixed-version → DistroPackageFixed ignore (no match) ===
+// === fixed-version → distro-fixed ignore (no match) ===
 
 func TestMatcherApk_FixedVersionProducesIgnore_Alpine(t *testing.T) {
        dbtest.DBs(t, "alpine318").
@@ -121,7 +112,7 @@
                                Build()
 
                        db.Match(t, &matcher, p).Ignores().
-                               
SelectRelatedPackageIgnore(reasonDistroPackageFixed, "CVE-2024-0727").
+                               
SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2024-0727").
                                ForPackage(pkgID).
                                
WithRelationshipType(artifact.OwnershipByFileOverlapRelationship)
                })
@@ -139,7 +130,7 @@
                                Build()
 
                        db.Match(t, &matcher, p).Ignores().
-                               
SelectRelatedPackageIgnore(reasonDistroPackageFixed, "CVE-2024-0727").
+                               
SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2024-0727").
                                ForPackage(pkgID).
                                
WithRelationshipType(artifact.OwnershipByFileOverlapRelationship)
                })
@@ -147,7 +138,7 @@
 
 // TestMatcherApk_FixedVersionInUpstreamProducesIgnore verifies that when a
 // binary apk package's upstream is at or past the secdb fix, the
-// DistroPackageFixed ignore is emitted against the binary package's ID
+// distro-fixed ignore is emitted against the binary package's ID
 // (catalogPkg) - not the synthetic upstream - so consumers can suppress
 // language-ecosystem matches that overlap the binary by file ownership.
 func TestMatcherApk_FixedVersionInUpstreamProducesIgnore(t *testing.T) {
@@ -163,19 +154,19 @@
                                Build()
 
                        db.Match(t, &matcher, p).Ignores().
-                               
SelectRelatedPackageIgnore(reasonDistroPackageFixed, "CVE-2024-0727").
+                               
SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2024-0727").
                                ForPackage(pkgID).
                                
WithRelationshipType(artifact.OwnershipByFileOverlapRelationship)
                })
 }
 
-// === NAK → Explicit APK NAK + DistroPackageFixed ignores ===
+// === NAK → distro-nak + distro-fixed ignores ===
 
 // TestMatcherApk_NakProducesIgnore_Alpine verifies the NAK path: alpine
 // CVE-2019-6470 lists bind with Version="0", which the v6 OS transformer
 // turns into a "< 0" ApkFormat constraint. The matcher emits two ignores
-// per NAK - one DistroPackageFixed via the shared MatchPackageByDistro
-// fixed/unaffected ownership path, and one apk-specific Explicit APK NAK
+// per NAK - one distro-fixed via the shared MatchPackageByDistro
+// fixed/unaffected ownership path, and one apk-specific distro-nak
 // via findNaksForPackage. Both point at the same package + CVE.
 func TestMatcherApk_NakProducesIgnore_Alpine(t *testing.T) {
        dbtest.DBs(t, "alpine318").
@@ -189,10 +180,10 @@
                                Build()
 
                        ignores := db.Match(t, &matcher, p).Ignores()
-                       
ignores.SelectRelatedPackageIgnore(reasonExplicitApkNak, "CVE-2019-6470").
+                       
ignores.SelectRelatedPackageIgnore(ignorereasons.DistroNAK, "CVE-2019-6470").
                                ForPackage(pkgID).
                                
WithRelationshipType(artifact.OwnershipByFileOverlapRelationship)
-                       
ignores.SelectRelatedPackageIgnore(reasonDistroPackageFixed, "CVE-2019-6470").
+                       
ignores.SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2019-6470").
                                ForPackage(pkgID).
                                
WithRelationshipType(artifact.OwnershipByFileOverlapRelationship)
                })
@@ -211,10 +202,10 @@
                                Build()
 
                        ignores := db.Match(t, &matcher, p).Ignores()
-                       
ignores.SelectRelatedPackageIgnore(reasonExplicitApkNak, "CVE-2024-47535").
+                       
ignores.SelectRelatedPackageIgnore(ignorereasons.DistroNAK, "CVE-2024-47535").
                                ForPackage(pkgID).
                                
WithRelationshipType(artifact.OwnershipByFileOverlapRelationship)
-                       
ignores.SelectRelatedPackageIgnore(reasonDistroPackageFixed, "CVE-2024-47535").
+                       
ignores.SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2024-47535").
                                ForPackage(pkgID).
                                
WithRelationshipType(artifact.OwnershipByFileOverlapRelationship)
                })
@@ -237,10 +228,10 @@
                                Build()
 
                        ignores := db.Match(t, &matcher, p).Ignores()
-                       
ignores.SelectRelatedPackageIgnore(reasonExplicitApkNak, "CVE-2019-6470").
+                       
ignores.SelectRelatedPackageIgnore(ignorereasons.DistroNAK, "CVE-2019-6470").
                                ForPackage(pkgID).
                                
WithRelationshipType(artifact.OwnershipByFileOverlapRelationship)
-                       
ignores.SelectRelatedPackageIgnore(reasonDistroPackageFixed, "CVE-2019-6470").
+                       
ignores.SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2019-6470").
                                ForPackage(pkgID).
                                
WithRelationshipType(artifact.OwnershipByFileOverlapRelationship)
                })
@@ -290,7 +281,7 @@
 // TestMatcherApk_NvdDroppedWhenSecdbHasFix verifies that when secdb knows
 // about a CVE and considers the package fixed, the NVD CPE record is
 // dropped even if NVD still considers the upstream version vulnerable. The
-// only output is a DistroPackageFixed ignore from the secdb path.
+// only output is a distro-fixed ignore from the secdb path.
 func TestMatcherApk_NvdDroppedWhenSecdbHasFix(t *testing.T) {
        // alpine fix: openssl 3.1.4-r5. NVD CVE-2024-0727 lists openssl in
        // [3.1.0, 3.1.5), so 3.1.4 still matches the NVD CPE range - this is
@@ -307,7 +298,7 @@
                                Build()
 
                        db.Match(t, &matcher, p).Ignores().
-                               
SelectRelatedPackageIgnore(reasonDistroPackageFixed, "CVE-2024-0727").
+                               
SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2024-0727").
                                ForPackage(pkgID).
                                
WithRelationshipType(artifact.OwnershipByFileOverlapRelationship)
                })
@@ -459,12 +450,12 @@
                        findings.DoesNotHaveAnyVulnerabilities("CVE-2024-47535")
 
                        // the upstream NAK still produces both apk-NAK and
-                       // DistroPackageFixed ignores keyed to the catalog 
package.
+                       // distro-fixed ignores keyed to the catalog package.
                        ignores := findings.Ignores()
-                       
ignores.SelectRelatedPackageIgnore(reasonExplicitApkNak, "CVE-2024-47535").
+                       
ignores.SelectRelatedPackageIgnore(ignorereasons.DistroNAK, "CVE-2024-47535").
                                ForPackage(pkgID).
                                
WithRelationshipType(artifact.OwnershipByFileOverlapRelationship)
-                       
ignores.SelectRelatedPackageIgnore(reasonDistroPackageFixed, "CVE-2024-47535").
+                       
ignores.SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2024-47535").
                                ForPackage(pkgID).
                                
WithRelationshipType(artifact.OwnershipByFileOverlapRelationship)
                })
@@ -506,10 +497,10 @@
                // must not surface as its own match.
                findings.DoesNotHaveAnyVulnerabilities("CVE-2026-24398")
 
-               // the distro fixed path still emits one DistroPackageFixed 
ignore per
+               // the distro fixed path still emits one distro-fixed ignore per
                // identifier (the CGA id plus its CVE/GHSA aliases).
                findings.Ignores().
-                       SelectRelatedPackageIgnores(reasonDistroPackageFixed,
+                       SelectRelatedPackageIgnores(ignorereasons.DistroFixed,
                                "CGA-22hv-wp9q-4779",
                                "CVE-2026-24398",
                                "GHSA-r354-f388-2fhh").
@@ -573,7 +564,7 @@
 
                // the ranges-less advisory must NOT be treated as an apk NAK: 
it is affected at every
                // version, not "not affected". The "< 0" NAK filter no longer 
matches a record that
-               // carries no "< 0" constraint, so no Explicit APK NAK ignores 
are emitted.
+               // carries no "< 0" constraint, so no distro-nak ignores are 
emitted.
                findings.Ignores().IsEmpty()
        })
 }
@@ -669,14 +660,14 @@
 // TestMatcherApk_ArchFilter_IgnoreWhenArchAgrees is the pair of
 // MatchWhenArchAgrees: same package, same arch, but a version past the
 // fix. The arch qualifier still passes so the fix path runs and emits
-// one DistroPackageFixed ignore per identifier (CGA id + aliases).
+// one distro-fixed ignore per identifier (CGA id + aliases).
 // Cross-checks that arch filtering doesn't short-circuit the
 // fixed-version ignore emission.
 func TestMatcherApk_ArchFilter_IgnoreWhenArchAgrees(t *testing.T) {
        dbtest.DBs(t, "chainguard-rolling").Run(func(t *testing.T, db 
*dbtest.DB) {
                matcher := Matcher{}
                // fix is 3.153.0-r0; 3.153.1-r0 is over the fix, so the 
matcher emits
-               // no match but does emit one DistroPackageFixed ignore per 
identifier
+               // no match but does emit one distro-fixed ignore per identifier
                // (the CGA id plus its CVE/GHSA aliases) so consumers can 
suppress
                // language-ecosystem findings that overlap by file ownership.
                pkgID := pkg.ID("langfuse-past-fix")
@@ -688,7 +679,7 @@
 
                // vulnerability fixed this pkg-version for this architecture
                db.Match(t, &matcher, p).Ignores().
-                       SelectRelatedPackageIgnores(reasonDistroPackageFixed,
+                       SelectRelatedPackageIgnores(ignorereasons.DistroFixed,
                                "CGA-22hv-wp9q-4779",
                                "CVE-2026-24398",
                                "GHSA-r354-f388-2fhh").
@@ -701,7 +692,7 @@
 // the package's arch is aarch64 but the only Chainguard APH for this name has
 // arch=x86_64, so OnlyQualifiedPackages drops it before the version check ever
 // runs. No match, no ignore (the vuln is filtered before reaching the fix
-// path that would emit a DistroPackageFixed ignore).
+// path that would emit a distro-fixed ignore).
 func TestMatcherApk_ArchFilter_NoMatchWhenArchDisagrees(t *testing.T) {
        dbtest.DBs(t, "chainguard-rolling").Run(func(t *testing.T, db 
*dbtest.DB) {
                matcher := Matcher{}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/grype-0.118.0/grype/matcher/apk/rootio_test.go 
new/grype-0.119.0/grype/matcher/apk/rootio_test.go
--- old/grype-0.118.0/grype/matcher/apk/rootio_test.go  2026-08-27 
20:40:29.000000000 +0200
+++ new/grype-0.119.0/grype/matcher/apk/rootio_test.go  2026-09-17 
17:25:25.000000000 +0200
@@ -6,6 +6,7 @@
        "github.com/stretchr/testify/assert"
        "github.com/stretchr/testify/require"
 
+       "github.com/anchore/grype/grype/internal/ignorereasons"
        "github.com/anchore/grype/grype/match"
        "github.com/anchore/grype/grype/pkg"
        "github.com/anchore/grype/internal/dbtest"
@@ -27,7 +28,7 @@
 //   - the NVD CPE match, but only where the distro feed has no opinion.
 //     A rootio NAK covering the same vulnerability by alias means the
 //     vendor has answered it, so no match is reported at all;
-//   - the rootio NAK as DistroPackageFixed IgnoreFilters that
+//   - the rootio NAK as distro-fixed IgnoreFilters that
 //     alias-unwind into the rootio record ID + the upstream CVE. Those
 //     are for packages that overlap this one by file, which is the only
 //     thing an IgnoreRelatedPackage can suppress — never the package it
@@ -88,7 +89,7 @@
 
                // rootio-libuv at the rootio fix. NVD CPE flags 1.44.2 (< vEnd
                // 1.48.0) — match surfaces. The rootio NAK matches alias
-               // CVE-2024-24806 and appears as the DistroPackageFixed ignore
+               // CVE-2024-24806 and appears as the distro-fixed ignore
                // pair that downstream code uses to drop the match.
                t.Run("rootio-libuv at rootio fix: no match, NAK ignore only", 
func(t *testing.T) {
                        pkgID := pkg.ID("rootio-libuv-at-fix")
@@ -103,7 +104,7 @@
                        // NVD CPE record is answered and never becomes a match
                        findings.DoesNotHaveAnyVulnerabilities("CVE-2024-24806")
                        findings.Ignores().
-                               
SelectRelatedPackageIgnores("DistroPackageFixed",
+                               
SelectRelatedPackageIgnores(ignorereasons.DistroFixed,
                                        "ROOT-OS-ALPINE-318-CVE-2024-24806",
                                        "CVE-2024-24806").
                                ForPackage(pkgID).
@@ -140,7 +141,7 @@
                        // NVD CPE record is answered and never becomes a match
                        findings.DoesNotHaveAnyVulnerabilities("CVE-2024-28182")
                        findings.Ignores().
-                               
SelectRelatedPackageIgnores("DistroPackageFixed",
+                               
SelectRelatedPackageIgnores(ignorereasons.DistroFixed,
                                        "ROOT-OS-ALPINE-318-CVE-2024-28182",
                                        "CVE-2024-28182").
                                ForPackage(pkgID).
@@ -174,7 +175,7 @@
                        // NVD CPE record is answered and never becomes a match
                        findings.DoesNotHaveAnyVulnerabilities("CVE-2024-10524")
                        findings.Ignores().
-                               
SelectRelatedPackageIgnores("DistroPackageFixed",
+                               
SelectRelatedPackageIgnores(ignorereasons.DistroFixed,
                                        "ROOT-OS-ALPINE-318-CVE-2024-10524",
                                        "CVE-2024-10524").
                                ForPackage(pkgID).
@@ -183,7 +184,7 @@
 
                // rootio-socat at rootio fix. CVE-2024-54661 has no NVD CPE 
entry
                // so there's no disclosure to suppress — but the matcher still
-               // emits the NAK as a DistroPackageFixed ignore (it lives in
+               // emits the NAK as a distro-fixed ignore (it lives in
                // `fixed` after fixed.Merge(unaffected)). This is the
                // "rootio-only" combination.
                t.Run("rootio-socat at rootio fix: NAK ignore only, no 
disclosure", func(t *testing.T) {
@@ -194,7 +195,7 @@
                                Build()
 
                        db.Match(t, &matcher, p).Ignores().
-                               
SelectRelatedPackageIgnores("DistroPackageFixed",
+                               
SelectRelatedPackageIgnores(ignorereasons.DistroFixed,
                                        "ROOT-OS-ALPINE-318-CVE-2024-54661",
                                        "CVE-2024-54661").
                                ForPackage(pkgID).
@@ -226,7 +227,7 @@
                                Build()
 
                        db.Match(t, &matcher, p).Ignores().
-                               
SelectRelatedPackageIgnore("DistroPackageFixed", "CVE-2024-0727").
+                               
SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2024-0727").
                                ForPackage(pkgID)
                })
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/grype-0.118.0/grype/matcher/dpkg/rootio_test.go 
new/grype-0.119.0/grype/matcher/dpkg/rootio_test.go
--- old/grype-0.118.0/grype/matcher/dpkg/rootio_test.go 2026-08-27 
20:40:29.000000000 +0200
+++ new/grype-0.119.0/grype/matcher/dpkg/rootio_test.go 2026-09-17 
17:25:25.000000000 +0200
@@ -3,6 +3,7 @@
 import (
        "testing"
 
+       "github.com/anchore/grype/grype/internal/ignorereasons"
        "github.com/anchore/grype/grype/match"
        "github.com/anchore/grype/grype/pkg"
        "github.com/anchore/grype/internal/dbtest"
@@ -47,7 +48,7 @@
                expectType match.Type // ignored when expectCVE is empty
 
                // expectFixedCVEs lists the CVE IDs that should surface as
-               // DistroPackageFixed ignores. The rootio NAK alias-unwinds into
+               // distro-fixed ignores. The rootio NAK alias-unwinds into
                // both the ROOT-OS-* record ID and the upstream CVE, so the
                // rootio-suppressed cases list both.
                expectFixedCVEs []string
@@ -65,7 +66,7 @@
                {
                        // At the rootio fix, the NAK lands in the unaffected 
set and
                        // shares the CVE alias with the upstream disclosure. 
The matcher
-                       // subtracts the disclosure and emits two 
DistroPackageFixed
+                       // subtracts the disclosure and emits two distro-fixed
                        // ignores: the ROOT-OS-* record and the aliased CVE.
                        name:            "rootio-gnupg2 at rootio fix: NAK 
suppresses upstream disclosure",
                        pkgName:         "rootio-gnupg2",
@@ -94,7 +95,7 @@
                },
                {
                        // Regular gnupg2 at the upstream fix is patched per 
Ubuntu's
-                       // own data. The matcher records a standard 
DistroPackageFixed
+                       // own data. The matcher records a standard distro-fixed
                        // ignore (no rootio involvement at all).
                        name:            "regular gnupg2 at upstream fix: 
distro-fixed by Ubuntu",
                        pkgName:         "gnupg2",
@@ -181,7 +182,7 @@
 
                                if len(tt.expectFixedCVEs) > 0 {
                                        findings.Ignores().
-                                               
SelectRelatedPackageIgnores("DistroPackageFixed", tt.expectFixedCVEs...).
+                                               
SelectRelatedPackageIgnores(ignorereasons.DistroFixed, tt.expectFixedCVEs...).
                                                ForPackage(pkgID)
                                }
                        })
@@ -272,7 +273,7 @@
 
                                if len(tt.expectFixedCVEs) > 0 {
                                        findings.Ignores().
-                                               
SelectRelatedPackageIgnores("DistroPackageFixed", tt.expectFixedCVEs...).
+                                               
SelectRelatedPackageIgnores(ignorereasons.DistroFixed, tt.expectFixedCVEs...).
                                                ForPackage(pkgID)
                                }
                        })
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/grype-0.118.0/grype/matcher/internal/distro.go 
new/grype-0.119.0/grype/matcher/internal/distro.go
--- old/grype-0.118.0/grype/matcher/internal/distro.go  2026-08-27 
20:40:29.000000000 +0200
+++ new/grype-0.119.0/grype/matcher/internal/distro.go  2026-09-17 
17:25:25.000000000 +0200
@@ -4,6 +4,7 @@
        "fmt"
        "strings"
 
+       "github.com/anchore/grype/grype/internal/ignorereasons"
        "github.com/anchore/grype/grype/match"
        "github.com/anchore/grype/grype/matcher/internal/result"
        "github.com/anchore/grype/grype/pkg"
@@ -97,7 +98,7 @@
        }
 
        // Use the SBOM package (not the synthetic upstream) for file ownership 
— the upstream package doesn't have file metadata.
-       ignores := OwnershipIgnores(matchPackage(searchPkg, catalogPkg), 
"DistroPackageFixed", fixed.Vulnerabilities()...)
+       ignores := OwnershipIgnores(matchPackage(searchPkg, catalogPkg), 
ignorereasons.DistroFixed, fixed.Vulnerabilities()...)
 
        return vulnerable.ToMatches(), ignores, nil
 }
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/grype-0.118.0/grype/matcher/internal/distro_test.go 
new/grype-0.119.0/grype/matcher/internal/distro_test.go
--- old/grype-0.118.0/grype/matcher/internal/distro_test.go     2026-08-27 
20:40:29.000000000 +0200
+++ new/grype-0.119.0/grype/matcher/internal/distro_test.go     2026-09-17 
17:25:25.000000000 +0200
@@ -9,6 +9,7 @@
        "github.com/stretchr/testify/require"
 
        "github.com/anchore/grype/grype/distro"
+       "github.com/anchore/grype/grype/internal/ignorereasons"
        "github.com/anchore/grype/grype/match"
        "github.com/anchore/grype/grype/pkg"
        "github.com/anchore/grype/grype/version"
@@ -301,7 +302,7 @@
                                require.True(t, ok, "expected IgnoreRule or 
IgnoreRelatedPackage types")
                                gotVulnIDs.Add(rule.Vulnerability)
                                assert.True(t, rule.IncludeAliases, "expected 
IncludeAliases to be true")
-                               assert.Contains(t, rule.Reason, 
"DistroPackageFixed")
+                               assert.Contains(t, rule.Reason, 
ignorereasons.DistroFixed)
                                assert.NotEmpty(t, rule.Package.Location, 
"expected location to be set")
                        }
 
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/grype-0.118.0/grype/vulnerability_matcher.go 
new/grype-0.119.0/grype/vulnerability_matcher.go
--- old/grype-0.118.0/grype/vulnerability_matcher.go    2026-08-27 
20:40:29.000000000 +0200
+++ new/grype-0.119.0/grype/vulnerability_matcher.go    2026-09-17 
17:25:25.000000000 +0200
@@ -46,6 +46,13 @@
        VexProcessor          *vex.Processor
        Alerts                AlertsConfig
 
+       // IncludeMatcherSuppressions includes matches that were dropped by
+       // hard-coded rules or matcher-provided ignore filters (e.g. distro
+       // fixed/NAK records suppressing matches on owned packages) in the
+       // ignoredMatches results. When false (the default) these are discarded
+       // after logging, preserving the previous behavior.
+       IncludeMatcherSuppressions bool
+
        // tracked packages with distro issues (populated during FindMatches)
        eolDistroPackages     []pkg.Package
        distroDetectionFailed bool
@@ -138,7 +145,7 @@
        var ignoredMatches []match.IgnoredMatch
 
        log.Trace("finding matches against DB")
-       matches, err := m.searchDBForMatches(ctx, pkgs, progressMonitor)
+       matches, droppedMatches, err := m.searchDBForMatches(ctx, pkgs, 
progressMonitor)
        if err != nil {
                if match.IsFatalError(err) {
                        return nil, nil, err
@@ -166,6 +173,14 @@
                ignoredMatches = m.mergeIgnoredMatches(originalIgnoredMatches, 
ignoredMatches)
        }
 
+       if m.IncludeMatcherSuppressions {
+               // include matches dropped by hard-coded rules and 
matcher-provided filters
+               // (e.g. distro fixed/NAK records suppressing matches on owned 
packages) so
+               // callers can see that a match was found and then suppressed; 
user-rule
+               // ignores keep their existing positions at the front of the 
slice
+               ignoredMatches = m.mergeIgnoredMatches(ignoredMatches, 
droppedMatches)
+       }
+
        return &matches, ignoredMatches, nil
 }
 
@@ -182,13 +197,18 @@
        return out
 }
 
+// searchDBForMatches returns the surviving matches plus every match that was
+// dropped by hard-coded rules or matcher-provided ignore filters, so callers
+// can surface the dropped set rather than losing it after logging.
+//
 //nolint:funlen
 func (m *VulnerabilityMatcher) searchDBForMatches(
        ctx context.Context,
        packages []pkg.Package,
        progressMonitor *monitorWriter,
-) (match.Matches, error) {
+) (match.Matches, []match.IgnoredMatch, error) {
        var allMatches []match.Match
+       var allDropped []match.IgnoredMatch
        var allIgnorers []match.IgnoreFilter
        matcherIndex, defaultMatcher := newMatcherIndex(m.Matchers)
 
@@ -218,13 +238,13 @@
                }
                for _, theMatcher := range matchAgainst {
                        if err := ctx.Err(); err != nil {
-                               return match.Matches{}, err
+                               return match.Matches{}, nil, err
                        }
 
                        matches, ignorers, err := callMatcherSafely(theMatcher, 
m.VulnerabilityProvider, p)
                        if err != nil {
                                if match.IsFatalError(err) {
-                                       return match.Matches{}, err
+                                       return match.Matches{}, nil, err
                                }
 
                                log.WithFields("error", err, "package", 
displayPackage(p)).Warn("matcher returned error")
@@ -240,6 +260,7 @@
                        logPackageMatches(p, additionalMatches)
                        logExplicitDroppedPackageMatches(p, dropped)
                        allMatches = append(allMatches, additionalMatches...)
+                       allDropped = append(allDropped, dropped...)
 
                        
progressMonitor.MatchesDiscovered.Add(int64(len(additionalMatches)))
 
@@ -255,6 +276,7 @@
        filtered, dropped := match.ApplyIgnoreFilters(allMatches, 
ignoredMatchFilter(allIgnorers))
        logIgnoredMatches(dropped)
        log.Debugf("took %v to process %v vulns with %v ignores", 
time.Since(startTime), len(allMatches), len(allIgnorers))
+       allDropped = append(allDropped, dropped...)
 
        // get deduplicated set of matches
        res := match.NewMatches(filtered...)
@@ -262,7 +284,7 @@
        // update the total discovered matches after removing all duplicates 
and ignores
        progressMonitor.MatchesDiscovered.Set(int64(res.Count()))
 
-       return res, errors.Join(matcherErrs...)
+       return res, allDropped, errors.Join(matcherErrs...)
 }
 
 func callMatcherSafely(m match.Matcher, vp vulnerability.Provider, p 
pkg.Package) (matches []match.Match, ignoredMatches []match.IgnoreFilter, err 
error) {
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' 
old/grype-0.118.0/grype/vulnerability_matcher_dropped_test.go 
new/grype-0.119.0/grype/vulnerability_matcher_dropped_test.go
--- old/grype-0.118.0/grype/vulnerability_matcher_dropped_test.go       
1970-01-01 01:00:00.000000000 +0100
+++ new/grype-0.119.0/grype/vulnerability_matcher_dropped_test.go       
2026-09-17 17:25:25.000000000 +0200
@@ -0,0 +1,175 @@
+package grype
+
+// Regression test for anchore/grype#3450 (see also #3282).
+//
+// Before this change, matches suppressed by hard-coded rules or
+// matcher-provided ignore filters (e.g. the distro-fixed ownership rule
+// emitted by OwnershipIgnores(..., ignorereasons.DistroFixed, ...)) were 
dropped
+// inside searchDBForMatches after logging and never returned to callers, so
+// `--show-suppressed` could not surface a regressed CVE that a FIXED secfix
+// entry was hiding (see the fuse-overlayfs-snapshotter / CVE-2026-25679
+// worked example in #3450).
+//
+// This test asserts, with IncludeMatcherSuppressions set:
+//  1. The suppressed bundled-component match reaches the caller in the
+//     second return of FindMatches / FindMatchesContext.
+//  2. Its AppliedIgnoreRules preserve the distro-fixed reason value
+//     and the vulnerability id.
+//
+// And with the default (false): the dropped match is discarded exactly as
+// before, so existing consumers see no behavior change.
+
+import (
+       "testing"
+
+       "github.com/stretchr/testify/assert"
+       "github.com/stretchr/testify/require"
+
+       "github.com/anchore/grype/grype/distro"
+       "github.com/anchore/grype/grype/internal/ignorereasons"
+       "github.com/anchore/grype/grype/match"
+       matcherMock "github.com/anchore/grype/grype/matcher/mock"
+       "github.com/anchore/grype/grype/pkg"
+       "github.com/anchore/grype/grype/version"
+       "github.com/anchore/grype/grype/vulnerability"
+       "github.com/anchore/grype/grype/vulnerability/mock"
+       "github.com/anchore/syft/syft/artifact"
+       "github.com/anchore/syft/syft/file"
+       syftPkg "github.com/anchore/syft/syft/pkg"
+)
+
+func TestVulnerabilityMatcher_DroppedMatchesSurfaceInIgnoredMatches(t 
*testing.T) {
+       apkPkgID := pkg.ID("apk-fuse-overlayfs-snapshotter")
+       stdlibPkgID := pkg.ID("go-stdlib")
+
+       // The Go stdlib CVE as it appears in the NVD provider (grype's nvd:cpe
+       // entry for cpe:2.3:a:golang:go:*).
+       stdlibVuln := vulnerability.Vulnerability{
+               Reference: vulnerability.Reference{
+                       ID:        "CVE-2026-25679",
+                       Namespace: "nvd:cpe",
+               },
+               PackageName: "stdlib",
+               Constraint:  version.MustGetConstraint("< 1.25.8", 
version.UnknownFormat),
+       }
+
+       // APK package [email protected] owns the stdlib 
binary
+       // via file overlap. The secfix entry at 2.1.7-r3 says CVE-2026-25679 is
+       // FIXED, so grype's OwnershipIgnores emits an IgnoreRelatedPackage rule
+       // with Reason ignorereasons.DistroFixed ("distro-fixed") that 
suppresses the stdlib match.
+       apkPkg := pkg.Package{
+               ID:      apkPkgID,
+               Name:    "fuse-overlayfs-snapshotter",
+               Version: "2.1.7-r7",
+               Type:    syftPkg.ApkPkg,
+               Distro:  distro.New(distro.Chainguard, "", ""),
+               Metadata: pkg.ApkMetadata{Files: []pkg.ApkFileRecord{
+                       {Path: "/usr/bin/containerd-fuse-overlayfs-grpc"},
+               }},
+       }
+       stdlibPkg := pkg.Package{
+               ID:      stdlibPkgID,
+               Name:    "stdlib",
+               Version: "go1.24.13",
+               Type:    syftPkg.GoModulePkg,
+               Locations: file.NewLocationSet(
+                       
file.NewLocation("/usr/bin/containerd-fuse-overlayfs-grpc"),
+               ),
+               RelatedPackages: map[artifact.RelationshipType][]*pkg.Package{
+                       artifact.OwnershipByFileOverlapRelationship: {
+                               {ID: apkPkgID, Name: 
"fuse-overlayfs-snapshotter"},
+                       },
+               },
+       }
+
+       vp := mock.VulnerabilityProvider(stdlibVuln)
+
+       // APK matcher returns no matches (r7 satisfies the FIXED constraint at
+       // r3, so the APK itself is not vulnerable) but returns an
+       // IgnoreRelatedPackage filter carrying the distro-fixed reason
+       // string that OwnershipIgnores uses in production
+       // (grype/matcher/internal/distro.go).
+       apkMatcher := matcherMock.New(syftPkg.ApkPkg, func(_ 
vulnerability.Provider, p pkg.Package) ([]match.Match, []match.IgnoreFilter, 
error) {
+               if p.Type != syftPkg.ApkPkg {
+                       return nil, nil, nil
+               }
+               return nil, []match.IgnoreFilter{
+                       match.IgnoreRelatedPackage{
+                               Reason:           ignorereasons.DistroFixed,
+                               RelationshipType: 
artifact.OwnershipByFileOverlapRelationship,
+                               VulnerabilityID:  stdlibVuln.ID,
+                               RelatedPackageID: p.ID,
+                       },
+               }, nil
+       })
+
+       // Go matcher returns the stdlib match for the CVE (which will then be
+       // suppressed by the apk matcher's returned filter).
+       goMatcher := matcherMock.New(syftPkg.GoModulePkg, func(_ 
vulnerability.Provider, p pkg.Package) ([]match.Match, []match.IgnoreFilter, 
error) {
+               if p.Type != syftPkg.GoModulePkg {
+                       return nil, nil, nil
+               }
+               return []match.Match{
+                       {
+                               Vulnerability: stdlibVuln,
+                               Package:       p,
+                               Details: match.Details{
+                                       {
+                                               Type:       match.CPEMatch,
+                                               Confidence: 1.0,
+                                               Matcher:    "go-matcher",
+                                       },
+                               },
+                       },
+               }, nil, nil
+       })
+
+       t.Run("opt-in surfaces the dropped match", func(t *testing.T) {
+               m := &VulnerabilityMatcher{
+                       VulnerabilityProvider:      vp,
+                       Matchers:                   []match.Matcher{apkMatcher, 
goMatcher},
+                       IncludeMatcherSuppressions: true,
+               }
+
+               remaining, ignored, err := m.FindMatches(
+                       []pkg.Package{apkPkg, stdlibPkg},
+                       pkg.Context{},
+               )
+               require.NoError(t, err)
+
+               assert.Zero(t, remaining.Count(),
+                       "main match set should be empty; the stdlib match 
should have been suppressed by the distro-fixed rule")
+
+               require.Len(t, ignored, 1,
+                       "expected exactly one entry in ignoredMatches carrying 
the suppressed stdlib match")
+               got := ignored[0]
+
+               assert.Equal(t, "CVE-2026-25679", got.Match.Vulnerability.ID)
+               assert.Equal(t, "stdlib", got.Match.Package.Name)
+               assert.Equal(t, "go1.24.13", got.Match.Package.Version)
+
+               // AppliedIgnoreRules: the OwnershipIgnores reason string and 
vulnerability
+               // id are preserved verbatim.
+               require.NotEmpty(t, got.AppliedIgnoreRules)
+               assert.Equal(t, ignorereasons.DistroFixed, 
got.AppliedIgnoreRules[0].Reason)
+               assert.Equal(t, "CVE-2026-25679", 
got.AppliedIgnoreRules[0].Vulnerability)
+       })
+
+       t.Run("default discards the dropped match as before", func(t 
*testing.T) {
+               m := &VulnerabilityMatcher{
+                       VulnerabilityProvider: vp,
+                       Matchers:              []match.Matcher{apkMatcher, 
goMatcher},
+               }
+
+               remaining, ignored, err := m.FindMatches(
+                       []pkg.Package{apkPkg, stdlibPkg},
+                       pkg.Context{},
+               )
+               require.NoError(t, err)
+
+               assert.Zero(t, remaining.Count(),
+                       "main match set should be empty; the stdlib match 
should have been suppressed by the distro-fixed rule")
+               assert.Empty(t, ignored,
+                       "with IncludeMatcherSuppressions unset, dropped matches 
must not appear in ignoredMatches")
+       })
+}
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/grype-0.118.0/grype/vulnerability_matcher_test.go 
new/grype-0.119.0/grype/vulnerability_matcher_test.go
--- old/grype-0.118.0/grype/vulnerability_matcher_test.go       2026-08-27 
20:40:29.000000000 +0200
+++ new/grype-0.119.0/grype/vulnerability_matcher_test.go       2026-09-17 
17:25:25.000000000 +0200
@@ -16,6 +16,7 @@
        "github.com/anchore/grype/grype/event"
        "github.com/anchore/grype/grype/event/monitor"
        "github.com/anchore/grype/grype/grypeerr"
+       "github.com/anchore/grype/grype/internal/ignorereasons"
        "github.com/anchore/grype/grype/match"
        "github.com/anchore/grype/grype/matcher"
        matcherMock "github.com/anchore/grype/grype/matcher/mock"
@@ -1152,14 +1153,14 @@
                                        ignores = append(ignores, 
match.IgnoreRule{
                                                Vulnerability:  nakVuln.ID,
                                                IncludeAliases: true,
-                                               Reason:         "Explicit APK 
NAK",
+                                               Reason:         
ignorereasons.DistroNAK,
                                                Package: 
match.IgnoreRulePackage{
                                                        Location: f.Path,
                                                },
                                        })
                                }
                                ignores = append(ignores, 
match.IgnoreRelatedPackage{
-                                       Reason:           "Explicit APK NAK by 
Ownership",
+                                       Reason:           
ignorereasons.DistroNAK,
                                        RelationshipType: 
artifact.OwnershipByFileOverlapRelationship,
                                        VulnerabilityID:  nakVuln.ID,
                                        RelatedPackageID: p.ID,
diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' 
'--exclude=.svnignore' old/grype-0.118.0/test/quality/test-db 
new/grype-0.119.0/test/quality/test-db
--- old/grype-0.118.0/test/quality/test-db      2026-08-27 20:40:29.000000000 
+0200
+++ new/grype-0.119.0/test/quality/test-db      2026-09-17 17:25:25.000000000 
+0200
@@ -1 +1 @@
-https://grype.anchore.io/databases/v6/vulnerability-db_v6.1.9_2026-08-01T00:38:20Z_1785567576.tar.zst
+https://grype.anchore.io/databases/v6/vulnerability-db_v6.1.9_2026-09-01T00:38:09Z_1788244329.tar.zst

++++++ grype.obsinfo ++++++
--- /var/tmp/diff_new_pack.8dHCDm/_old  2026-09-18 22:07:48.137771278 +0200
+++ /var/tmp/diff_new_pack.8dHCDm/_new  2026-09-18 22:07:48.144771571 +0200
@@ -1,5 +1,5 @@
 name: grype
-version: 0.118.0
-mtime: 1787856029
-commit: 756eb9a24f7beeafb6871a24e943e8a3ae210695
+version: 0.119.0
+mtime: 1789658725
+commit: b6f5194537747ee7f705f4113069ac9eb269919f
 

++++++ vendor.tar.gz ++++++
/work/SRC/openSUSE:Factory/grype/vendor.tar.gz 
/work/SRC/openSUSE:Factory/.grype.new.383539/vendor.tar.gz differ: char 133, 
line 1

Reply via email to