Angaben zum Datum
Datum des passenden GitHub-Releases.
Erstmals gesehen am .
OSV Scanner von Google
OSV Scanner 2.6.0
Version 2.6.0 veröffentlicht ein Multi-Arch-Image (linux/arm64) für osv-scanner-action, ergänzt eine Retry-Richtlinie mit exponentiellem Backoff für transiente gRPC-Fehler und verbessert über osv-scalibr die Lockfile-Auswertung (Git-URLs, pkg:git-PURLs, SPDX-Ausgabe) sowie die Unterstützung neuer Dateitypen per --experimental-plugins.
Features:
- Feature #2888 Publish multi-arch (
linux/arm64) image forosv-scanner-action. - Feature #3066 Configure retry policy with exponential backoff for transient gRPC errors in scalibr plugins.
- Dependency scanning & lockfile improvements via
osv-scalibr:- Extract Git repository URLs and support local OSV tag matching for Git-based dependencies in JavaScript lockfiles (
package-lock.json,yarn.lock,pnpm-lock.yaml,bun.lock). - Assign
pkg:gitPURL type to Git commit-pinned dependencies across JS and Cargo lockfiles to avoid false positives against registry packages (#2863). - Retain packages without a version or PURL in SPDX output (google/osv-scalibr#2375) and merge related packages based on lineage relationships.
- Extract Git repository URLs and support local OSV tag matching for Git-based dependencies in JavaScript lockfiles (
- New extractors and plugin support via
osv-scalibr:- Many additional filetypes are supported. These are not enabled by default yet, so if you need a particular new filetype, use
--experimental-pluginsflag. See "Supported Inventory Types" for the extractor name.
- Many additional filetypes are supported. These are not enabled by default yet, so if you need a particular new filetype, use