Script 'mail_helper' called by obssrc Hello community, here is the log from the commit of package grype for openSUSE:Factory checked in at 2026-09-18 22:06:43 ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Comparing /work/SRC/openSUSE:Factory/grype (Old) and /work/SRC/openSUSE:Factory/.grype.new.383539 (New) ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Package is "grype" Fri Sep 18 22:06:43 2026 rev:129 rq:1378716 version:0.119.0 Changes: -------- --- /work/SRC/openSUSE:Factory/grype/grype.changes 2026-08-28 19:52:01.544714766 +0200 +++ /work/SRC/openSUSE:Factory/.grype.new.383539/grype.changes 2026-09-18 22:07:36.511284013 +0200 @@ -1,0 +2,103 @@ +Fri Sep 18 05:06:33 UTC 2026 - Johannes Kastl <[email protected]> + +- Update to version 0.119.0: + * Added Features + - Expose distro-fixed dropped matches via ignoredMatches so + --show-suppressed can surface them [Issue #3450] [PR #3705] + - Licensing: copyright owner missing, needed for Debian + packaging [Issue #3501] + * Bug Fixes + - fixes typo in cpe example input for cpe-direct scan [PR + #3679] + - --by-cve: which advisory record survives the merge varies + between runs [Issue #3630] + * Additional Changes + - OpenVEX transformer drops the namespace from Go module PURLs + [Issue #3680] [PR #3683] + - Docs missing for include-aliases [Issue #3663] [PR #3671] + * Dependencies + 54 dependency changes (54 updated). 6 vulnerabilities + remediated. + - Remediated (6) + - GHSA-2v4p-qf9q-27wj (High) — google.golang.org/grpc + - GHSA-7jxh-36q5-gcqv (Medium) — + github.com/containerd/containerd/v2 + - GHSA-qc2q-p7wx-3px3 (Medium) — google.golang.org/grpc + - GHSA-vp52-pcj8-j9qc (High) — google.golang.org/grpc + - GO-2026-6354 (High) — golang.org/x/crypto + - GO-2026-6355 (High) — golang.org/x/crypto + - Updated (54 packages) + - cloud.google.com/go/auth v0.22.0 → v0.23.2 + - cloud.google.com/go/iam v1.11.0 → v1.12.0 + - cloud.google.com/go/logging v1.18.0 → v1.19.0 + - cloud.google.com/go/monitoring v1.29.0 → v1.30.0 + - cloud.google.com/go/storage v1.64.0 → v1.65.1 + - github.com/CycloneDX/cyclonedx-go v0.11.0 → v0.12.0 + - github.com/anchore/go-sync v0.1.1 → v0.1.2 + - github.com/anchore/stereoscope v0.3.1 → v0.3.2 + - github.com/anchore/syft v1.51.1 → v1.52.0 + - github.com/aws/aws-sdk-go-v2 v1.43.4 → v1.44.0 + - github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream + v1.7.16 → v1.7.20 + - github.com/aws/aws-sdk-go-v2/config v1.32.35 → v1.32.40 + - github.com/aws/aws-sdk-go-v2/credentials v1.19.34 → + v1.19.39 + - github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.35 → + v1.18.40 + - github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.35 + → v1.4.40 + - github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.35 + → v2.7.40 + - github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.36 → v1.4.41 + - github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding + v1.13.15 → v1.13.19 + - github.com/aws/aws-sdk-go-v2/service/internal/checksum + v1.9.28 → v1.10.0 + - github.com/aws/aws-sdk-go-v2/service/internal/presigned-url + v1.13.35 → v1.13.40 + - github.com/aws/aws-sdk-go-v2/service/internal/s3shared + v1.19.36 → v1.19.41 + - github.com/aws/aws-sdk-go-v2/service/s3 v1.106.5 → v1.108.0 + - github.com/aws/aws-sdk-go-v2/service/signin v1.5.4 → v1.6.0 + - github.com/aws/aws-sdk-go-v2/service/sso v1.33.4 → v1.34.0 + - github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.4 → + v1.39.0 + - github.com/aws/aws-sdk-go-v2/service/sts v1.45.4 → v1.46.0 + - github.com/aws/smithy-go v1.27.6 → v1.28.1 + - github.com/containerd/containerd/v2 v2.3.4 → v2.3.5 + (remediated GHSA-7jxh-36q5-gcqv) + - github.com/docker/cli v29.7.2+incompatible → + v29.8.0+incompatible + - github.com/google/go-containerregistry v0.21.9 → v0.22.1 + - github.com/googleapis/enterprise-certificate-proxy v0.3.19 + → v0.3.20 + - github.com/googleapis/gax-go/v2 v2.23.0 → v2.24.0 + - github.com/gpustack/gguf-parser-go v0.25.0 → v0.26.3 + - github.com/hashicorp/go-getter v1.8.8 → v1.8.9 + - github.com/klauspost/compress v1.19.2 → v1.20.0 + - github.com/moby/moby/api v1.55.0 → v1.56.0 + - github.com/moby/moby/client v0.5.1 → v0.6.0 + - github.com/pandatix/go-cvss v0.6.2 → v0.6.4 + - github.com/terminalstatic/go-xsd-validate v0.1.6 → v0.1.8 + - golang.org/x/crypto v0.55.0 → v0.56.0 (remediated + GO-2026-6354, GO-2026-6355) + - golang.org/x/mod v0.40.0 → v0.41.0 + - golang.org/x/time v0.15.0 → v0.16.0 + - google.golang.org/api v0.292.0 → v0.294.0 + - google.golang.org/genproto v0.0.0-aa98bba → v0.0.0-e75dac1 + - google.golang.org/genproto/googleapis/api v0.0.0-925bb5d → + v0.0.0-e75dac1 + - google.golang.org/genproto/googleapis/rpc v0.0.0-6ac0973 → + v0.0.0-08b0e42 + - google.golang.org/grpc v1.83.0 → v1.83.2 (remediated + GHSA-2v4p-qf9q-27wj, GHSA-qc2q-p7wx-3px3, + GHSA-vp52-pcj8-j9qc) + - google.golang.org/protobuf v1.36.12-0.f2248ac → v1.36.12 + - modernc.org/cc/v4 v4.29.1 → v4.29.2 + - modernc.org/ccgo/v4 v4.34.6 → v4.35.0 + - modernc.org/gc/v3 v3.1.4 → v3.1.5 + - modernc.org/libc v1.74.4 → v1.75.6 + - modernc.org/memory v1.11.0 → v1.12.1 + - modernc.org/sqlite v1.56.0 → v1.58.0 + +------------------------------------------------------------------- Old: ---- grype-0.118.0.obscpio New: ---- grype-0.119.0.obscpio ++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++ Other differences: ------------------ ++++++ grype.spec ++++++ --- /var/tmp/diff_new_pack.8dHCDm/_old 2026-09-18 22:07:38.054348683 +0200 +++ /var/tmp/diff_new_pack.8dHCDm/_new 2026-09-18 22:07:38.057348808 +0200 @@ -17,7 +17,7 @@ Name: grype -Version: 0.118.0 +Version: 0.119.0 Release: 0 Summary: A vulnerability scanner for container images and filesystems License: Apache-2.0 ++++++ _service ++++++ --- /var/tmp/diff_new_pack.8dHCDm/_old 2026-09-18 22:07:38.114351197 +0200 +++ /var/tmp/diff_new_pack.8dHCDm/_new 2026-09-18 22:07:38.118351365 +0200 @@ -3,7 +3,7 @@ <param name="url">https://github.com/anchore/grype.git</param> <param name="scm">git</param> <param name="exclude">.git</param> - <param name="revision">refs/tags/v0.118.0</param> + <param name="revision">refs/tags/v0.119.0</param> <param name="match-tag">v*</param> <param name="versionformat">@PARENT_TAG@</param> <param name="versionrewrite-pattern">v(.*)</param> ++++++ _servicedata ++++++ --- /var/tmp/diff_new_pack.8dHCDm/_old 2026-09-18 22:07:38.159353083 +0200 +++ /var/tmp/diff_new_pack.8dHCDm/_new 2026-09-18 22:07:38.165353335 +0200 @@ -3,6 +3,6 @@ <param name="url">https://github.com/anchore/grype</param> <param name="changesrevision">fa8b7e2a528cf1f8b098123f256c61db9e5df69c</param></service><service name="tar_scm"> <param name="url">https://github.com/anchore/grype.git</param> - <param name="changesrevision">756eb9a24f7beeafb6871a24e943e8a3ae210695</param></service></servicedata> + <param name="changesrevision">b6f5194537747ee7f705f4113069ac9eb269919f</param></service></servicedata> (No newline at EOF) ++++++ grype-0.118.0.obscpio -> grype-0.119.0.obscpio ++++++ diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/cmd/grype/cli/commands/root.go new/grype-0.119.0/cmd/grype/cli/commands/root.go --- old/grype-0.118.0/cmd/grype/cli/commands/root.go 2026-08-27 20:40:29.000000000 +0200 +++ new/grype-0.119.0/cmd/grype/cli/commands/root.go 2026-09-17 17:25:25.000000000 +0200 @@ -73,7 +73,7 @@ {{.appName}} purl:path/to/purl/file read a newline separated file of package URLs from a path on disk {{.appName}} PURL read a single package PURL directly (e.g. pkg:apk/[email protected]?distro=alpine-3.20.3) {{.appName}} cpes:path/to/cpes/file read a newline separated file of package CPEs from a path on disk - {{.appName}} CPE read a single CPE directly (e.g. cpe:2.3:a:openssl:openssl:3.0.14:*:*:*:*:*) + {{.appName}} CPE read a single CPE directly (e.g. cpe:2.3:a:openssl:openssl:3.0.14:*:*:*:*:*:*:* or cpe:/a:openssl:openssl:3.0.14) {{.appName}} zarf:path/to/package.tar.zst scan all SBOMs within a Zarf package archive You can also pipe in Syft JSON directly: @@ -234,6 +234,7 @@ Alerts: grype.AlertsConfig{ EnableEOLDistroWarnings: opts.Alerts.EnableEOLDistroWarnings, }, + IncludeMatcherSuppressions: opts.IncludeMatcherSuppressions, } remainingMatches, ignoredMatches, err := vulnMatcher.FindMatchesContext(ctx, packages, pkgContext) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/cmd/grype/cli/options/grype.go new/grype-0.119.0/cmd/grype/cli/options/grype.go --- old/grype-0.118.0/cmd/grype/cli/options/grype.go 2026-08-27 20:40:29.000000000 +0200 +++ new/grype-0.119.0/cmd/grype/cli/options/grype.go 2026-09-17 17:25:25.000000000 +0200 @@ -31,7 +31,8 @@ FailOn string `yaml:"fail-on-severity" json:"fail-on-severity" mapstructure:"fail-on-severity"` Registry registry `yaml:"registry" json:"registry" mapstructure:"registry"` ShowSuppressed bool `yaml:"show-suppressed" json:"show-suppressed" mapstructure:"show-suppressed"` - ByCVE bool `yaml:"by-cve" json:"by-cve" mapstructure:"by-cve"` // --by-cve, indicates if the original match vulnerability IDs should be preserved or the CVE should be used instead + IncludeMatcherSuppressions bool `yaml:"include-matcher-suppressions" json:"include-matcher-suppressions" mapstructure:"include-matcher-suppressions"` // include matches suppressed internally by matchers (distro fixed/NAK records, built-in false-positive list) in the ignored matches output, default=false + ByCVE bool `yaml:"by-cve" json:"by-cve" mapstructure:"by-cve"` // --by-cve, indicates if the original match vulnerability IDs should be preserved or the CVE should be used instead SortBy SortBy `yaml:",inline" json:",inline" mapstructure:",squash"` Name string `yaml:"name" json:"name" mapstructure:"name"` DefaultImagePullSource string `yaml:"default-image-pull-source" json:"default-image-pull-source" mapstructure:"default-image-pull-source"` @@ -71,6 +72,7 @@ CheckForAppUpdate: true, VexAdd: []string{}, MatchUpstreamKernelHeaders: false, + IncludeMatcherSuppressions: false, SortBy: defaultSortBy(), Timestamp: true, Alerts: defaultAlerts(), @@ -196,22 +198,29 @@ descriptions.Add(&o.Pretty, `pretty-print output`) descriptions.Add(&o.FailOn, `upon scanning, if a severity is found at or above the given severity then the return code will be 1 default is unset which will skip this validation (options: negligible, low, medium, high, critical)`) - descriptions.Add(&o.Ignore, `A list of vulnerability ignore rules, one or more property may be specified and all matching vulnerabilities will be ignored. + descriptions.Add(&o.Ignore, `a list of vulnerability ignore rules; a match must meet ALL criteria specified in a rule to be ignored. This is the full set of supported rule fields: - - vulnerability: CVE-2008-4318 - fix-state: unknown + - vulnerability: CVE-2008-4318 # match by vulnerability ID (required if no other criteria are given) + namespace: nvd:cpe # match by vulnerability namespace (e.g. nvd:cpe, github:language:go) + fix-state: unknown # match by fix state; options: fixed, not-fixed, wont-fix, unknown + match-type: exact-direct-match # match by how the vulnerability was found; options: exact-direct-match, exact-indirect-match, cpe-match + reason: "tolerated by policy" # optional human-readable note recorded on the ignored match (does not affect matching) + include-aliases: true # also apply the vulnerability ID match to aliases/related CVEs (default: false) package: - name: libcurl - version: 1.5.1 - type: npm - location: "/usr/local/lib/node_modules/**" + name: libcurl # match by package name (supports regular expressions) + version: 1.5.1 # match by package version + language: python # match by package language (e.g. python, javascript, java, go, …) + type: npm # match by package type (e.g. rpm, deb, apk, gem, npm, go-module, …) + location: "/usr/local/lib/node_modules/**" # match by package location (supports glob patterns) + upstream-name: curl # match by upstream package name (supports regular expressions) -VEX fields apply when Grype reads vex data: +VEX fields apply when Grype reads VEX data: - vex-status: not_affected vex-justification: vulnerable_code_not_present `) descriptions.Add(&o.VexAdd, `VEX statuses to consider as ignored rules`) descriptions.Add(&o.MatchUpstreamKernelHeaders, `match kernel-header packages with upstream kernel as kernel vulnerabilities`) + descriptions.Add(&o.IncludeMatcherSuppressions, `include matches suppressed internally by matchers (e.g. distro fixed/NAK records, the built-in false-positive list) in the ignored matches output`) } func (o Grype) FailOnSeverity() *vulnerability.Severity { diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/go.mod new/grype-0.119.0/go.mod --- old/grype-0.118.0/go.mod 2026-08-27 20:40:29.000000000 +0200 +++ new/grype-0.119.0/go.mod 2026-09-17 17:25:25.000000000 +0200 @@ -3,7 +3,7 @@ go 1.26.3 require ( - github.com/CycloneDX/cyclonedx-go v0.11.0 + github.com/CycloneDX/cyclonedx-go v0.12.0 github.com/Masterminds/semver/v3 v3.5.0 github.com/Masterminds/sprig/v3 v3.3.0 github.com/OneOfOne/xxhash v1.2.8 @@ -17,7 +17,7 @@ github.com/anchore/go-logger v0.1.1 github.com/anchore/go-version v1.2.2-0.20210903204242-51efa5b487c4 github.com/anchore/packageurl-go v0.2.0 - github.com/anchore/stereoscope v0.3.1 + github.com/anchore/stereoscope v0.3.2 github.com/aquasecurity/go-pep440-version v0.0.1 github.com/araddon/dateparse v0.0.0-20210429162001-6b43995a97de github.com/bitnami/go-version v0.0.0-20250505154626-452e8c5ee607 @@ -36,18 +36,18 @@ github.com/gocsaf/csaf/v3 v3.5.1 github.com/gohugoio/hashstructure v0.6.0 github.com/google/go-cmp v0.7.0 - github.com/google/go-containerregistry v0.21.9 + github.com/google/go-containerregistry v0.22.1 github.com/google/shlex v0.0.0-20191202100458-e7afc7fbc510 github.com/google/uuid v1.6.0 github.com/gookit/color v1.6.1 github.com/hako/durafmt v0.0.0-20210608085754-5c1018a4e16b github.com/hashicorp/go-cleanhttp v0.5.2 - github.com/hashicorp/go-getter v1.8.8 + github.com/hashicorp/go-getter v1.8.9 github.com/hashicorp/go-multierror v1.1.1 github.com/iancoleman/strcase v0.3.0 github.com/invopop/jsonschema v0.14.0 github.com/jinzhu/copier v0.4.0 - github.com/klauspost/compress v1.19.2 + github.com/klauspost/compress v1.20.0 github.com/knqyf263/go-apk-version v0.0.0-20200609155635-041fdbb8563f github.com/knqyf263/go-deb-version v0.0.0-20241115132648-6f4aee6ccd23 github.com/masahiro331/go-mvn-version v0.0.0-20250131095131-f4974fa13b8a @@ -56,7 +56,7 @@ github.com/olekukonko/tablewriter v1.1.4 github.com/openvex/go-vex v0.2.8 github.com/owenrumney/go-sarif v1.1.2-0.20231003122901-1000f5e05554 - github.com/pandatix/go-cvss v0.6.2 + github.com/pandatix/go-cvss v0.6.4 // pinned to pull in 386 arch fix: https://github.com/scylladb/go-set/commit/cc7b2070d91ebf40d233207b633e28f5bd8f03a5 github.com/scylladb/go-set v1.0.3-0.20200225121959-cc7b2070d91e github.com/sergi/go-diff v1.4.0 @@ -71,14 +71,14 @@ github.com/xi2/xz v0.0.0-20171230120015-48954b6210f8 golang.org/x/exp v0.0.0-20260410095643-746e56fc9e2f golang.org/x/text v0.41.0 - golang.org/x/time v0.15.0 + golang.org/x/time v0.16.0 golang.org/x/tools v0.49.0 gopkg.in/yaml.v3 v3.0.1 gorm.io/gorm v1.31.2 ) require ( - github.com/anchore/syft v1.51.1 + github.com/anchore/syft v1.52.0 github.com/bmatcuk/doublestar/v4 v4.10.0 github.com/santhosh-tekuri/jsonschema/v6 v6.0.3 ) @@ -86,12 +86,12 @@ require ( cel.dev/expr v0.25.2 // indirect cloud.google.com/go v0.123.0 // indirect - cloud.google.com/go/auth v0.22.0 // indirect + cloud.google.com/go/auth v0.23.2 // indirect cloud.google.com/go/auth/oauth2adapt v0.2.8 // indirect cloud.google.com/go/compute/metadata v0.9.0 // indirect - cloud.google.com/go/iam v1.11.0 // indirect - cloud.google.com/go/monitoring v1.29.0 // indirect - cloud.google.com/go/storage v1.64.0 // indirect + cloud.google.com/go/iam v1.12.0 // indirect + cloud.google.com/go/monitoring v1.30.0 // indirect + cloud.google.com/go/storage v1.65.1 // indirect dario.cat/mergo v1.0.2 // indirect github.com/BurntSushi/toml v1.6.0 // indirect github.com/DataDog/zstd v1.5.7 // indirect @@ -111,28 +111,28 @@ github.com/anchore/go-macholibre v0.1.1 // indirect github.com/anchore/go-rpmdb v0.2.0 // indirect github.com/anchore/go-struct-converter v0.2.0-rc2 // indirect - github.com/anchore/go-sync v0.1.1 // indirect + github.com/anchore/go-sync v0.1.2 // indirect github.com/andybalholm/brotli v1.2.0 // indirect github.com/apparentlymart/go-textseg/v15 v15.0.0 // indirect github.com/aquasecurity/go-version v0.0.1 // indirect - github.com/aws/aws-sdk-go-v2 v1.43.4 // indirect - github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.16 // indirect - github.com/aws/aws-sdk-go-v2/config v1.32.35 // indirect - github.com/aws/aws-sdk-go-v2/credentials v1.19.34 // indirect - github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.35 // indirect - github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.35 // indirect - github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.35 // indirect - github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.36 // indirect - github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.15 // indirect - github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.28 // indirect - github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.35 // indirect - github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.36 // indirect - github.com/aws/aws-sdk-go-v2/service/s3 v1.106.5 // indirect - github.com/aws/aws-sdk-go-v2/service/signin v1.5.4 // indirect - github.com/aws/aws-sdk-go-v2/service/sso v1.33.4 // indirect - github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.4 // indirect - github.com/aws/aws-sdk-go-v2/service/sts v1.45.4 // indirect - github.com/aws/smithy-go v1.27.6 // indirect + github.com/aws/aws-sdk-go-v2 v1.44.0 // indirect + github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.20 // indirect + github.com/aws/aws-sdk-go-v2/config v1.32.40 // indirect + github.com/aws/aws-sdk-go-v2/credentials v1.19.39 // indirect + github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.40 // indirect + github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.40 // indirect + github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.40 // indirect + github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.41 // indirect + github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.19 // indirect + github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.10.0 // indirect + github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.40 // indirect + github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.41 // indirect + github.com/aws/aws-sdk-go-v2/service/s3 v1.108.0 // indirect + github.com/aws/aws-sdk-go-v2/service/signin v1.6.0 // indirect + github.com/aws/aws-sdk-go-v2/service/sso v1.34.0 // indirect + github.com/aws/aws-sdk-go-v2/service/ssooidc v1.39.0 // indirect + github.com/aws/aws-sdk-go-v2/service/sts v1.46.0 // indirect + github.com/aws/smithy-go v1.28.1 // indirect github.com/aymanbagabas/go-osc52/v2 v2.0.1 // indirect github.com/bahlo/generic-list-go v0.2.0 // indirect github.com/becheran/wildmatch-go v1.0.0 // indirect @@ -155,7 +155,7 @@ github.com/cncf/xds/go v0.0.0-20260202195803-dba9d589def2 // indirect github.com/containerd/cgroups/v3 v3.1.3 // indirect github.com/containerd/containerd/api v1.11.1 // indirect - github.com/containerd/containerd/v2 v2.3.4 // indirect + github.com/containerd/containerd/v2 v2.3.5 // indirect github.com/containerd/continuity v0.5.0 // indirect github.com/containerd/errdefs v1.0.0 // indirect github.com/containerd/errdefs/pkg v0.3.0 // indirect @@ -169,7 +169,7 @@ github.com/deitch/magic v0.0.0-20240306090643-c67ab88f10cb // indirect github.com/diskfs/go-diskfs v1.9.4 // indirect github.com/distribution/reference v0.6.0 // indirect - github.com/docker/cli v29.7.2+incompatible // indirect + github.com/docker/cli v29.8.0+incompatible // indirect github.com/docker/docker-credential-helpers v0.9.5 // indirect github.com/docker/go-connections v0.8.1 // indirect github.com/docker/go-units v0.5.0 // indirect @@ -199,9 +199,9 @@ github.com/google/licensecheck v0.3.1 // indirect github.com/google/pprof v0.0.0-20260802141513-ef3492d7dac3 // indirect github.com/google/s2a-go v0.1.9 // indirect - github.com/googleapis/enterprise-certificate-proxy v0.3.19 // indirect - github.com/googleapis/gax-go/v2 v2.23.0 // indirect - github.com/gpustack/gguf-parser-go v0.25.0 // indirect + github.com/googleapis/enterprise-certificate-proxy v0.3.20 // indirect + github.com/googleapis/gax-go/v2 v2.24.0 // indirect + github.com/gpustack/gguf-parser-go v0.26.3 // indirect github.com/hashicorp/aws-sdk-go-base/v2 v2.0.0-beta.74 // indirect github.com/hashicorp/errwrap v1.1.0 // indirect github.com/hashicorp/go-version v1.9.0 // indirect @@ -236,8 +236,8 @@ github.com/mitchellh/reflectwalk v1.0.2 // indirect github.com/moby/docker-image-spec v1.3.1 // indirect github.com/moby/locker v1.0.1 // indirect - github.com/moby/moby/api v1.55.0 // indirect - github.com/moby/moby/client v0.5.1 // indirect + github.com/moby/moby/api v1.56.0 // indirect + github.com/moby/moby/client v0.6.0 // indirect github.com/moby/sys/atomicwriter v0.1.0 // indirect github.com/moby/sys/mountinfo v0.7.2 // indirect github.com/moby/sys/sequential v0.6.0 // indirect @@ -320,8 +320,8 @@ go.yaml.in/yaml/v3 v3.0.5 // indirect go.yaml.in/yaml/v4 v4.0.0-rc.2 // indirect go4.org v0.0.0-20230225012048-214862532bf5 // indirect - golang.org/x/crypto v0.55.0 // indirect - golang.org/x/mod v0.40.0 // indirect + golang.org/x/crypto v0.56.0 // indirect + golang.org/x/mod v0.41.0 // indirect golang.org/x/net v0.58.0 // indirect golang.org/x/oauth2 v0.36.0 // indirect golang.org/x/sync v0.22.0 // indirect @@ -329,16 +329,16 @@ golang.org/x/term v0.45.0 // indirect golang.org/x/xerrors v0.0.0-20240903120638-7835f813f4da // indirect gonum.org/v1/gonum v0.17.0 // indirect - google.golang.org/api v0.292.0 // indirect - google.golang.org/genproto v0.0.0-20260519071638-aa98bba5eb94 // indirect - google.golang.org/genproto/googleapis/api v0.0.0-20260630182238-925bb5da69e7 // indirect - google.golang.org/genproto/googleapis/rpc v0.0.0-20260803160001-6ac0973c030d // indirect - google.golang.org/grpc v1.83.0 // indirect - google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af // indirect + google.golang.org/api v0.294.0 // indirect + google.golang.org/genproto v0.0.0-20260715232425-e75dac1f907d // indirect + google.golang.org/genproto/googleapis/api v0.0.0-20260715232425-e75dac1f907d // indirect + google.golang.org/genproto/googleapis/rpc v0.0.0-20260819154853-08b0e4226688 // indirect + google.golang.org/grpc v1.83.2 // indirect + google.golang.org/protobuf v1.36.12 // indirect gopkg.in/warnings.v0 v0.1.2 // indirect howett.net/plist v1.0.1 // indirect - modernc.org/libc v1.74.4 // indirect + modernc.org/libc v1.75.6 // indirect modernc.org/mathutil v1.7.1 // indirect - modernc.org/memory v1.11.0 // indirect - modernc.org/sqlite v1.56.0 // indirect + modernc.org/memory v1.12.1 // indirect + modernc.org/sqlite v1.58.0 // indirect ) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/go.sum new/grype-0.119.0/go.sum --- old/grype-0.118.0/go.sum 2026-08-27 20:40:29.000000000 +0200 +++ new/grype-0.119.0/go.sum 2026-09-17 17:25:25.000000000 +0200 @@ -31,8 +31,8 @@ cloud.google.com/go v0.99.0/go.mod h1:w0Xx2nLzqWJPuozYQX+hFfCSI8WioryfRDzkoI/Y2ZA= cloud.google.com/go v0.123.0 h1:2NAUJwPR47q+E35uaJeYoNhuNEM9kM8SjgRgdeOJUSE= cloud.google.com/go v0.123.0/go.mod h1:xBoMV08QcqUGuPW65Qfm1o9Y4zKZBpGS+7bImXLTAZU= -cloud.google.com/go/auth v0.22.0 h1:Xp9wAKkLoeaYb5pYZZoQGz4E9sdPxIbzS3gywZE3ciQ= -cloud.google.com/go/auth v0.22.0/go.mod h1:M9o2Oz+YI2jAfxewJgb1vyI3vceHF+eohmxyzmrl+9s= +cloud.google.com/go/auth v0.23.2 h1:pxSCpfiji41hpzpPdMCftEUCezpgpqmmDdYiAjCKXxo= +cloud.google.com/go/auth v0.23.2/go.mod h1:4DhBRcqvtljQN3dJ57qtqbib5ZGCYE5f2crfiiC2EM0= cloud.google.com/go/auth/oauth2adapt v0.2.8 h1:keo8NaayQZ6wimpNSmW5OPc283g65QNIiLpZnkHRbnc= cloud.google.com/go/auth/oauth2adapt v0.2.8/go.mod h1:XQ9y31RkqZCcwJWNSx2Xvric3RrU88hAYYbjDWYDL+c= cloud.google.com/go/bigquery v1.0.1/go.mod h1:i/xbL2UlR5RvWAURpBYZTtm/cXjCha9lbfbpx4poX+o= @@ -46,14 +46,14 @@ cloud.google.com/go/datastore v1.0.0/go.mod h1:LXYbyblFSglQ5pkeyhO+Qmw7ukd3C+pD7TKLgZqpHYE= cloud.google.com/go/datastore v1.1.0/go.mod h1:umbIZjpQpHh4hmRpGhH4tLFup+FVzqBi1b3c64qFpCk= cloud.google.com/go/firestore v1.6.1/go.mod h1:asNXNOzBdyVQmEU+ggO8UPodTkEVFW5Qx+rwHnAz+EY= -cloud.google.com/go/iam v1.11.0 h1:KieQ9Pb+LLPak1O3Rv3GgCxhnmkYf7Xyh0P5HfF1jFM= -cloud.google.com/go/iam v1.11.0/go.mod h1:KP+nKGugNJW4LcLx1uEZcq1ok5sQHFaQehQNl4QDgV4= -cloud.google.com/go/logging v1.18.0 h1:KhzZq+1cSkPH9YUaKLLhLtQxIHitVayBmk0sGfoM9+k= -cloud.google.com/go/logging v1.18.0/go.mod h1:ZGKnpBaURITh+g/uom2VhbiFoFWvejcrHPDhxFtU/gI= +cloud.google.com/go/iam v1.12.0 h1:Aki3bX9aHUDKPHfnRJfDcTdVedvy6quGBQcTqx3DRXk= +cloud.google.com/go/iam v1.12.0/go.mod h1:FEZ4lXpADAC2AIpQY7LANNjjwyQ2jK439CI2VaD+sLY= +cloud.google.com/go/logging v1.19.0 h1:NCqhdVUg3wQ8Cobdf16FDSuTGi3+6+hdSBHrY5TsR6Q= +cloud.google.com/go/logging v1.19.0/go.mod h1:i40NZCHC9Gqvod4yE+yQfDWwlgwW/SrshkkGibCHxcA= cloud.google.com/go/longrunning v1.2.0 h1:WjYH3YHBGCxGJP9M4dWGHBfXr/cFIjMkNgWcJj7/iMM= cloud.google.com/go/longrunning v1.2.0/go.mod h1:5KMQALFGOCtFoi2xSOA1u3H7WKlhmckgiyFw7+LGQp0= -cloud.google.com/go/monitoring v1.29.0 h1:AHhDsFaSax1/4k+qlIDX/SDGe6hggnfXJ9dkgD9qBPY= -cloud.google.com/go/monitoring v1.29.0/go.mod h1:72NOVjJXHY/HBfoLT0+qlCZBT059+9VXLeAnL2PeeVM= +cloud.google.com/go/monitoring v1.30.0 h1:r/d+JUbyKmJ8b07iznuKfzVzrIXTWxHQ3lBRm3x2LlY= +cloud.google.com/go/monitoring v1.30.0/go.mod h1:htlUR0QWVMrjFzZmN4LGnMAve9xB/eduwjmINxVZ8RM= cloud.google.com/go/pubsub v1.0.1/go.mod h1:R0Gpsv3s54REJCy4fxDixWD93lHJMoZTyQ2kNxGRt3I= cloud.google.com/go/pubsub v1.1.0/go.mod h1:EwwdRX2sKPjnvnqCa270oGRyludottCI76h+R3AArQw= cloud.google.com/go/pubsub v1.2.0/go.mod h1:jhfEVHT8odbXTkndysNHCcx0awwzvfOlguIAii9o8iA= @@ -63,8 +63,8 @@ cloud.google.com/go/storage v1.6.0/go.mod h1:N7U0C8pVQ/+NIKOBQyamJIeKQKkZ+mxpohlUTyfDhBk= cloud.google.com/go/storage v1.8.0/go.mod h1:Wv1Oy7z6Yz3DshWRJFhqM/UCfaWIRTdp0RXyy7KQOVs= cloud.google.com/go/storage v1.10.0/go.mod h1:FLPqc6j+Ki4BU591ie1oL6qBQGu2Bl/tZ9ullr3+Kg0= -cloud.google.com/go/storage v1.64.0 h1:KLpxI/oX9LxeRsNqn877d2WyeT3ryiEwnGt8pwcSPZg= -cloud.google.com/go/storage v1.64.0/go.mod h1:lWyAtwvDZHdL3k68WVKbESP6bmWaV23ZJJ/JEVw/ZaQ= +cloud.google.com/go/storage v1.65.1 h1:LRRpBJUTf+OXDPX9jZUKZ3mSLIsz3htG+qUpeNZovyA= +cloud.google.com/go/storage v1.65.1/go.mod h1:UsS9OgFg/XHOSYakQ8ZtLWWeyGkk1WnmD/GsGfN0BHM= cloud.google.com/go/trace v1.16.0 h1:GmQovzFc5F0CNfl0VLgL64aoTtu7xsM0YajW2GlG9+E= cloud.google.com/go/trace v1.16.0/go.mod h1:r+bdAn16dKLSV1G2D5v3e58IlQlizfxWrUfjx7kM7X0= dario.cat/mergo v1.0.2 h1:85+piFYR1tMbRrLcDwR18y4UKJ3aH1Tbzi24VRW1TK8= @@ -79,8 +79,8 @@ github.com/BurntSushi/toml v1.6.0 h1:dRaEfpa2VI55EwlIW72hMRHdWouJeRF7TPYhI+AUQjk= github.com/BurntSushi/toml v1.6.0/go.mod h1:ukJfTF/6rtPPRCnwkur4qwRxa8vTRFBF0uk2lLoLwho= github.com/BurntSushi/xgb v0.0.0-20160522181843-27f122750802/go.mod h1:IVnqGOEym/WlBOVXweHU+Q+/VP0lqqI8lqeDx9IjBqo= -github.com/CycloneDX/cyclonedx-go v0.11.0 h1:GokP8FiRC+foiuwWhSSLpSD5H4hSWtGnR3wo7apkBFI= -github.com/CycloneDX/cyclonedx-go v0.11.0/go.mod h1:vUvbCXQsEm48OI6oOlanxstwNByXjCZ2wuleUlwGEO8= +github.com/CycloneDX/cyclonedx-go v0.12.0 h1:/7Jum36UA6V043tQZ/fE3jf+Nf9gn/qxUFfd7QReMy8= +github.com/CycloneDX/cyclonedx-go v0.12.0/go.mod h1:V2577HhxDDCDLYfkm55WJrz16nHTfyQZwcWUBSG7Z28= github.com/DataDog/datadog-go v3.2.0+incompatible/go.mod h1:LButxg5PwREeZtORoXG3tL4fMGNddJ+vMq1mwgfaqoQ= github.com/DataDog/zstd v1.5.7 h1:ybO8RBeh29qrxIhCA9E8gKY6xfONU9T6G6aP9DTKfLE= github.com/DataDog/zstd v1.5.7/go.mod h1:g4AWEaM3yOg3HYfnJ3YIawPnVdXJh9QME85blwSAmyw= @@ -146,16 +146,16 @@ github.com/anchore/go-rpmdb v0.2.0/go.mod h1:ATsRlpCXstnoYfzqBfhwGw0U2dolx1BBQ9rAU8jWBAw= github.com/anchore/go-struct-converter v0.2.0-rc2 h1:q+859fW2/jbHJHB2etbNfRlFwYpknyvbqqk1hUdamQ4= github.com/anchore/go-struct-converter v0.2.0-rc2/go.mod h1:cDBA5vhcR62nXWo8QH9/Kk2807o65ISaHPNPX66L+Uw= -github.com/anchore/go-sync v0.1.1 h1:91SZ+YqUIIHmf2jPAYZPuHqM/ZqnK1pVJDWtET6+AJE= -github.com/anchore/go-sync v0.1.1/go.mod h1:3haGsk2BnaoVhsfqae8Kd0FKIAILE1Hw69P4Xo5iVBw= +github.com/anchore/go-sync v0.1.2 h1:RDD5RCanrWqhbtBulqPSZpERadUlgcYjpybYzYd3Uk8= +github.com/anchore/go-sync v0.1.2/go.mod h1:grjZH059bCHM6f6jh+Y7VYvX/q8YcjkDJqG6nplHGkE= github.com/anchore/go-version v1.2.2-0.20210903204242-51efa5b487c4 h1:rmZG77uXgE+o2gozGEBoUMpX27lsku+xrMwlmBZJtbg= github.com/anchore/go-version v1.2.2-0.20210903204242-51efa5b487c4/go.mod h1:Bkc+JYWjMCF8OyZ340IMSIi2Ebf3uwByOk6ho4wne1E= github.com/anchore/packageurl-go v0.2.0 h1:CkrM4RMUwrEGAiE1OVlxaZNzWj0TuHRey7o4T/EAErk= github.com/anchore/packageurl-go v0.2.0/go.mod h1:2JCgOQMIsqZ7TmliXG4PnUthPJAKE3mWQbsW2XHjAOE= -github.com/anchore/stereoscope v0.3.1 h1:SFLeRyi+3L0fVDTcd4sjT6Xalvi9pju7DegeUMmxna8= -github.com/anchore/stereoscope v0.3.1/go.mod h1:KHLeUz03/lpsxM8jvs7gFSWRHCXB9MLnxpusCIPe3ME= -github.com/anchore/syft v1.51.1 h1:H/a0/Cw5Y3Nsa8/XFupCMcrLsF/5KnMYw/gzGVPRgmM= -github.com/anchore/syft v1.51.1/go.mod h1:pv0fzHqh1+8hKecHHE68KXiGiZQ0i/UHyH3+4lZ+vPU= +github.com/anchore/stereoscope v0.3.2 h1:A2FDMSU56m3rErO1e0CtWAVcDS8tc2iX4UXTw1hyPnI= +github.com/anchore/stereoscope v0.3.2/go.mod h1:/IUDVDka+4gufc8kDw+JO3gFl9PkpCjJ2r3bd9UWouM= +github.com/anchore/syft v1.52.0 h1:BelCbd0Q3grSbtoLgNJ0cx/r/Gd1Jj7t11dp91eXd1Y= +github.com/anchore/syft v1.52.0/go.mod h1:N9d70RgFm2/yVtA/EZTaeKQ/qw9oOrmfRXnFy/QV+VE= github.com/andreyvit/diff v0.0.0-20170406064948-c7f18ee00883/go.mod h1:rCTlJbsFo29Kk6CurOXKm700vrz8f0KW0JNfpkRJY/8= github.com/andybalholm/brotli v1.2.0 h1:ukwgCxwYrmACq68yiUqwIWnGY0cTPox/M94sVwToPjQ= github.com/andybalholm/brotli v1.2.0/go.mod h1:rzTDkvFWvIrjDXZHkuS16NPggd91W3kUSvPlQ1pLaKY= @@ -179,42 +179,42 @@ github.com/armon/go-socks5 v0.0.0-20160902184237-e75332964ef5/go.mod h1:wHh0iHkYZB8zMSxRWpUBQtwG5a7fFgvEO+odwuTv2gs= github.com/atotto/clipboard v0.1.4 h1:EH0zSVneZPSuFR11BlR9YppQTVDbh5+16AmcJi4g1z4= github.com/atotto/clipboard v0.1.4/go.mod h1:ZY9tmq7sm5xIbd9bOK4onWV4S6X0u6GY7Vn0Yu86PYI= -github.com/aws/aws-sdk-go-v2 v1.43.4 h1:b9FTvbRwy+JCsfp2Wp6wV/KbOx3Aj7nkoFb2cRX0IhE= -github.com/aws/aws-sdk-go-v2 v1.43.4/go.mod h1:70vwSy16txshwG+g55WkpgPKDIByzHI8ccBsOteo3bQ= -github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.16 h1:aiuaKlDweRC5qExJondpWjOgyzMHpofpwspGXUtwn4c= -github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.16/go.mod h1:nG/LOlmox9BDe9HvQnXWzgcK8uKbgBMZ/Hp5pVt/21I= -github.com/aws/aws-sdk-go-v2/config v1.32.35 h1:UEzXuET8E42lxBPijuACu/tEK7v5lFPlk0Q+GT5WD9E= -github.com/aws/aws-sdk-go-v2/config v1.32.35/go.mod h1:KaMtJpFa2JlL2BStjjHQVwQpzZEmw+ND/EgVrfFoo2g= -github.com/aws/aws-sdk-go-v2/credentials v1.19.34 h1:y6GkSmcv5myd1ngrYbGmiLlwQqB6TQhOuN/tbSSuWDY= -github.com/aws/aws-sdk-go-v2/credentials v1.19.34/go.mod h1:w3dTcnDVoQIewjo7JG45hduAToikiIFLC4FIO7fndvw= -github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.35 h1:+S7kbJoLDDQ5tE+lHrUBgMkzC8NLgsaioS2F3dVoFAE= -github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.35/go.mod h1:Ak7xXviIARfFdNUJ9Etb0bdVDt/KAvKjMGJVLWXDzik= -github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.35 h1:kzVuGlatQtYinwBJEEyLAbggepCoavosiaHHX9+fD+c= -github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.35/go.mod h1:0yLx0yEI+SfqeJMPvOtIEFoZbiQYXMGszBueiutQyaI= -github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.35 h1:WK6CjihTuLisCjSKKbildJ79sGZZgbBz3iNa7VsKIhU= -github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.35/go.mod h1:KYleN57luLoe97R7vTnx8PMcVrr9gAcRECtOjl91DNg= -github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.36 h1:jbGY4CXLzZElOXgGsexlC3Hi+3YM0rSmk4opFXKqg/k= -github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.36/go.mod h1:uBu/9aKsS/UQGc72RAt3y54kjgYQxmhut8ZD2dXCDNE= -github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.15 h1:JJLBQxwY+AFwuPAi5ivGc1ChnTdUt4cXMv7e76m2c/Y= -github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.15/go.mod h1:lQknBIe78MVL0cQOQDlag8KGflMbMEVFx9mB6O8ENvk= -github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.28 h1:Q1TF1J9jVD+vFo0LzNnmNdQ9EAt52TS+MQlq9Ir+Yxo= -github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.28/go.mod h1:4KqXXC/p1hrotmouDFbrRoWaLy962b9PMUReCG6+uWo= -github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.35 h1:BBEElKh4a+rKshvjrfpajTe9CbpZvrbb4Jkg2PB7RzA= -github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.35/go.mod h1:zaZk983w//8beSruBVec/mr4CmDwgZitW/qzGhAAX0g= -github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.36 h1:EUIwBoN+q7UmhAejxgD27APiRjh1vwCFo53gSqdT0BM= -github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.36/go.mod h1:6u00gmlTGR6W0b2k9NBrld7MnOEmf1Spqx0VVt6AqyE= -github.com/aws/aws-sdk-go-v2/service/s3 v1.106.5 h1:HpN6GgZ3T8pSvRp81ZsgumNjlvRsa+9M0ZL2o6W4uLY= -github.com/aws/aws-sdk-go-v2/service/s3 v1.106.5/go.mod h1:5FTZoQxhmLEiCAtYVk6V+t0iS/B5yGZVLZ3Wq5FDJZI= -github.com/aws/aws-sdk-go-v2/service/signin v1.5.4 h1:cOJELVNrq5Q3Udry2GLuHUM7MhwpeaQRdYaoa6GI/yI= -github.com/aws/aws-sdk-go-v2/service/signin v1.5.4/go.mod h1:f4LxzKBtaTxD7xh3PiVg3CE1tchQemfmghaJr+NbK2c= -github.com/aws/aws-sdk-go-v2/service/sso v1.33.4 h1:AMW7a7S8iQaHjBYZdU3PCq4GKRPijTPRAc7e6XtEThY= -github.com/aws/aws-sdk-go-v2/service/sso v1.33.4/go.mod h1:QQNsFV1DVXoXcZt18FS8lI8rtUrlDyAuWZLQ5shunv4= -github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.4 h1:AsbZcJAQPRmHDJG8K1N0pof/1zPWjVT8TFlTWuGLSvo= -github.com/aws/aws-sdk-go-v2/service/ssooidc v1.38.4/go.mod h1:6imqztH0//t0mKbl6yWl7swSEl7F/w32oAmqB3vP1ag= -github.com/aws/aws-sdk-go-v2/service/sts v1.45.4 h1:w/AryDYMjSUANSQ2uoZxJovUsMTwWJNTv3IMex30Y+4= -github.com/aws/aws-sdk-go-v2/service/sts v1.45.4/go.mod h1:WeBiAa67azG7Su9Vf+ChGDBLiAozJCXzdjXiPBUwtbc= -github.com/aws/smithy-go v1.27.6 h1:0zjT8jgK3jbrTT7JJ3EE6JsMhX8JTrZ+f1sEndYDXrA= -github.com/aws/smithy-go v1.27.6/go.mod h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc= +github.com/aws/aws-sdk-go-v2 v1.44.0 h1:4IbaHhtzy+4h37z4JQyO9a2QsiCml3CNYHtq5hIHigo= +github.com/aws/aws-sdk-go-v2 v1.44.0/go.mod h1:bttEH6JqnUL8LepvDVfdrds/fZ5bCIxzpe3abyUrhDU= +github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.20 h1:GPRlPwz40I2B2VrBEASOA3Bi77NyeqejNLkifosX0rs= +github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.20/go.mod h1:g7PNzKcsOKWb4fkSRBA7BZVAS6Y8IcxzN+nRohhQ1Q8= +github.com/aws/aws-sdk-go-v2/config v1.32.40 h1:lAVC9gMmKusmqDRe32dPtgKl/BWvJmMJoWELKHCAObw= +github.com/aws/aws-sdk-go-v2/config v1.32.40/go.mod h1:8xOJLbe/hOj1g4PVsfJYV7O2byq+UGET1onDdUgbwqc= +github.com/aws/aws-sdk-go-v2/credentials v1.19.39 h1:XOg8LC3Kgnsa3WiPQjc7Bi8k5IBN92cPYfIV9XMFss0= +github.com/aws/aws-sdk-go-v2/credentials v1.19.39/go.mod h1:GonTDBQ+mTpCVNwaHjj0PagspfrYYMEqOx7FehoEP/I= +github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.40 h1:r5aGipEVgI9aT/tAGjdrPbDQvIAKdTrS3rUPQtG4Rmo= +github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.40/go.mod h1:vOD3CnPxAdkL6MWZeROkZsTlskklMFfgVFkHzx/oZpY= +github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.40 h1:UIXlbijuB2XK1Kr57fo8iIxCuaSHJzwZ1uo+2tbEYIk= +github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.40/go.mod h1:wcEsL6jscjZjVUinb0Q5qD/GXOG1yT3GNfmT9HuDwzU= +github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.40 h1:xLQVRDs2NddDmK9BEyh5KSlJ1Gpy5/GIJXrV6WcVGAE= +github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.40/go.mod h1:XRXnpFVFGLaEVK+olDdFIM1vNa04ETW452oFGEPUxAo= +github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.41 h1:nv/ILuCY0yXACzMQwvtt/HbqDDjemZiI0AeDbxGQlnU= +github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.41/go.mod h1:dzvOSpxaPqQ3j0xS6Lc1vyVuWW0RBj7s/QqYpzu3Q/0= +github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.19 h1:bAdDl/HkGCcGPoe25ToSHEw23VIxt6CT5fLcg111BKg= +github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.19/go.mod h1:KaUzbLxv4CeSxh6ZCl9B4m7CuFenS8kUEaDs+f/DQr4= +github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.10.0 h1:U8/A0RRBaEspzH1uul3JHLbypXwEGUkRkvoT9f0ATcM= +github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.10.0/go.mod h1:UELStX5KwtJNtQxa+UuF8dc3z4UYc40e8yHYJSozNwY= +github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.40 h1:gr3Fw1cxZXNCdeo/lQ7isHEHzvHVM7z75qb2zW9aMjw= +github.com/aws/aws-sdk-go-v2/service/internal/presigned-url v1.13.40/go.mod h1:8z/9CmfnQhiuXD7Ykbcg4a/whSWsniE0ODSx9uwVzfk= +github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.41 h1:Q9DIKDuJix/oJnQxFpQ26L0EwVa/YNo4k2kbktrjQjE= +github.com/aws/aws-sdk-go-v2/service/internal/s3shared v1.19.41/go.mod h1:x+TuqkOIG1SZS0+yN54sExGA9ZpjhPO6vPdYnpTFX1M= +github.com/aws/aws-sdk-go-v2/service/s3 v1.108.0 h1:Yp+x5PKXEmoqHsgP/pAkBy5Tyq1UlXAzM0OInh0vxWw= +github.com/aws/aws-sdk-go-v2/service/s3 v1.108.0/go.mod h1:locV6DtXyp7Xzr2BG6jtsbeBi3YAWJ/CY4xUThYmIwQ= +github.com/aws/aws-sdk-go-v2/service/signin v1.6.0 h1:agcr0j8YeFEzdXNo17Rg9MbbjLRjrimabwNtji4e+lU= +github.com/aws/aws-sdk-go-v2/service/signin v1.6.0/go.mod h1:qU5PxgQ4JiUOOMotzfO3+5oUda5W+8JDVKyLQqlrJik= +github.com/aws/aws-sdk-go-v2/service/sso v1.34.0 h1:FxaN8/sn61DTXNI6Gt678tFJUY8iUsCchm6Y/F/RjaA= +github.com/aws/aws-sdk-go-v2/service/sso v1.34.0/go.mod h1:vu4OY6s8LJtT8BtYG2LD6BGSZMptkYn3o5hvCPB22jc= +github.com/aws/aws-sdk-go-v2/service/ssooidc v1.39.0 h1:crWKPeGYTBTuBxQ3p73kjfJvt4brUIsr+Fuypko8FxY= +github.com/aws/aws-sdk-go-v2/service/ssooidc v1.39.0/go.mod h1:HjjZVhaBz0JBR/kbWKThmNDhFKS7y6EURuk493tJk9Y= +github.com/aws/aws-sdk-go-v2/service/sts v1.46.0 h1:IZ63JdogSNNjex/jsODNv7jGDcO/xJYd9FsgyfCsp1g= +github.com/aws/aws-sdk-go-v2/service/sts v1.46.0/go.mod h1:I+rwAf3spG5dITBaAo3xXRowk8kiOhtU1kYxfvCTC44= +github.com/aws/smithy-go v1.28.1 h1:R/nXH00c8qcfCzQVELtRw+eLQWtzv+VAIEFJ1/xxXlQ= +github.com/aws/smithy-go v1.28.1/go.mod h1:YE2RhdIuDbA5E5bTdciG9KrW3+TiEONeUWCqxX9i1Fc= github.com/aymanbagabas/go-osc52/v2 v2.0.1 h1:HwpRHbFMcZLEVr42D4p7XBqjyuxQH5SMiErDT4WkJ2k= github.com/aymanbagabas/go-osc52/v2 v2.0.1/go.mod h1:uYgXzlJ7ZpABp8OJ+exZzJJhRNQ2ASbcXHWsFqH8hp8= github.com/bahlo/generic-list-go v0.2.0 h1:5sz/EEAK+ls5wF+NeqDpk5+iNdMDXrh3z3nPnH1Wvgk= @@ -304,8 +304,8 @@ github.com/containerd/cgroups/v3 v3.1.3/go.mod h1:PKZ2AcWmSBsY/tJUVhtS/rluX0b1uq1GmPO1ElCmbOw= github.com/containerd/containerd/api v1.11.1 h1:h8nfoDW9+fNsC/9TwiAHj8B1GzXKtR4eFtkhi/X5RLU= github.com/containerd/containerd/api v1.11.1/go.mod h1:CaQFRu+N1MtbgL6JDOJLUB1hCKESU1lD6MuTJhgtdlw= -github.com/containerd/containerd/v2 v2.3.4 h1:c2PJo/9UGVdiiw8SwrxuLxWGY+9b3jQ6Xp9zntneIvI= -github.com/containerd/containerd/v2 v2.3.4/go.mod h1:a30D8fWZJ1Uzx/2WpjLbLsxBkq9He41pe8ENW+QZ3LY= +github.com/containerd/containerd/v2 v2.3.5 h1:9MYlI81gUcOZ0WsCkSMtvOU7rTR3hqAoa2eCzhoLlkA= +github.com/containerd/containerd/v2 v2.3.5/go.mod h1:RXDyLPaI3zoO7dFdAW9/54W4cix+z3A6larieufC9mg= github.com/containerd/continuity v0.5.0 h1:7a85HZpCSs+1Zps0Ee3DPSuAWY+0SJM1JNM51nlEVDg= github.com/containerd/continuity v0.5.0/go.mod h1:/lNJvtJKUQStBzpVQ1+rasXO1LAWtUQssk28EZvJ3nE= github.com/containerd/errdefs v1.0.0 h1:tg5yIfIlQIrxYtu9ajqY42W3lpS19XqdxRQeEwYG8PI= @@ -348,8 +348,8 @@ github.com/djherbis/times v1.6.0/go.mod h1:gOHeRAz2h+VJNZ5Gmc/o7iD9k4wW7NMVqieYCY99oc0= github.com/dlclark/regexp2 v1.11.0 h1:G/nrcoOa7ZXlpoa/91N3X7mM3r8eIlMBBJZvsz/mxKI= github.com/dlclark/regexp2 v1.11.0/go.mod h1:DHkYz0B9wPfa6wondMfaivmHpzrQ3v9q8cnmRbL6yW8= -github.com/docker/cli v29.7.2+incompatible h1:dlkwallR8XqfeVnA2ELEhdwvb4lsSwuB4IgsG8Q9cLY= -github.com/docker/cli v29.7.2+incompatible/go.mod h1:JLrzqnKDaYBop7H2jaqPtU4hHvMKP+vjCwu2uszcLI8= +github.com/docker/cli v29.8.0+incompatible h1:ih0c2jq/nN7QfES8zIfwSzIhRScjs4ehER+kZ60aeSk= +github.com/docker/cli v29.8.0+incompatible/go.mod h1:JLrzqnKDaYBop7H2jaqPtU4hHvMKP+vjCwu2uszcLI8= github.com/docker/docker v28.5.2+incompatible h1:DBX0Y0zAjZbSrm1uzOkdr1onVghKaftjlSWt4AFexzM= github.com/docker/docker v28.5.2+incompatible/go.mod h1:eEKB0N0r5NX/I1kEveEz05bcu8tLC/8azJZsviup8Sk= github.com/docker/docker-credential-helpers v0.9.5 h1:EFNN8DHvaiK8zVqFA2DT6BjXE0GzfLOZ38ggPTKePkY= @@ -525,8 +525,8 @@ github.com/google/go-cmp v0.5.9/go.mod h1:17dUlkBOakJ0+DkrSSNjCkIjxS6bF9zb3elmeNGIjoY= github.com/google/go-cmp v0.7.0 h1:wk8382ETsv4JYUZwIsn6YpYiWiBsYLSJiTsyBybVuN8= github.com/google/go-cmp v0.7.0/go.mod h1:pXiqmnSA92OHEEa9HXL2W4E7lf9JzCmGVUdgjX3N/iU= -github.com/google/go-containerregistry v0.21.9 h1:F+D4uZ3iA3DLMJLfhaqMdHJbzeqm/216WGQq2dokuLs= -github.com/google/go-containerregistry v0.21.9/go.mod h1:dP5XNKcL7kMFF/TB3LfvWmVhAcv7iqkHb3oDK8aauTo= +github.com/google/go-containerregistry v0.22.1 h1:RZuuSYhTvlDvtsK+NkutoCZ//C0X2ebLK8X8l3ULs84= +github.com/google/go-containerregistry v0.22.1/go.mod h1:bJR35SK8XgisYmhg/FMQ/5RK0S/XrOAqLBV5/LR2XE0= github.com/google/gofuzz v1.0.0/go.mod h1:dBl0BpW6vV/+mYPU4Po3pmUjxk6FQPldtuIdl/M65Eg= github.com/google/licensecheck v0.3.1 h1:QoxgoDkaeC4nFrtGN1jV7IPmDCHFNIVh54e5hSt6sPs= github.com/google/licensecheck v0.3.1/go.mod h1:ORkR35t/JjW+emNKtfJDII0zlciG9JgbT7SmsohlHmY= @@ -563,21 +563,21 @@ github.com/google/uuid v1.1.2/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo= github.com/google/uuid v1.6.0 h1:NIvaJDMOsjHA8n1jAhLSgzrAzy1Hgr+hNrb57e+94F0= github.com/google/uuid v1.6.0/go.mod h1:TIyPZe4MgqvfeYDBFedMoGGpEw/LqOeaOT+nhxU+yHo= -github.com/googleapis/enterprise-certificate-proxy v0.3.19 h1:mMOE7DN2+p76/EdIrmAy9B9bH+yC4563vmnJ34QR8i4= -github.com/googleapis/enterprise-certificate-proxy v0.3.19/go.mod h1:rSEsBUemEBZEexP2y6jPp16LUmUbjmSbcPMQizR0o4k= +github.com/googleapis/enterprise-certificate-proxy v0.3.20 h1:t/xL64VUoN69MuMRQuJETqYGOw4Z9mSRJK9epIEtwFk= +github.com/googleapis/enterprise-certificate-proxy v0.3.20/go.mod h1:L3D/IQExI6LqEjBdXcZQ1WluSgigQmSwBboFstVPM4w= github.com/googleapis/gax-go/v2 v2.0.4/go.mod h1:0Wqv26UfaUD9n4G6kQubkQ+KchISgw+vpHVxEJEs9eg= github.com/googleapis/gax-go/v2 v2.0.5/go.mod h1:DWXyrwAJ9X0FpwwEdw+IPEYBICEFu5mhpdKc/us6bOk= github.com/googleapis/gax-go/v2 v2.1.0/go.mod h1:Q3nei7sK6ybPYH7twZdmQpAd1MKb7pfu6SK+H1/DsU0= github.com/googleapis/gax-go/v2 v2.1.1/go.mod h1:hddJymUZASv3XPyGkUpKj8pPO47Rmb0eJc8R6ouapiM= -github.com/googleapis/gax-go/v2 v2.23.0 h1:Tchl7qkvE7Ip3y+ztvNufYFvkfqTe7NfLTYGIdJRLuE= -github.com/googleapis/gax-go/v2 v2.23.0/go.mod h1:rBQKOVJCdb8IFEzg+FCwlt1LP/xMDGuqUXhUG+XMXEg= +github.com/googleapis/gax-go/v2 v2.24.0 h1:myMaPYyF9MecEmvQqMqomIwn9t/4KCZN9qnwsS76wlg= +github.com/googleapis/gax-go/v2 v2.24.0/go.mod h1:IaTHBDd7NHxSCiu0vEs8pQZu4dGZrWwuSoxCnk16OFM= github.com/gookit/assert v0.1.1 h1:lh3GcawXe/p+cU7ESTZ5Ui3Sm/x8JWpIis4/1aF0mY0= github.com/gookit/assert v0.1.1/go.mod h1:jS5bmIVQZTIwk42uXl4lyj4iaaxx32tqH16CFj0VX2E= github.com/gookit/color v1.2.5/go.mod h1:AhIE+pS6D4Ql0SQWbBeXPHw7gY0/sjHoA4s/n1KB7xg= github.com/gookit/color v1.6.1 h1:KoTnDxJPRgrL0SoX0f8rCFg2zI0t4E3GZZBMo2nN8LU= github.com/gookit/color v1.6.1/go.mod h1:9ACFc7/1IpHGBW8RwuDm/0YEnhg3dwwXpoMsmtyHfjs= -github.com/gpustack/gguf-parser-go v0.25.0 h1:1AMBhMKtI24nTtn588Bq53FqNiOvEw1x9Nb4HbRrThs= -github.com/gpustack/gguf-parser-go v0.25.0/go.mod h1:y4TwTtDqFWTK+xvprOjRUh+dowgU2TKCX37vRKvGiZ0= +github.com/gpustack/gguf-parser-go v0.26.3 h1:F63PlUPIW56HGU5k4Crv0JAG9ojtz/TuwzgMYlb82Ec= +github.com/gpustack/gguf-parser-go v0.26.3/go.mod h1:y4TwTtDqFWTK+xvprOjRUh+dowgU2TKCX37vRKvGiZ0= github.com/grpc-ecosystem/grpc-gateway v1.16.0 h1:gmcG1KaJ57LophUzW0Hy8NmPhnMZb4M0+kPpLofRdBo= github.com/grpc-ecosystem/grpc-gateway v1.16.0/go.mod h1:BDjrQk3hbvj6Nolgz8mAMFbcEtjT1g+wF4CSlocrBnw= github.com/grpc-ecosystem/grpc-gateway/v2 v2.28.0 h1:HWRh5R2+9EifMyIHV7ZV+MIZqgz+PMpZ14Jynv3O2Zs= @@ -595,8 +595,8 @@ github.com/hashicorp/go-cleanhttp v0.5.1/go.mod h1:JpRdi6/HCYpAwUzNwuwqhbovhLtngrth3wmdIIUrZ80= github.com/hashicorp/go-cleanhttp v0.5.2 h1:035FKYIWjmULyFRBKPs8TBQoi0x6d9G4xc9neXJWAZQ= github.com/hashicorp/go-cleanhttp v0.5.2/go.mod h1:kO/YDlP8L1346E6Sodw+PrpBSV4/SoxCXGY6BqNFT48= -github.com/hashicorp/go-getter v1.8.8 h1:sRakhf+EH6s0LZLO2IgBwZ6hAFp+fZOZMNREwVELV80= -github.com/hashicorp/go-getter v1.8.8/go.mod h1:fqFlibKpwfns/s4oljLB3upJspyfFLQhS7031PlfUDc= +github.com/hashicorp/go-getter v1.8.9 h1:1AOTMUmz/S/GuqOTE6+bg6nwPXTEbKr3Tc/T/lVS7is= +github.com/hashicorp/go-getter v1.8.9/go.mod h1:qI7vH/m552bXutKe4UkWptOJl4bo2KeO/CSOoh4s0ps= github.com/hashicorp/go-hclog v0.12.0/go.mod h1:whpDNt7SSdeAju8AWKIWsul05p54N/39EeqMAyrmvFQ= github.com/hashicorp/go-hclog v1.0.0/go.mod h1:whpDNt7SSdeAju8AWKIWsul05p54N/39EeqMAyrmvFQ= github.com/hashicorp/go-immutable-radix v1.0.0/go.mod h1:0y9vanUI8NX6FsYoO3zeMjhV/C5i9g4Q3DwcSNZ4P60= @@ -672,8 +672,8 @@ github.com/kisielk/errcheck v1.5.0/go.mod h1:pFxgyoBC7bSaBwPgfKdkLd5X25qrDl4LWUI2bnpBCr8= github.com/kisielk/gotool v1.0.0/go.mod h1:XhKaO+MFFWcvkIS/tQcRk01m1F5IRFswLeQ+oQHNcck= github.com/klauspost/compress v1.4.1/go.mod h1:RyIbtBH6LamlWaDj8nUwkbUhJ87Yi3uG0guNDohfE1A= -github.com/klauspost/compress v1.19.2 h1:hMRETovs/pu/dVWN7zIT1PGG8t509MwT6bO7XSi26R8= -github.com/klauspost/compress v1.19.2/go.mod h1:cwPg85FWrGar70rWktvGQj8/hthj3wpl0PGDogxkrSQ= +github.com/klauspost/compress v1.20.0 h1:a3C1ke2ohxFymNlb2HWAHjDeKCI90scRskErZkR0ezA= +github.com/klauspost/compress v1.20.0/go.mod h1:LUdAzn7YLVvxLpc7y3V1m40wESHTgc1422pwwBSKYuI= github.com/klauspost/cpuid v1.2.0/go.mod h1:Pj4uuM528wm8OyEC2QMXAi2YiTZ96dNQPGgoMS4s3ek= github.com/klauspost/cpuid/v2 v2.3.0 h1:S4CRMLnYUhGeDFDqkGriYKdfoFlDnMtqTiI/sFzhA9Y= github.com/klauspost/cpuid/v2 v2.3.0/go.mod h1:hqwkgyIinND0mEev00jJYCxPNVRVXFQeu1XKlok6oO0= @@ -757,10 +757,10 @@ github.com/moby/docker-image-spec v1.3.1/go.mod h1:eKmb5VW8vQEh/BAr2yvVNvuiJuY6UIocYsFu/DxxRpo= github.com/moby/locker v1.0.1 h1:fOXqR41zeveg4fFODix+1Ch4mj/gT0NE1XJbp/epuBg= github.com/moby/locker v1.0.1/go.mod h1:S7SDdo5zpBK84bzzVlKr2V0hz+7x9hWbYC/kq7oQppc= -github.com/moby/moby/api v1.55.0 h1:2/sexvQyqIWS8pRSCFddBfpW2qE7vR7FCL+vN8pxwMc= -github.com/moby/moby/api v1.55.0/go.mod h1:+RQ6wluLwtYaTd1WnPLykIDPekkuyD/ROWQClE83pzs= -github.com/moby/moby/client v0.5.1 h1:tYNaJno4c0HXz12y5BiqEDy0rVTYkWzI26lGvnTMiJw= -github.com/moby/moby/client v0.5.1/go.mod h1:odLstlZ6uSnfvAgVxMpvgmb8SUdd+siH2T0GBuxVAlM= +github.com/moby/moby/api v1.56.0 h1:GQzua3NA599ASSIICx0iFgiJeO9YkdDARvQsm23ZZuQ= +github.com/moby/moby/api v1.56.0/go.mod h1:sZ+THbVWkjOmBPPfbnzdD/G1LuIexWhqlSHHPTDQ1Uk= +github.com/moby/moby/client v0.6.0 h1:AJjEB21QPbXSXjDsZorFBoDZPhMrfbpaPLgSMAW9Bgs= +github.com/moby/moby/client v0.6.0/go.mod h1:OCo00wNRyA3m4lmJ228W3JbyCN4ZNNYjpOXiJydBdcQ= github.com/moby/sys/atomicwriter v0.1.0 h1:kw5D/EqkBwsBFi0ss9v1VG3wIkVhzGvLklJ+w3A14Sw= github.com/moby/sys/atomicwriter v0.1.0/go.mod h1:Ul8oqv2ZMNHOceF643P6FKPXeCmYtlQMvpizfsSoaWs= github.com/moby/sys/mountinfo v0.7.2 h1:1shs6aH5s4o5H2zQLn796ADW1wMrIwHsyJ2v9KouLrg= @@ -823,8 +823,8 @@ github.com/owenrumney/go-sarif v1.1.2-0.20231003122901-1000f5e05554/go.mod h1:n73K/hcuJ50MiVznXyN4rde6fZY7naGKWBXOLFTyc94= github.com/package-url/packageurl-go v0.1.5 h1:O4efRXja2XQ5CtiiYiCZ22k/m7i5ugLiAghgcC+eDgk= github.com/package-url/packageurl-go v0.1.5/go.mod h1:nKAWB8E6uk1MHqiS/lQb9pYBGH2+mdJ2PJc2s50dQY0= -github.com/pandatix/go-cvss v0.6.2 h1:TFiHlzUkT67s6UkelHmK6s1INKVUG7nlKYiWWDTITGI= -github.com/pandatix/go-cvss v0.6.2/go.mod h1:jDXYlQBZrc8nvrMUVVvTG8PhmuShOnKrxP53nOFkt8Q= +github.com/pandatix/go-cvss v0.6.4 h1:9w2RCO/Q4UTiJyEgpCHRiVc6CfrsFEnkoX+OtATqKio= +github.com/pandatix/go-cvss v0.6.4/go.mod h1:/ukvQnYlrKl3o/DVp7/GO2UZyZheuo/maOK0U1nBEhQ= github.com/pascaldekloe/goe v0.0.0-20180627143212-57f6aae5913c/go.mod h1:lzWF7FIEvWOWxwDKqyGYQf6ZUaNfKdP144TG7ZOy1lc= github.com/pascaldekloe/goe v0.1.0/go.mod h1:lzWF7FIEvWOWxwDKqyGYQf6ZUaNfKdP144TG7ZOy1lc= github.com/pb33f/ordered-map/v2 v2.3.1 h1:5319HDO0aw4DA4gzi+zv4FXU9UlSs3xGZ40wcP1nBjY= @@ -981,8 +981,8 @@ github.com/sylabs/squashfs v1.0.6/go.mod h1:DlDeUawVXLWAsSRa085Eo0ZenGzAB32JdAUFaB0LZfE= github.com/tailscale/hujson v0.0.0-20260302212456-ecc657c15afd h1:Rf9uhF1+VJ7ZHqxrG8pJ6YacmHvVCmByDmGbAWCc/gA= github.com/tailscale/hujson v0.0.0-20260302212456-ecc657c15afd/go.mod h1:EbW0wDK/qEUYI0A5bqq0C2kF8JTQwWONmGDBbzsxxHo= -github.com/terminalstatic/go-xsd-validate v0.1.6 h1:TenYeQ3eY631qNi1/cTmLH/s2slHPRKTTHT+XSHkepo= -github.com/terminalstatic/go-xsd-validate v0.1.6/go.mod h1:18lsvYFofBflqCrvo1umpABZ99+GneNTw2kEEc8UPJw= +github.com/terminalstatic/go-xsd-validate v0.1.8 h1:UVrTCy1j3DhwaYTTUF+QYO/Nan13S0tf+Jwi+p45Bf0= +github.com/terminalstatic/go-xsd-validate v0.1.8/go.mod h1:1kb47fi2c6onlf+B7UrrQ9VYraOhcYwFm3iG+J6F4Zo= github.com/therootcompany/xz v1.0.1 h1:CmOtsn1CbtmyYiusbfmhmkpAAETj0wBIH6kCYaX+xzw= github.com/therootcompany/xz v1.0.1/go.mod h1:3K3UH1yCKgBneZYhuQUvJ9HPD19UEXEI0BWbMn8qNMY= github.com/tidwall/gjson v1.14.2/go.mod h1:/wbyibRr2FHMks5tjHJ5F8dMZh3AcwJEMf5vlfC0lxk= @@ -1107,8 +1107,8 @@ golang.org/x/crypto v0.0.0-20210817164053-32db794688a5/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc= golang.org/x/crypto v0.0.0-20210921155107-089bfa567519/go.mod h1:GvvjBRRGRdwPK5ydBHafDWAxML/pGHZbMvKqRZ5+Abc= golang.org/x/crypto v0.0.0-20220622213112-05595931fe9d/go.mod h1:IxCIyHEi3zRg3s0A5j5BB6A9Jmi73HwBIUl50j+osU4= -golang.org/x/crypto v0.55.0 h1:+KWHjbgOaAQ66dh/YlkZKHlz9ZUlq61AFirAR9ntP8M= -golang.org/x/crypto v0.55.0/go.mod h1:uq0V9dE/fzQuJtbnL+2EhWOE63vo164FY8xqEnV9xis= +golang.org/x/crypto v0.56.0 h1:GUh5Ii4J5jtcseSMiRqr1jXCNHoxjeV9Fmekc2oLy6Y= +golang.org/x/crypto v0.56.0/go.mod h1:OMW5y6CY9l38uPLmxU6l6pwcXp1obtLo3e6gT7gQR2I= golang.org/x/exp v0.0.0-20190121172915-509febef88a4/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA= golang.org/x/exp v0.0.0-20190306152737-a1d7652674e8/go.mod h1:CJ0aWSM057203Lf6IL+f9T1iT9GByDxfZKAQTCR3kQA= golang.org/x/exp v0.0.0-20190510132918-efd6b22b2522/go.mod h1:ZjyILWgesfNpC6sMxTJOJm9Kp84zZh5NQWvqDGG3Qr8= @@ -1149,8 +1149,8 @@ golang.org/x/mod v0.5.0/go.mod h1:5OXOZSfqPIIbmVBIIKWRFfZjPR0E5r58TLhUjH0a2Ro= golang.org/x/mod v0.6.0-dev.0.20220419223038-86c51ed26bb4/go.mod h1:jJ57K6gSWd91VN4djpZkiMVwK6gcyfeH4XE8wZrZaV4= golang.org/x/mod v0.8.0/go.mod h1:iBbtSCu2XBx23ZKBPSOrRkjjQPZFPuis4dIYUhu/chs= -golang.org/x/mod v0.40.0 h1:hUv+3cXcdRHz08UmSiOob7sadHig73uo5bkXxQ/tvUs= -golang.org/x/mod v0.40.0/go.mod h1:0/weTWkPWGBikyTWAX3dkjVztMmBA5hM0DH6BElSupE= +golang.org/x/mod v0.41.0 h1:qJmnOUb4YB+FsEuM3HcWucdZASCPGhsX6uljO6pog0c= +golang.org/x/mod v0.41.0/go.mod h1:Ek9pY8RKWXwsWvd3rQiHYtMqkjSUV+s1Rj7j4H5Ur6o= golang.org/x/net v0.0.0-20180724234803-3673e40ba225/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4= golang.org/x/net v0.0.0-20180826012351-8a410e7b638d/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4= golang.org/x/net v0.0.0-20181023162649-9b4f9f5ad519/go.mod h1:mL1N/T3taQHkDXs73rZJwtUhF3w3ftmwwsq0BUmARs4= @@ -1329,8 +1329,8 @@ golang.org/x/time v0.0.0-20181108054448-85acf8d2951c/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ= golang.org/x/time v0.0.0-20190308202827-9d24e82272b4/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ= golang.org/x/time v0.0.0-20191024005414-555d28b269f0/go.mod h1:tRJNPiyCQ0inRvYxbN9jk5I+vvW/OXSQhTDSoE431IQ= -golang.org/x/time v0.15.0 h1:bbrp8t3bGUeFOx08pvsMYRTCVSMk89u4tKbNOZbp88U= -golang.org/x/time v0.15.0/go.mod h1:Y4YMaQmXwGQZoFaVFk4YpCt4FLQMYKZe9oeV/f4MSno= +golang.org/x/time v0.16.0 h1:vMb6ptszcQMkcwiRTAuNNU50gom6++Q/6gY2hDM6VDE= +golang.org/x/time v0.16.0/go.mod h1:rVKOqvZeKvrDKTQiAHJ7wmwP0RzleSphoEA9RcdLA0s= golang.org/x/tools v0.0.0-20180917221912-90fa682c2a6e/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= golang.org/x/tools v0.0.0-20190114222345-bf090417da8b/go.mod h1:n7NCudcB/nEzxVGmLbDWY5pfWTLqBcC2KZ6jyYvM4mQ= golang.org/x/tools v0.0.0-20190226205152-f727befe758c/go.mod h1:9Yl7xja0Znq3iFh3HoIrodX9oNMXvdceNzlUR8zjMvY= @@ -1429,8 +1429,8 @@ google.golang.org/api v0.59.0/go.mod h1:sT2boj7M9YJxZzgeZqXogmhfmRWDtPzT31xkieUbuZU= google.golang.org/api v0.61.0/go.mod h1:xQRti5UdCmoCEqFxcz93fTl338AVqDgyaDRuOZ3hg9I= google.golang.org/api v0.62.0/go.mod h1:dKmwPCydfsad4qCH08MSdgWjfHOyfpd4VtDGgRFdavw= -google.golang.org/api v0.292.0 h1:Ewiwo/GTtiaPZSNAZQUcWLh8AYDEoPmIXyJfeoTSMHU= -google.golang.org/api v0.292.0/go.mod h1:07kjmMnFGm2RQuCza2EZM/5N68G/fVvFb1xKjWqoFA0= +google.golang.org/api v0.294.0 h1:8gASjJxdtcIieB3OqbkLcF0FfbXVNqKtU5iozD1ssvA= +google.golang.org/api v0.294.0/go.mod h1:02qB8+Ox1ZFzcaKFMguy1nQLJmSIyvV6Ff4txJEXtl4= google.golang.org/appengine v1.1.0/go.mod h1:EbEs0AVv82hx2wNQdGPgUI5lhzA/G0D9YwlJXL52JkM= google.golang.org/appengine v1.4.0/go.mod h1:xpcJRLb0r/rnEns0DIKYYv+WjYCduHsrkT7/EB5XEv4= google.golang.org/appengine v1.5.0/go.mod h1:xpcJRLb0r/rnEns0DIKYYv+WjYCduHsrkT7/EB5XEv4= @@ -1501,12 +1501,12 @@ google.golang.org/genproto v0.0.0-20211203200212-54befc351ae9/go.mod h1:5CzLGKJ67TSI2B9POpiiyGha0AjJvZIUgRMt1dSmuhc= google.golang.org/genproto v0.0.0-20211206160659-862468c7d6e0/go.mod h1:5CzLGKJ67TSI2B9POpiiyGha0AjJvZIUgRMt1dSmuhc= google.golang.org/genproto v0.0.0-20211208223120-3a66f561d7aa/go.mod h1:5CzLGKJ67TSI2B9POpiiyGha0AjJvZIUgRMt1dSmuhc= -google.golang.org/genproto v0.0.0-20260519071638-aa98bba5eb94 h1:YJjbgu+dkp5kUJLfpMyCLfBIWZb/FcJyuLeo1gVBOuo= -google.golang.org/genproto v0.0.0-20260519071638-aa98bba5eb94/go.mod h1:RRHjglSYABVCWpQ7USCpdfhcd9t4PkajvVwyynZizTc= -google.golang.org/genproto/googleapis/api v0.0.0-20260630182238-925bb5da69e7 h1:jQ9p21COKWjP3VwuFrNRiiOTMh3mPpN45R7SLrH/HUU= -google.golang.org/genproto/googleapis/api v0.0.0-20260630182238-925bb5da69e7/go.mod h1:KqHwBx2upmfa1XSi1WuRvC+2VGCLtooKkfmyvRbUmqA= -google.golang.org/genproto/googleapis/rpc v0.0.0-20260803160001-6ac0973c030d h1:IL4hdHzcUv2l/gcg98/Rj3FbtE6axwqslOW8SW0C+S0= -google.golang.org/genproto/googleapis/rpc v0.0.0-20260803160001-6ac0973c030d/go.mod h1:4Hqkh8ycfw05ld/3BWL7rJOSfebL2Q+DVDeRgYgxUU8= +google.golang.org/genproto v0.0.0-20260715232425-e75dac1f907d h1:C9v1o0/4quuhOAfmRXA2j+we0PqZIp8traLdeogF3Ms= +google.golang.org/genproto v0.0.0-20260715232425-e75dac1f907d/go.mod h1:Wz2wFJntZFmLGo7pLDXZ3wYk5hyc0Mb+SkHhDDXT+lU= +google.golang.org/genproto/googleapis/api v0.0.0-20260715232425-e75dac1f907d h1:QwnJwPte4XXAkhPu26LTDIahnsMSUV0kK8HkxbC+Pc4= +google.golang.org/genproto/googleapis/api v0.0.0-20260715232425-e75dac1f907d/go.mod h1:WRrQ7/7N19PypuT0fxLOL5Lq0waoiRri4FbtHDEKrGE= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260819154853-08b0e4226688 h1:cYNAzI2sUwhmCcoj9TxvihSrqsxt6uIkj3rDRhSDmW4= +google.golang.org/genproto/googleapis/rpc v0.0.0-20260819154853-08b0e4226688/go.mod h1:DjtHYE8FKJLivXcBEjGwndXfIC23G0VpXiXKqG179uA= google.golang.org/grpc v1.19.0/go.mod h1:mqu4LbDTu4XGKhr4mRzUsmM4RtVoemTSY81AxZiDr8c= google.golang.org/grpc v1.20.1/go.mod h1:10oTOabMzJvdu6/UiuZezV6QK5dSlG84ov/aaiqXj38= google.golang.org/grpc v1.21.1/go.mod h1:oYelfM1adQP15Ek0mdvEgi9Df8B9CZIaU1084ijfRaM= @@ -1534,8 +1534,8 @@ google.golang.org/grpc v1.40.0/go.mod h1:ogyxbiOoUXAkP+4+xa6PZSE9DZgIHtSpzjDTB9KAK34= google.golang.org/grpc v1.40.1/go.mod h1:ogyxbiOoUXAkP+4+xa6PZSE9DZgIHtSpzjDTB9KAK34= google.golang.org/grpc v1.42.0/go.mod h1:k+4IHHFw41K8+bbowsex27ge2rCb65oeWqe4jJ590SU= -google.golang.org/grpc v1.83.0 h1:JeNZEKJFbQxArAMl+hiytHauacDNqJUllNfmIMmpqnQ= -google.golang.org/grpc v1.83.0/go.mod h1:kDyl6SKsiHKt0uylY5gtn5cEjkrIOhQOGDgIc4JGwzQ= +google.golang.org/grpc v1.83.2 h1:EManeRomTObA0BU7I8vXgg/78uE5MJ9M8B39EX2WscU= +google.golang.org/grpc v1.83.2/go.mod h1:YPI1hK3kDked6iHvgX3tR0y+nX/qpMFKhPgFsokw1S8= google.golang.org/grpc/cmd/protoc-gen-go-grpc v1.1.0/go.mod h1:6Kw0yEErY5E/yWrBtf03jp27GLLJujG4z/JK95pnjjw= google.golang.org/protobuf v0.0.0-20200109180630-ec00e32a8dfd/go.mod h1:DFci5gLYBciE7Vtevhsrf46CRTquxDuWsQurQQe4oz8= google.golang.org/protobuf v0.0.0-20200221191635-4d8936d0db64/go.mod h1:kwYJMbMJ01Woi6D6+Kah6886xMZcty6N08ah7+eCXa0= @@ -1550,8 +1550,8 @@ google.golang.org/protobuf v1.26.0-rc.1/go.mod h1:jlhhOSvTdKEhbULTjvd4ARK9grFBp09yW+WbY/TyQbw= google.golang.org/protobuf v1.26.0/go.mod h1:9q0QmTI4eRPtz6boOQmLYwt+qCgq0jsYwAQnmE0givc= google.golang.org/protobuf v1.27.1/go.mod h1:9q0QmTI4eRPtz6boOQmLYwt+qCgq0jsYwAQnmE0givc= -google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af h1:+5/Sw3GsDNlEmu7TfklWKPdQ0Ykja5VEmq2i817+jbI= -google.golang.org/protobuf v1.36.12-0.20260120151049-f2248ac996af/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco= +google.golang.org/protobuf v1.36.12 h1:pJOKDDOyeXErUroCihFAd5LQuwXBSpVnKGrj5o/fwxc= +google.golang.org/protobuf v1.36.12/go.mod h1:HTf+CrKn2C3g5S8VImy6tdcUvCska2kB7j23XfzDpco= gopkg.in/alecthomas/kingpin.v2 v2.2.6/go.mod h1:FMv+mEhP44yOT+4EoQTLFTRgOQ1FBLkstjWtayDeSgw= gopkg.in/check.v1 v0.0.0-20161208181325-20d25e280405/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= gopkg.in/check.v1 v1.0.0-20180628173108-788fd7840127/go.mod h1:Co6ibVJAznAaIkqp8huTwlJQCZ016jof/cbN4VW5Yz0= @@ -1589,30 +1589,30 @@ honnef.co/go/tools v0.0.1-2020.1.4/go.mod h1:X/FiERA/W4tHapMX5mGpAtMSVEeEUOyHaw9vFzvIQ3k= howett.net/plist v1.0.1 h1:37GdZ8tP09Q35o9ych3ehygcsL+HqKSwzctveSlarvM= howett.net/plist v1.0.1/go.mod h1:lqaXoTrLY4hg8tnEzNru53gicrbv7rrk+2xJA/7hw9g= -modernc.org/cc/v4 v4.29.1 h1:MKgdCV3WykTSPqpVrnxdEDS0HEd2FHpKZDzxzU5LyeI= -modernc.org/cc/v4 v4.29.1/go.mod h1:OnovgIhbbMXMu1aISnJ0wvVD1KnW+cAUJkIrAWh+kVI= -modernc.org/ccgo/v4 v4.34.6 h1:sBgfIwyN0TQ9C5hwIeuqyeAKyMWnbvj2fvpF4L11uzU= -modernc.org/ccgo/v4 v4.34.6/go.mod h1:SZ8YcN9NG7XVsQYdm6jYBvi8PQP1qi+kqB6OhjqI3Fk= +modernc.org/cc/v4 v4.29.2 h1:h6+9ciCnPKutf4I03CvheAvDLX7+IHlqR6Iy6J+cgd8= +modernc.org/cc/v4 v4.29.2/go.mod h1:OnovgIhbbMXMu1aISnJ0wvVD1KnW+cAUJkIrAWh+kVI= +modernc.org/ccgo/v4 v4.35.0 h1:F+TUsmw09QxLzmi3aeYYGxjAXarmZaKgj3mKQHNaA8w= +modernc.org/ccgo/v4 v4.35.0/go.mod h1:qrVGs9S3Sr2Ztcg9ve+kTAYMp5a3YvWjo+SoN06kJ5I= modernc.org/fileutil v1.4.0 h1:j6ZzNTftVS054gi281TyLjHPp6CPHr2KCxEXjEbD6SM= modernc.org/fileutil v1.4.0/go.mod h1:EqdKFDxiByqxLk8ozOxObDSfcVOv/54xDs/DUHdvCUU= modernc.org/gc/v2 v2.6.5 h1:nyqdV8q46KvTpZlsw66kWqwXRHdjIlJOhG6kxiV/9xI= modernc.org/gc/v2 v2.6.5/go.mod h1:YgIahr1ypgfe7chRuJi2gD7DBQiKSLMPgBQe9oIiito= -modernc.org/gc/v3 v3.1.4 h1:2g65LGVSmFQrXeITAw97x7hCRvZFcyE1uDP+7Vng7JI= -modernc.org/gc/v3 v3.1.4/go.mod h1:HFK/6AGESC7Ex+EZJhJ2Gni6cTaYpSMmU/cT9RmlfYY= +modernc.org/gc/v3 v3.1.5 h1:21ldfPfRYE31Tb7B3mwAK8gy1AxP4+dKjrOQPfqakoc= +modernc.org/gc/v3 v3.1.5/go.mod h1:HFK/6AGESC7Ex+EZJhJ2Gni6cTaYpSMmU/cT9RmlfYY= modernc.org/goabi0 v0.2.0 h1:HvEowk7LxcPd0eq6mVOAEMai46V+i7Jrj13t4AzuNks= modernc.org/goabi0 v0.2.0/go.mod h1:CEFRnnJhKvWT1c1JTI3Avm+tgOWbkOu5oPA8eH8LnMI= -modernc.org/libc v1.74.4 h1:fX1Omw4o2/1C2iRkkIsrQTasJQldLhRmuPreXLoWs9k= -modernc.org/libc v1.74.4/go.mod h1:eeQAS9W3sZeKYMFubydxJpII9ybHWshk+7or7bLG9co= +modernc.org/libc v1.75.6 h1:yKk8qo+Di4gkmvRboK8ocCqH22FiUCR6jRy2OwtCRus= +modernc.org/libc v1.75.6/go.mod h1:bO5o2ztHxBb2rjz0PgdHN0sSMw57CgxGFLZ3Qd/QpVQ= modernc.org/mathutil v1.7.1 h1:GCZVGXdaN8gTqB1Mf/usp1Y/hSqgI2vAGGP4jZMCxOU= modernc.org/mathutil v1.7.1/go.mod h1:4p5IwJITfppl0G4sUEDtCr4DthTaT47/N3aT6MhfgJg= -modernc.org/memory v1.11.0 h1:o4QC8aMQzmcwCK3t3Ux/ZHmwFPzE6hf2Y5LbkRs+hbI= -modernc.org/memory v1.11.0/go.mod h1:/JP4VbVC+K5sU2wZi9bHoq2MAkCnrt2r98UGeSK7Mjw= +modernc.org/memory v1.12.1 h1:nFMiWrpStgZczNl6XI9GnIk/rWhYIyHGUaR04pGbp9g= +modernc.org/memory v1.12.1/go.mod h1:/JP4VbVC+K5sU2wZi9bHoq2MAkCnrt2r98UGeSK7Mjw= modernc.org/opt v0.2.0 h1:tGyef5ApycA7FSEOMraay9SaTk5zmbx7Tu+cJs4QKZg= modernc.org/opt v0.2.0/go.mod h1:03fq9lsNfvkYSfxrfUhZCWPk1lm4cq4N+Bh//bEtgns= modernc.org/sortutil v1.2.1 h1:+xyoGf15mM3NMlPDnFqrteY07klSFxLElE2PVuWIJ7w= modernc.org/sortutil v1.2.1/go.mod h1:7ZI3a3REbai7gzCLcotuw9AC4VZVpYMjDzETGsSMqJE= -modernc.org/sqlite v1.56.0 h1:/D8e2RfFqoy/Zc6PuC76U28zFwmI/sYx1Kjm4yEn9e0= -modernc.org/sqlite v1.56.0/go.mod h1:yCJ2cmAaIkHQ25oXWrF8H4O1lIfPYPR26yCEDj2P3pQ= +modernc.org/sqlite v1.58.0 h1:38u40/bwkfM7f0Myhosl+SEMltSDxnGdQf8o6Kjmys0= +modernc.org/sqlite v1.58.0/go.mod h1:rsD2CckafgObKC4DhBlGBf+RiHxkc3hINGt1Xw32tVY= modernc.org/strutil v1.2.1 h1:UneZBkQA+DX2Rp35KcM69cSsNES9ly8mQWD71HKlOA0= modernc.org/strutil v1.2.1/go.mod h1:EHkiggD70koQxjVdSBM3JKM7k6L0FbGE5eymy9i3B9A= modernc.org/token v1.1.0 h1:Xl7Ap9dKaEs5kLoOQeQmPWevfnk/DM5qcLcYlA8ys6Y= diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/grype/db/v6/build/transformers/openvex/transform.go new/grype-0.119.0/grype/db/v6/build/transformers/openvex/transform.go --- old/grype-0.118.0/grype/db/v6/build/transformers/openvex/transform.go 2026-08-27 20:40:29.000000000 +0200 +++ new/grype-0.119.0/grype/db/v6/build/transformers/openvex/transform.go 2026-09-17 17:25:25.000000000 +0200 @@ -158,7 +158,13 @@ switch purl.Type { case packageurl.TypeMaven: return purl.Namespace + ":" + purl.Name - case packageurl.TypeNPM: + case packageurl.TypeNPM, packageurl.TypeGolang: + // For Go the namespace is not metadata, it is the leading part of the + // module path: pkg:golang/github.com/gin-gonic/gin splits into + // Namespace="github.com/gin-gonic" and Name="gin", and the module is + // only identified by the two joined. Dropping it would file the + // statement under "gin". A module with no namespace, such as + // pkg:golang/stdlib, is returned unchanged by the check above. return purl.Namespace + "/" + purl.Name } return purl.Name diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/grype/db/v6/build/transformers/openvex/transform_test.go new/grype-0.119.0/grype/db/v6/build/transformers/openvex/transform_test.go --- old/grype-0.118.0/grype/db/v6/build/transformers/openvex/transform_test.go 2026-08-27 20:40:29.000000000 +0200 +++ new/grype-0.119.0/grype/db/v6/build/transformers/openvex/transform_test.go 2026-09-17 17:25:25.000000000 +0200 @@ -8,6 +8,8 @@ govex "github.com/openvex/go-vex/pkg/vex" "github.com/stretchr/testify/require" + "github.com/anchore/packageurl-go" + "github.com/anchore/grype/grype/db/internal/provider/unmarshal" "github.com/anchore/grype/grype/db/provider" db "github.com/anchore/grype/grype/db/v6" @@ -621,3 +623,67 @@ }) } } + +func Test_packageNameFromPURL(t *testing.T) { + tests := []struct { + name string + purl string + want string + }{ + { + // A Go module is identified by its full path; the namespace is the + // leading part of it rather than metadata, so dropping it filed the + // statement under a different package than the advisory and matcher + // paths use. + name: "golang module keeps its namespace", + purl: "pkg:golang/github.com/gin-gonic/[email protected]", + want: "github.com/gin-gonic/gin", + }, + { + name: "golang module on a vanity host", + purl: "pkg:golang/k8s.io/[email protected]", + want: "k8s.io/client-go", + }, + { + name: "golang module with a version suffix in the name", + purl: "pkg:golang/gopkg.in/[email protected]", + want: "gopkg.in/yaml.v3", + }, + { + name: "golang module with no namespace is unchanged", + purl: "pkg:golang/[email protected]", + want: "stdlib", + }, + { + name: "maven keeps the groupId separator", + purl: "pkg:maven/org.apache.commons/[email protected]", + want: "org.apache.commons:commons-lang3", + }, + { + name: "npm scoped name is rejoined", + purl: "pkg:npm/%40angular/[email protected]", + want: "@angular/core", + }, + { + // An ecosystem whose namespace is metadata rather than identity is + // left alone, so this change does not widen beyond Go. + name: "namespace that is not part of the name is dropped", + purl: "pkg:deb/debian/[email protected]", + want: "curl", + }, + { + name: "flat ecosystem is unchanged", + purl: "pkg:pypi/[email protected]", + want: "urllib3", + }, + } + + for _, tt := range tests { + t.Run(tt.name, func(t *testing.T) { + purl, err := packageurl.FromString(tt.purl) + require.NoError(t, err) + + require.Equal(t, tt.want, packageNameFromPURL(&purl)) + }) + } +} diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/grype/internal/ignorereasons/ignore_reasons.go new/grype-0.119.0/grype/internal/ignorereasons/ignore_reasons.go --- old/grype-0.118.0/grype/internal/ignorereasons/ignore_reasons.go 1970-01-01 01:00:00.000000000 +0100 +++ new/grype-0.119.0/grype/internal/ignorereasons/ignore_reasons.go 2026-09-17 17:25:25.000000000 +0200 @@ -0,0 +1,15 @@ +// Package ignorereasons holds the reason values grype writes on the ignore +// rules created by its own internal suppressions. These become visible to +// consumers via VulnerabilityMatcher.IncludeMatcherSuppressions; the string +// values in output are the interface, not these symbols. +package ignorereasons + +const ( + // DistroFixed is the reason recorded when a distro fix record for an + // owning package suppresses a match on an owned package. + DistroFixed = "distro-fixed" + + // DistroNAK is the reason recorded when a distro record declaring a + // package not vulnerable suppresses a match. + DistroNAK = "distro-nak" +) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/grype/match/ignore_test.go new/grype-0.119.0/grype/match/ignore_test.go --- old/grype-0.118.0/grype/match/ignore_test.go 2026-08-27 20:40:29.000000000 +0200 +++ new/grype-0.119.0/grype/match/ignore_test.go 2026-09-17 17:25:25.000000000 +0200 @@ -6,6 +6,7 @@ "github.com/google/uuid" "github.com/stretchr/testify/assert" + "github.com/anchore/grype/grype/internal/ignorereasons" "github.com/anchore/grype/grype/pkg" "github.com/anchore/grype/grype/vulnerability" "github.com/anchore/syft/syft/artifact" @@ -1181,7 +1182,7 @@ } filter := IgnoreRelatedPackage{ - Reason: "Explicit APK NAK by Ownership", + Reason: ignorereasons.DistroNAK, RelationshipType: artifact.OwnershipByFileOverlapRelationship, VulnerabilityID: "GHSA-xjjg-vmw6-c2p9", RelatedPackageID: ownerPkgID, @@ -1241,6 +1242,7 @@ assert.NotEmpty(t, rules, "expected match to be ignored") assert.Equal(t, filter.VulnerabilityID, rules[0].Vulnerability) assert.Equal(t, filter.Reason, rules[0].Reason) + assert.True(t, rules[0].IncludeAliases, "emitted rule should include aliases") } else { assert.Empty(t, rules, "expected match to NOT be ignored") } diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/grype/matcher/apk/matcher.go new/grype-0.119.0/grype/matcher/apk/matcher.go --- old/grype-0.118.0/grype/matcher/apk/matcher.go 2026-08-27 20:40:29.000000000 +0200 +++ new/grype-0.119.0/grype/matcher/apk/matcher.go 2026-09-17 17:25:25.000000000 +0200 @@ -5,6 +5,7 @@ "fmt" "slices" + "github.com/anchore/grype/grype/internal/ignorereasons" "github.com/anchore/grype/grype/match" "github.com/anchore/grype/grype/matcher/internal" "github.com/anchore/grype/grype/matcher/internal/result" @@ -15,11 +16,6 @@ syftPkg "github.com/anchore/syft/syft/pkg" ) -const ( - ignoreReasonDistroFixed = "DistroPackageFixed" - ignoreReasonExplicitNAK = "Explicit APK NAK" -) - var ( nakVersionString = version.MustGetConstraint("< 0", version.ApkFormat).String() @@ -75,7 +71,7 @@ ignores := slices.Concat( cpeIgnores, nakIgnores, - internal.OwnershipIgnores(p, ignoreReasonDistroFixed, allFixed.Vulnerabilities()...), + internal.OwnershipIgnores(p, ignorereasons.DistroFixed, allFixed.Vulnerabilities()...), ) return vulnerable.ToMatches(), ignores, nil @@ -138,7 +134,7 @@ naks = naks.Merge(upstreamNaks) } - return internal.OwnershipIgnores(p, ignoreReasonExplicitNAK, naks.Vulnerabilities()...), nil + return internal.OwnershipIgnores(p, ignorereasons.DistroNAK, naks.Vulnerabilities()...), nil } // cpeResults finds NVD (CPE-indexed) results for the package itself and for each of its diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/grype/matcher/apk/matcher_test.go new/grype-0.119.0/grype/matcher/apk/matcher_test.go --- old/grype-0.118.0/grype/matcher/apk/matcher_test.go 2026-08-27 20:40:29.000000000 +0200 +++ new/grype-0.119.0/grype/matcher/apk/matcher_test.go 2026-09-17 17:25:25.000000000 +0200 @@ -5,6 +5,7 @@ "github.com/stretchr/testify/require" + "github.com/anchore/grype/grype/internal/ignorereasons" "github.com/anchore/grype/grype/match" "github.com/anchore/grype/grype/pkg" "github.com/anchore/grype/grype/version" @@ -14,16 +15,6 @@ syftPkg "github.com/anchore/syft/syft/pkg" ) -// reasonDistroPackageFixed is the IgnoreRelatedPackage reason emitted by the -// shared internal/MatchPackageByDistro path for vulns the secdb considers -// fixed (or unaffected/NAK) for the package. -const reasonDistroPackageFixed = "DistroPackageFixed" - -// reasonExplicitApkNak is the IgnoreRelatedPackage reason emitted by the -// apk-specific findNaksForPackage path for secdb entries with the apk -// "< 0" sentinel constraint. -const reasonExplicitApkNak = "Explicit APK NAK" - // reasonCPENotVulnerable is the IgnoreRelatedPackage reason emitted by // MatchPackageByCPEs for CPE matches that resolved a vulnerability record // for the package's CPE but whose version constraint is not satisfied by @@ -107,7 +98,7 @@ }) } -// === fixed-version → DistroPackageFixed ignore (no match) === +// === fixed-version → distro-fixed ignore (no match) === func TestMatcherApk_FixedVersionProducesIgnore_Alpine(t *testing.T) { dbtest.DBs(t, "alpine318"). @@ -121,7 +112,7 @@ Build() db.Match(t, &matcher, p).Ignores(). - SelectRelatedPackageIgnore(reasonDistroPackageFixed, "CVE-2024-0727"). + SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2024-0727"). ForPackage(pkgID). WithRelationshipType(artifact.OwnershipByFileOverlapRelationship) }) @@ -139,7 +130,7 @@ Build() db.Match(t, &matcher, p).Ignores(). - SelectRelatedPackageIgnore(reasonDistroPackageFixed, "CVE-2024-0727"). + SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2024-0727"). ForPackage(pkgID). WithRelationshipType(artifact.OwnershipByFileOverlapRelationship) }) @@ -147,7 +138,7 @@ // TestMatcherApk_FixedVersionInUpstreamProducesIgnore verifies that when a // binary apk package's upstream is at or past the secdb fix, the -// DistroPackageFixed ignore is emitted against the binary package's ID +// distro-fixed ignore is emitted against the binary package's ID // (catalogPkg) - not the synthetic upstream - so consumers can suppress // language-ecosystem matches that overlap the binary by file ownership. func TestMatcherApk_FixedVersionInUpstreamProducesIgnore(t *testing.T) { @@ -163,19 +154,19 @@ Build() db.Match(t, &matcher, p).Ignores(). - SelectRelatedPackageIgnore(reasonDistroPackageFixed, "CVE-2024-0727"). + SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2024-0727"). ForPackage(pkgID). WithRelationshipType(artifact.OwnershipByFileOverlapRelationship) }) } -// === NAK → Explicit APK NAK + DistroPackageFixed ignores === +// === NAK → distro-nak + distro-fixed ignores === // TestMatcherApk_NakProducesIgnore_Alpine verifies the NAK path: alpine // CVE-2019-6470 lists bind with Version="0", which the v6 OS transformer // turns into a "< 0" ApkFormat constraint. The matcher emits two ignores -// per NAK - one DistroPackageFixed via the shared MatchPackageByDistro -// fixed/unaffected ownership path, and one apk-specific Explicit APK NAK +// per NAK - one distro-fixed via the shared MatchPackageByDistro +// fixed/unaffected ownership path, and one apk-specific distro-nak // via findNaksForPackage. Both point at the same package + CVE. func TestMatcherApk_NakProducesIgnore_Alpine(t *testing.T) { dbtest.DBs(t, "alpine318"). @@ -189,10 +180,10 @@ Build() ignores := db.Match(t, &matcher, p).Ignores() - ignores.SelectRelatedPackageIgnore(reasonExplicitApkNak, "CVE-2019-6470"). + ignores.SelectRelatedPackageIgnore(ignorereasons.DistroNAK, "CVE-2019-6470"). ForPackage(pkgID). WithRelationshipType(artifact.OwnershipByFileOverlapRelationship) - ignores.SelectRelatedPackageIgnore(reasonDistroPackageFixed, "CVE-2019-6470"). + ignores.SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2019-6470"). ForPackage(pkgID). WithRelationshipType(artifact.OwnershipByFileOverlapRelationship) }) @@ -211,10 +202,10 @@ Build() ignores := db.Match(t, &matcher, p).Ignores() - ignores.SelectRelatedPackageIgnore(reasonExplicitApkNak, "CVE-2024-47535"). + ignores.SelectRelatedPackageIgnore(ignorereasons.DistroNAK, "CVE-2024-47535"). ForPackage(pkgID). WithRelationshipType(artifact.OwnershipByFileOverlapRelationship) - ignores.SelectRelatedPackageIgnore(reasonDistroPackageFixed, "CVE-2024-47535"). + ignores.SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2024-47535"). ForPackage(pkgID). WithRelationshipType(artifact.OwnershipByFileOverlapRelationship) }) @@ -237,10 +228,10 @@ Build() ignores := db.Match(t, &matcher, p).Ignores() - ignores.SelectRelatedPackageIgnore(reasonExplicitApkNak, "CVE-2019-6470"). + ignores.SelectRelatedPackageIgnore(ignorereasons.DistroNAK, "CVE-2019-6470"). ForPackage(pkgID). WithRelationshipType(artifact.OwnershipByFileOverlapRelationship) - ignores.SelectRelatedPackageIgnore(reasonDistroPackageFixed, "CVE-2019-6470"). + ignores.SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2019-6470"). ForPackage(pkgID). WithRelationshipType(artifact.OwnershipByFileOverlapRelationship) }) @@ -290,7 +281,7 @@ // TestMatcherApk_NvdDroppedWhenSecdbHasFix verifies that when secdb knows // about a CVE and considers the package fixed, the NVD CPE record is // dropped even if NVD still considers the upstream version vulnerable. The -// only output is a DistroPackageFixed ignore from the secdb path. +// only output is a distro-fixed ignore from the secdb path. func TestMatcherApk_NvdDroppedWhenSecdbHasFix(t *testing.T) { // alpine fix: openssl 3.1.4-r5. NVD CVE-2024-0727 lists openssl in // [3.1.0, 3.1.5), so 3.1.4 still matches the NVD CPE range - this is @@ -307,7 +298,7 @@ Build() db.Match(t, &matcher, p).Ignores(). - SelectRelatedPackageIgnore(reasonDistroPackageFixed, "CVE-2024-0727"). + SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2024-0727"). ForPackage(pkgID). WithRelationshipType(artifact.OwnershipByFileOverlapRelationship) }) @@ -459,12 +450,12 @@ findings.DoesNotHaveAnyVulnerabilities("CVE-2024-47535") // the upstream NAK still produces both apk-NAK and - // DistroPackageFixed ignores keyed to the catalog package. + // distro-fixed ignores keyed to the catalog package. ignores := findings.Ignores() - ignores.SelectRelatedPackageIgnore(reasonExplicitApkNak, "CVE-2024-47535"). + ignores.SelectRelatedPackageIgnore(ignorereasons.DistroNAK, "CVE-2024-47535"). ForPackage(pkgID). WithRelationshipType(artifact.OwnershipByFileOverlapRelationship) - ignores.SelectRelatedPackageIgnore(reasonDistroPackageFixed, "CVE-2024-47535"). + ignores.SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2024-47535"). ForPackage(pkgID). WithRelationshipType(artifact.OwnershipByFileOverlapRelationship) }) @@ -506,10 +497,10 @@ // must not surface as its own match. findings.DoesNotHaveAnyVulnerabilities("CVE-2026-24398") - // the distro fixed path still emits one DistroPackageFixed ignore per + // the distro fixed path still emits one distro-fixed ignore per // identifier (the CGA id plus its CVE/GHSA aliases). findings.Ignores(). - SelectRelatedPackageIgnores(reasonDistroPackageFixed, + SelectRelatedPackageIgnores(ignorereasons.DistroFixed, "CGA-22hv-wp9q-4779", "CVE-2026-24398", "GHSA-r354-f388-2fhh"). @@ -573,7 +564,7 @@ // the ranges-less advisory must NOT be treated as an apk NAK: it is affected at every // version, not "not affected". The "< 0" NAK filter no longer matches a record that - // carries no "< 0" constraint, so no Explicit APK NAK ignores are emitted. + // carries no "< 0" constraint, so no distro-nak ignores are emitted. findings.Ignores().IsEmpty() }) } @@ -669,14 +660,14 @@ // TestMatcherApk_ArchFilter_IgnoreWhenArchAgrees is the pair of // MatchWhenArchAgrees: same package, same arch, but a version past the // fix. The arch qualifier still passes so the fix path runs and emits -// one DistroPackageFixed ignore per identifier (CGA id + aliases). +// one distro-fixed ignore per identifier (CGA id + aliases). // Cross-checks that arch filtering doesn't short-circuit the // fixed-version ignore emission. func TestMatcherApk_ArchFilter_IgnoreWhenArchAgrees(t *testing.T) { dbtest.DBs(t, "chainguard-rolling").Run(func(t *testing.T, db *dbtest.DB) { matcher := Matcher{} // fix is 3.153.0-r0; 3.153.1-r0 is over the fix, so the matcher emits - // no match but does emit one DistroPackageFixed ignore per identifier + // no match but does emit one distro-fixed ignore per identifier // (the CGA id plus its CVE/GHSA aliases) so consumers can suppress // language-ecosystem findings that overlap by file ownership. pkgID := pkg.ID("langfuse-past-fix") @@ -688,7 +679,7 @@ // vulnerability fixed this pkg-version for this architecture db.Match(t, &matcher, p).Ignores(). - SelectRelatedPackageIgnores(reasonDistroPackageFixed, + SelectRelatedPackageIgnores(ignorereasons.DistroFixed, "CGA-22hv-wp9q-4779", "CVE-2026-24398", "GHSA-r354-f388-2fhh"). @@ -701,7 +692,7 @@ // the package's arch is aarch64 but the only Chainguard APH for this name has // arch=x86_64, so OnlyQualifiedPackages drops it before the version check ever // runs. No match, no ignore (the vuln is filtered before reaching the fix -// path that would emit a DistroPackageFixed ignore). +// path that would emit a distro-fixed ignore). func TestMatcherApk_ArchFilter_NoMatchWhenArchDisagrees(t *testing.T) { dbtest.DBs(t, "chainguard-rolling").Run(func(t *testing.T, db *dbtest.DB) { matcher := Matcher{} diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/grype/matcher/apk/rootio_test.go new/grype-0.119.0/grype/matcher/apk/rootio_test.go --- old/grype-0.118.0/grype/matcher/apk/rootio_test.go 2026-08-27 20:40:29.000000000 +0200 +++ new/grype-0.119.0/grype/matcher/apk/rootio_test.go 2026-09-17 17:25:25.000000000 +0200 @@ -6,6 +6,7 @@ "github.com/stretchr/testify/assert" "github.com/stretchr/testify/require" + "github.com/anchore/grype/grype/internal/ignorereasons" "github.com/anchore/grype/grype/match" "github.com/anchore/grype/grype/pkg" "github.com/anchore/grype/internal/dbtest" @@ -27,7 +28,7 @@ // - the NVD CPE match, but only where the distro feed has no opinion. // A rootio NAK covering the same vulnerability by alias means the // vendor has answered it, so no match is reported at all; -// - the rootio NAK as DistroPackageFixed IgnoreFilters that +// - the rootio NAK as distro-fixed IgnoreFilters that // alias-unwind into the rootio record ID + the upstream CVE. Those // are for packages that overlap this one by file, which is the only // thing an IgnoreRelatedPackage can suppress — never the package it @@ -88,7 +89,7 @@ // rootio-libuv at the rootio fix. NVD CPE flags 1.44.2 (< vEnd // 1.48.0) — match surfaces. The rootio NAK matches alias - // CVE-2024-24806 and appears as the DistroPackageFixed ignore + // CVE-2024-24806 and appears as the distro-fixed ignore // pair that downstream code uses to drop the match. t.Run("rootio-libuv at rootio fix: no match, NAK ignore only", func(t *testing.T) { pkgID := pkg.ID("rootio-libuv-at-fix") @@ -103,7 +104,7 @@ // NVD CPE record is answered and never becomes a match findings.DoesNotHaveAnyVulnerabilities("CVE-2024-24806") findings.Ignores(). - SelectRelatedPackageIgnores("DistroPackageFixed", + SelectRelatedPackageIgnores(ignorereasons.DistroFixed, "ROOT-OS-ALPINE-318-CVE-2024-24806", "CVE-2024-24806"). ForPackage(pkgID). @@ -140,7 +141,7 @@ // NVD CPE record is answered and never becomes a match findings.DoesNotHaveAnyVulnerabilities("CVE-2024-28182") findings.Ignores(). - SelectRelatedPackageIgnores("DistroPackageFixed", + SelectRelatedPackageIgnores(ignorereasons.DistroFixed, "ROOT-OS-ALPINE-318-CVE-2024-28182", "CVE-2024-28182"). ForPackage(pkgID). @@ -174,7 +175,7 @@ // NVD CPE record is answered and never becomes a match findings.DoesNotHaveAnyVulnerabilities("CVE-2024-10524") findings.Ignores(). - SelectRelatedPackageIgnores("DistroPackageFixed", + SelectRelatedPackageIgnores(ignorereasons.DistroFixed, "ROOT-OS-ALPINE-318-CVE-2024-10524", "CVE-2024-10524"). ForPackage(pkgID). @@ -183,7 +184,7 @@ // rootio-socat at rootio fix. CVE-2024-54661 has no NVD CPE entry // so there's no disclosure to suppress — but the matcher still - // emits the NAK as a DistroPackageFixed ignore (it lives in + // emits the NAK as a distro-fixed ignore (it lives in // `fixed` after fixed.Merge(unaffected)). This is the // "rootio-only" combination. t.Run("rootio-socat at rootio fix: NAK ignore only, no disclosure", func(t *testing.T) { @@ -194,7 +195,7 @@ Build() db.Match(t, &matcher, p).Ignores(). - SelectRelatedPackageIgnores("DistroPackageFixed", + SelectRelatedPackageIgnores(ignorereasons.DistroFixed, "ROOT-OS-ALPINE-318-CVE-2024-54661", "CVE-2024-54661"). ForPackage(pkgID). @@ -226,7 +227,7 @@ Build() db.Match(t, &matcher, p).Ignores(). - SelectRelatedPackageIgnore("DistroPackageFixed", "CVE-2024-0727"). + SelectRelatedPackageIgnore(ignorereasons.DistroFixed, "CVE-2024-0727"). ForPackage(pkgID) }) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/grype/matcher/dpkg/rootio_test.go new/grype-0.119.0/grype/matcher/dpkg/rootio_test.go --- old/grype-0.118.0/grype/matcher/dpkg/rootio_test.go 2026-08-27 20:40:29.000000000 +0200 +++ new/grype-0.119.0/grype/matcher/dpkg/rootio_test.go 2026-09-17 17:25:25.000000000 +0200 @@ -3,6 +3,7 @@ import ( "testing" + "github.com/anchore/grype/grype/internal/ignorereasons" "github.com/anchore/grype/grype/match" "github.com/anchore/grype/grype/pkg" "github.com/anchore/grype/internal/dbtest" @@ -47,7 +48,7 @@ expectType match.Type // ignored when expectCVE is empty // expectFixedCVEs lists the CVE IDs that should surface as - // DistroPackageFixed ignores. The rootio NAK alias-unwinds into + // distro-fixed ignores. The rootio NAK alias-unwinds into // both the ROOT-OS-* record ID and the upstream CVE, so the // rootio-suppressed cases list both. expectFixedCVEs []string @@ -65,7 +66,7 @@ { // At the rootio fix, the NAK lands in the unaffected set and // shares the CVE alias with the upstream disclosure. The matcher - // subtracts the disclosure and emits two DistroPackageFixed + // subtracts the disclosure and emits two distro-fixed // ignores: the ROOT-OS-* record and the aliased CVE. name: "rootio-gnupg2 at rootio fix: NAK suppresses upstream disclosure", pkgName: "rootio-gnupg2", @@ -94,7 +95,7 @@ }, { // Regular gnupg2 at the upstream fix is patched per Ubuntu's - // own data. The matcher records a standard DistroPackageFixed + // own data. The matcher records a standard distro-fixed // ignore (no rootio involvement at all). name: "regular gnupg2 at upstream fix: distro-fixed by Ubuntu", pkgName: "gnupg2", @@ -181,7 +182,7 @@ if len(tt.expectFixedCVEs) > 0 { findings.Ignores(). - SelectRelatedPackageIgnores("DistroPackageFixed", tt.expectFixedCVEs...). + SelectRelatedPackageIgnores(ignorereasons.DistroFixed, tt.expectFixedCVEs...). ForPackage(pkgID) } }) @@ -272,7 +273,7 @@ if len(tt.expectFixedCVEs) > 0 { findings.Ignores(). - SelectRelatedPackageIgnores("DistroPackageFixed", tt.expectFixedCVEs...). + SelectRelatedPackageIgnores(ignorereasons.DistroFixed, tt.expectFixedCVEs...). ForPackage(pkgID) } }) diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/grype/matcher/internal/distro.go new/grype-0.119.0/grype/matcher/internal/distro.go --- old/grype-0.118.0/grype/matcher/internal/distro.go 2026-08-27 20:40:29.000000000 +0200 +++ new/grype-0.119.0/grype/matcher/internal/distro.go 2026-09-17 17:25:25.000000000 +0200 @@ -4,6 +4,7 @@ "fmt" "strings" + "github.com/anchore/grype/grype/internal/ignorereasons" "github.com/anchore/grype/grype/match" "github.com/anchore/grype/grype/matcher/internal/result" "github.com/anchore/grype/grype/pkg" @@ -97,7 +98,7 @@ } // Use the SBOM package (not the synthetic upstream) for file ownership — the upstream package doesn't have file metadata. - ignores := OwnershipIgnores(matchPackage(searchPkg, catalogPkg), "DistroPackageFixed", fixed.Vulnerabilities()...) + ignores := OwnershipIgnores(matchPackage(searchPkg, catalogPkg), ignorereasons.DistroFixed, fixed.Vulnerabilities()...) return vulnerable.ToMatches(), ignores, nil } diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/grype/matcher/internal/distro_test.go new/grype-0.119.0/grype/matcher/internal/distro_test.go --- old/grype-0.118.0/grype/matcher/internal/distro_test.go 2026-08-27 20:40:29.000000000 +0200 +++ new/grype-0.119.0/grype/matcher/internal/distro_test.go 2026-09-17 17:25:25.000000000 +0200 @@ -9,6 +9,7 @@ "github.com/stretchr/testify/require" "github.com/anchore/grype/grype/distro" + "github.com/anchore/grype/grype/internal/ignorereasons" "github.com/anchore/grype/grype/match" "github.com/anchore/grype/grype/pkg" "github.com/anchore/grype/grype/version" @@ -301,7 +302,7 @@ require.True(t, ok, "expected IgnoreRule or IgnoreRelatedPackage types") gotVulnIDs.Add(rule.Vulnerability) assert.True(t, rule.IncludeAliases, "expected IncludeAliases to be true") - assert.Contains(t, rule.Reason, "DistroPackageFixed") + assert.Contains(t, rule.Reason, ignorereasons.DistroFixed) assert.NotEmpty(t, rule.Package.Location, "expected location to be set") } diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/grype/vulnerability_matcher.go new/grype-0.119.0/grype/vulnerability_matcher.go --- old/grype-0.118.0/grype/vulnerability_matcher.go 2026-08-27 20:40:29.000000000 +0200 +++ new/grype-0.119.0/grype/vulnerability_matcher.go 2026-09-17 17:25:25.000000000 +0200 @@ -46,6 +46,13 @@ VexProcessor *vex.Processor Alerts AlertsConfig + // IncludeMatcherSuppressions includes matches that were dropped by + // hard-coded rules or matcher-provided ignore filters (e.g. distro + // fixed/NAK records suppressing matches on owned packages) in the + // ignoredMatches results. When false (the default) these are discarded + // after logging, preserving the previous behavior. + IncludeMatcherSuppressions bool + // tracked packages with distro issues (populated during FindMatches) eolDistroPackages []pkg.Package distroDetectionFailed bool @@ -138,7 +145,7 @@ var ignoredMatches []match.IgnoredMatch log.Trace("finding matches against DB") - matches, err := m.searchDBForMatches(ctx, pkgs, progressMonitor) + matches, droppedMatches, err := m.searchDBForMatches(ctx, pkgs, progressMonitor) if err != nil { if match.IsFatalError(err) { return nil, nil, err @@ -166,6 +173,14 @@ ignoredMatches = m.mergeIgnoredMatches(originalIgnoredMatches, ignoredMatches) } + if m.IncludeMatcherSuppressions { + // include matches dropped by hard-coded rules and matcher-provided filters + // (e.g. distro fixed/NAK records suppressing matches on owned packages) so + // callers can see that a match was found and then suppressed; user-rule + // ignores keep their existing positions at the front of the slice + ignoredMatches = m.mergeIgnoredMatches(ignoredMatches, droppedMatches) + } + return &matches, ignoredMatches, nil } @@ -182,13 +197,18 @@ return out } +// searchDBForMatches returns the surviving matches plus every match that was +// dropped by hard-coded rules or matcher-provided ignore filters, so callers +// can surface the dropped set rather than losing it after logging. +// //nolint:funlen func (m *VulnerabilityMatcher) searchDBForMatches( ctx context.Context, packages []pkg.Package, progressMonitor *monitorWriter, -) (match.Matches, error) { +) (match.Matches, []match.IgnoredMatch, error) { var allMatches []match.Match + var allDropped []match.IgnoredMatch var allIgnorers []match.IgnoreFilter matcherIndex, defaultMatcher := newMatcherIndex(m.Matchers) @@ -218,13 +238,13 @@ } for _, theMatcher := range matchAgainst { if err := ctx.Err(); err != nil { - return match.Matches{}, err + return match.Matches{}, nil, err } matches, ignorers, err := callMatcherSafely(theMatcher, m.VulnerabilityProvider, p) if err != nil { if match.IsFatalError(err) { - return match.Matches{}, err + return match.Matches{}, nil, err } log.WithFields("error", err, "package", displayPackage(p)).Warn("matcher returned error") @@ -240,6 +260,7 @@ logPackageMatches(p, additionalMatches) logExplicitDroppedPackageMatches(p, dropped) allMatches = append(allMatches, additionalMatches...) + allDropped = append(allDropped, dropped...) progressMonitor.MatchesDiscovered.Add(int64(len(additionalMatches))) @@ -255,6 +276,7 @@ filtered, dropped := match.ApplyIgnoreFilters(allMatches, ignoredMatchFilter(allIgnorers)) logIgnoredMatches(dropped) log.Debugf("took %v to process %v vulns with %v ignores", time.Since(startTime), len(allMatches), len(allIgnorers)) + allDropped = append(allDropped, dropped...) // get deduplicated set of matches res := match.NewMatches(filtered...) @@ -262,7 +284,7 @@ // update the total discovered matches after removing all duplicates and ignores progressMonitor.MatchesDiscovered.Set(int64(res.Count())) - return res, errors.Join(matcherErrs...) + return res, allDropped, errors.Join(matcherErrs...) } func callMatcherSafely(m match.Matcher, vp vulnerability.Provider, p pkg.Package) (matches []match.Match, ignoredMatches []match.IgnoreFilter, err error) { diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/grype/vulnerability_matcher_dropped_test.go new/grype-0.119.0/grype/vulnerability_matcher_dropped_test.go --- old/grype-0.118.0/grype/vulnerability_matcher_dropped_test.go 1970-01-01 01:00:00.000000000 +0100 +++ new/grype-0.119.0/grype/vulnerability_matcher_dropped_test.go 2026-09-17 17:25:25.000000000 +0200 @@ -0,0 +1,175 @@ +package grype + +// Regression test for anchore/grype#3450 (see also #3282). +// +// Before this change, matches suppressed by hard-coded rules or +// matcher-provided ignore filters (e.g. the distro-fixed ownership rule +// emitted by OwnershipIgnores(..., ignorereasons.DistroFixed, ...)) were dropped +// inside searchDBForMatches after logging and never returned to callers, so +// `--show-suppressed` could not surface a regressed CVE that a FIXED secfix +// entry was hiding (see the fuse-overlayfs-snapshotter / CVE-2026-25679 +// worked example in #3450). +// +// This test asserts, with IncludeMatcherSuppressions set: +// 1. The suppressed bundled-component match reaches the caller in the +// second return of FindMatches / FindMatchesContext. +// 2. Its AppliedIgnoreRules preserve the distro-fixed reason value +// and the vulnerability id. +// +// And with the default (false): the dropped match is discarded exactly as +// before, so existing consumers see no behavior change. + +import ( + "testing" + + "github.com/stretchr/testify/assert" + "github.com/stretchr/testify/require" + + "github.com/anchore/grype/grype/distro" + "github.com/anchore/grype/grype/internal/ignorereasons" + "github.com/anchore/grype/grype/match" + matcherMock "github.com/anchore/grype/grype/matcher/mock" + "github.com/anchore/grype/grype/pkg" + "github.com/anchore/grype/grype/version" + "github.com/anchore/grype/grype/vulnerability" + "github.com/anchore/grype/grype/vulnerability/mock" + "github.com/anchore/syft/syft/artifact" + "github.com/anchore/syft/syft/file" + syftPkg "github.com/anchore/syft/syft/pkg" +) + +func TestVulnerabilityMatcher_DroppedMatchesSurfaceInIgnoredMatches(t *testing.T) { + apkPkgID := pkg.ID("apk-fuse-overlayfs-snapshotter") + stdlibPkgID := pkg.ID("go-stdlib") + + // The Go stdlib CVE as it appears in the NVD provider (grype's nvd:cpe + // entry for cpe:2.3:a:golang:go:*). + stdlibVuln := vulnerability.Vulnerability{ + Reference: vulnerability.Reference{ + ID: "CVE-2026-25679", + Namespace: "nvd:cpe", + }, + PackageName: "stdlib", + Constraint: version.MustGetConstraint("< 1.25.8", version.UnknownFormat), + } + + // APK package [email protected] owns the stdlib binary + // via file overlap. The secfix entry at 2.1.7-r3 says CVE-2026-25679 is + // FIXED, so grype's OwnershipIgnores emits an IgnoreRelatedPackage rule + // with Reason ignorereasons.DistroFixed ("distro-fixed") that suppresses the stdlib match. + apkPkg := pkg.Package{ + ID: apkPkgID, + Name: "fuse-overlayfs-snapshotter", + Version: "2.1.7-r7", + Type: syftPkg.ApkPkg, + Distro: distro.New(distro.Chainguard, "", ""), + Metadata: pkg.ApkMetadata{Files: []pkg.ApkFileRecord{ + {Path: "/usr/bin/containerd-fuse-overlayfs-grpc"}, + }}, + } + stdlibPkg := pkg.Package{ + ID: stdlibPkgID, + Name: "stdlib", + Version: "go1.24.13", + Type: syftPkg.GoModulePkg, + Locations: file.NewLocationSet( + file.NewLocation("/usr/bin/containerd-fuse-overlayfs-grpc"), + ), + RelatedPackages: map[artifact.RelationshipType][]*pkg.Package{ + artifact.OwnershipByFileOverlapRelationship: { + {ID: apkPkgID, Name: "fuse-overlayfs-snapshotter"}, + }, + }, + } + + vp := mock.VulnerabilityProvider(stdlibVuln) + + // APK matcher returns no matches (r7 satisfies the FIXED constraint at + // r3, so the APK itself is not vulnerable) but returns an + // IgnoreRelatedPackage filter carrying the distro-fixed reason + // string that OwnershipIgnores uses in production + // (grype/matcher/internal/distro.go). + apkMatcher := matcherMock.New(syftPkg.ApkPkg, func(_ vulnerability.Provider, p pkg.Package) ([]match.Match, []match.IgnoreFilter, error) { + if p.Type != syftPkg.ApkPkg { + return nil, nil, nil + } + return nil, []match.IgnoreFilter{ + match.IgnoreRelatedPackage{ + Reason: ignorereasons.DistroFixed, + RelationshipType: artifact.OwnershipByFileOverlapRelationship, + VulnerabilityID: stdlibVuln.ID, + RelatedPackageID: p.ID, + }, + }, nil + }) + + // Go matcher returns the stdlib match for the CVE (which will then be + // suppressed by the apk matcher's returned filter). + goMatcher := matcherMock.New(syftPkg.GoModulePkg, func(_ vulnerability.Provider, p pkg.Package) ([]match.Match, []match.IgnoreFilter, error) { + if p.Type != syftPkg.GoModulePkg { + return nil, nil, nil + } + return []match.Match{ + { + Vulnerability: stdlibVuln, + Package: p, + Details: match.Details{ + { + Type: match.CPEMatch, + Confidence: 1.0, + Matcher: "go-matcher", + }, + }, + }, + }, nil, nil + }) + + t.Run("opt-in surfaces the dropped match", func(t *testing.T) { + m := &VulnerabilityMatcher{ + VulnerabilityProvider: vp, + Matchers: []match.Matcher{apkMatcher, goMatcher}, + IncludeMatcherSuppressions: true, + } + + remaining, ignored, err := m.FindMatches( + []pkg.Package{apkPkg, stdlibPkg}, + pkg.Context{}, + ) + require.NoError(t, err) + + assert.Zero(t, remaining.Count(), + "main match set should be empty; the stdlib match should have been suppressed by the distro-fixed rule") + + require.Len(t, ignored, 1, + "expected exactly one entry in ignoredMatches carrying the suppressed stdlib match") + got := ignored[0] + + assert.Equal(t, "CVE-2026-25679", got.Match.Vulnerability.ID) + assert.Equal(t, "stdlib", got.Match.Package.Name) + assert.Equal(t, "go1.24.13", got.Match.Package.Version) + + // AppliedIgnoreRules: the OwnershipIgnores reason string and vulnerability + // id are preserved verbatim. + require.NotEmpty(t, got.AppliedIgnoreRules) + assert.Equal(t, ignorereasons.DistroFixed, got.AppliedIgnoreRules[0].Reason) + assert.Equal(t, "CVE-2026-25679", got.AppliedIgnoreRules[0].Vulnerability) + }) + + t.Run("default discards the dropped match as before", func(t *testing.T) { + m := &VulnerabilityMatcher{ + VulnerabilityProvider: vp, + Matchers: []match.Matcher{apkMatcher, goMatcher}, + } + + remaining, ignored, err := m.FindMatches( + []pkg.Package{apkPkg, stdlibPkg}, + pkg.Context{}, + ) + require.NoError(t, err) + + assert.Zero(t, remaining.Count(), + "main match set should be empty; the stdlib match should have been suppressed by the distro-fixed rule") + assert.Empty(t, ignored, + "with IncludeMatcherSuppressions unset, dropped matches must not appear in ignoredMatches") + }) +} diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/grype/vulnerability_matcher_test.go new/grype-0.119.0/grype/vulnerability_matcher_test.go --- old/grype-0.118.0/grype/vulnerability_matcher_test.go 2026-08-27 20:40:29.000000000 +0200 +++ new/grype-0.119.0/grype/vulnerability_matcher_test.go 2026-09-17 17:25:25.000000000 +0200 @@ -16,6 +16,7 @@ "github.com/anchore/grype/grype/event" "github.com/anchore/grype/grype/event/monitor" "github.com/anchore/grype/grype/grypeerr" + "github.com/anchore/grype/grype/internal/ignorereasons" "github.com/anchore/grype/grype/match" "github.com/anchore/grype/grype/matcher" matcherMock "github.com/anchore/grype/grype/matcher/mock" @@ -1152,14 +1153,14 @@ ignores = append(ignores, match.IgnoreRule{ Vulnerability: nakVuln.ID, IncludeAliases: true, - Reason: "Explicit APK NAK", + Reason: ignorereasons.DistroNAK, Package: match.IgnoreRulePackage{ Location: f.Path, }, }) } ignores = append(ignores, match.IgnoreRelatedPackage{ - Reason: "Explicit APK NAK by Ownership", + Reason: ignorereasons.DistroNAK, RelationshipType: artifact.OwnershipByFileOverlapRelationship, VulnerabilityID: nakVuln.ID, RelatedPackageID: p.ID, diff -urN '--exclude=CVS' '--exclude=.cvsignore' '--exclude=.svn' '--exclude=.svnignore' old/grype-0.118.0/test/quality/test-db new/grype-0.119.0/test/quality/test-db --- old/grype-0.118.0/test/quality/test-db 2026-08-27 20:40:29.000000000 +0200 +++ new/grype-0.119.0/test/quality/test-db 2026-09-17 17:25:25.000000000 +0200 @@ -1 +1 @@ -https://grype.anchore.io/databases/v6/vulnerability-db_v6.1.9_2026-08-01T00:38:20Z_1785567576.tar.zst +https://grype.anchore.io/databases/v6/vulnerability-db_v6.1.9_2026-09-01T00:38:09Z_1788244329.tar.zst ++++++ grype.obsinfo ++++++ --- /var/tmp/diff_new_pack.8dHCDm/_old 2026-09-18 22:07:48.137771278 +0200 +++ /var/tmp/diff_new_pack.8dHCDm/_new 2026-09-18 22:07:48.144771571 +0200 @@ -1,5 +1,5 @@ name: grype -version: 0.118.0 -mtime: 1787856029 -commit: 756eb9a24f7beeafb6871a24e943e8a3ae210695 +version: 0.119.0 +mtime: 1789658725 +commit: b6f5194537747ee7f705f4113069ac9eb269919f ++++++ vendor.tar.gz ++++++ /work/SRC/openSUSE:Factory/grype/vendor.tar.gz /work/SRC/openSUSE:Factory/.grype.new.383539/vendor.tar.gz differ: char 133, line 1
