Zum Inhalt springen

OSV Scanner Updates & Release Notes

10 Einträge aus 1 Quelle. Zuletzt aktualisiert:

Folge OSV Scanner, um die Release Notes in deinen Feed zu holen.

Angaben zum Datum

Datum des passenden GitHub-Releases.

Erstmals gesehen am .

OSV Scanner von Google

OSV Scanner 2.6.0

Version 2.6.0 veröffentlicht ein Multi-Arch-Image (linux/arm64) für osv-scanner-action, ergänzt eine Retry-Richtlinie mit exponentiellem Backoff für transiente gRPC-Fehler und verbessert über osv-scalibr die Lockfile-Auswertung (Git-URLs, pkg:git-PURLs, SPDX-Ausgabe) sowie die Unterstützung neuer Dateitypen per --experimental-plugins.

Features:

  • Feature #2888 Publish multi-arch (linux/arm64) image for osv-scanner-action.
  • Feature #3066 Configure retry policy with exponential backoff for transient gRPC errors in scalibr plugins.
  • Dependency scanning & lockfile improvements via osv-scalibr:
    • Extract Git repository URLs and support local OSV tag matching for Git-based dependencies in JavaScript lockfiles (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock).
    • Assign pkg:git PURL type to Git commit-pinned dependencies across JS and Cargo lockfiles to avoid false positives against registry packages (#2863).
    • Retain packages without a version or PURL in SPDX output (google/osv-scalibr#2375) and merge related packages based on lineage relationships.
  • New extractors and plugin support via osv-scalibr:
    • Many additional filetypes are supported. These are not enabled by default yet, so if you need a particular new filetype, use --experimental-plugins flag. See "Supported Inventory Types" for the extractor name.

Fixes: …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum des passenden GitHub-Releases.

Erstmals gesehen am .

OSV Scanner von Google

OSV Scanner 2.5.1

Version 2.5.1 behebt Fehler: Paket-Namespaces bleiben bei osv.dev-Abfragen erhalten, die Umgebungsvariable OSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY wird wieder unterstützt und lokales Matching mit --offline-vulnerabilities funktioniert auch bei NetworkOnline.

Fixes:

  • Preserve package namespaces when querying osv.dev API (fixes #2978).
  • Re-add support for the OSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY environment variable (fixes #2983).
  • Fix local vulnerability matching (--offline-vulnerabilities) not working when network capability is NetworkOnline.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum des passenden GitHub-Releases.

Erstmals gesehen am .

OSV Scanner von Google

OSV Scanner 2.5.0

Version 2.5.0 stellt Scanning, Filterung und Matching vollständig auf die osv-scalibr-Pipeline um, ergänzt den javascript/vsix-Extractor und weitere Ökosystem-Zuordnungen und behebt Fehler bei RHEL-Epochen, requirements.txt sowie NPM- und Composer-PURLs.

Features & Refactors:

  • Full OSV-Scalibr pipeline: Migrated scanning, filtering, and matching in osv-scanner to use osv-scalibr end-to-end, so most plugins that's supported in osv-scalibr should be supported via the --experimental-plugins flag (#2935).

  • New extractors and ecosystem support via osv-scalibr:

    • Add javascript/vsix extractor to support scanning VS Code extension (.vsix) packages.
    • Extend ecosystem mapping for:
      • SUSE
      • Azure Linux / Mariner
      • Alpaquita
      • Mageia
      • openSUSE Leap
      • Debian and Ubuntu PURL
  • PURL Type Resolution: Updated osvscannerjson extractor to map ecosystem names to valid PURL types (golang, gem, cargo, npm, etc.).

Fixes:

  • Bug #2915 Fix issue where osv-scanner reported already-fixed advisories as unfixed for RHEL-family RPM packages (Red Hat, AlmaLinux, Rocky Linux) with epochs by sending epoch-qualified versions.
  • Fix Python requirements.txt extractor in osv-scalibr, specifically regular expressions used to extract package names and per-requirement options (Fixes #2940, #2931)
  • Fix NPM and Composer PURL generation in osv-scalibr, separating package namespace (scope) from package name

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum des passenden GitHub-Releases.

Erstmals gesehen am .

OSV Scanner von Google

OSV Scanner 2.4.0

Version 2.4.0 unterstützt CycloneDX 1.7, aktiviert standardmäßig die Plugins für .csproj, nugetcpm und swift/packageresolved, erkennt Alpine-Distro-Versionen aus PURL-Qualifiern, bietet eine Docker-Variante des pre-commit-Hooks, die Einstellung ScanGoModVersion und das Scannen von Canonical-Chisel-Images.

Features:

  • Feature #2815 Add support for the CycloneDX 1.7 specification (bumps cyclonedx-go to v0.11.0).
  • Feature #2799 Enable .csproj and Central Package Management (nugetcpm) source scanning plugins by default.
  • Feature #2871 Extract and parse Alpine OS distro version (e.g. Alpine:v3.17, Alpine:edge) from PURL distro qualifiers to scan packages under their respective Alpine ecosystems.
  • Feature #2801 Enable the swift/packageresolved plugin by default to support SwiftURL vulnerability scans.
  • Feature #2666 Add a Docker-based variant of the pre-commit hook in .pre-commit-hooks.yaml to avoid local compilation.
  • Feature #2637 Add a new configuration setting ScanGoModVersion (disabled by default) to avoid parsing toolchain version directives directly from go.mod, preventing misleading warnings.
  • Feature #2772 Scan container images built with Canonical Chisel by enabling the os/chisel extractor plugin.

Fixes: …

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum des passenden GitHub-Releases.

Erstmals gesehen am .

OSV Scanner von Google

OSV Scanner 2.3.8 (inkl. 2.3.7)

Die Versionen 2.3.7/2.3.8 beheben Installationsprobleme mit go install, überspringen Pakete mit kurzen Commit-Hashes statt den Scan abzubrechen und sichern die Dateipfad-Behandlung mit os.OpenRoot ab.

Fixes:

  • Fix installation issues with go install due to dependency conflicts (downgrade containerd/cgroups/v3, moby/buildkit and opencontainers/runtime-spec).
  • Bug #2762 Skip packages with short commit hashes instead of aborting scan.
  • Bug #2781 Secure file path handling with os.OpenRoot.
  • Bug #2766 Correct typos across docs, configs, and Go source.

Misc:

  • Update osv-scalibr to v0.4.6-0.20260504042738-9293bfa4f86f.
  • Remove replace directive (#2782).
  • Update contributing.md (#2779).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum des passenden GitHub-Releases.

Erstmals gesehen am .

OSV Scanner von Google

OSV Scanner 2.3.6

Version 2.3.6 unterstützt Regex-Matching für Paketnamen-Overrides und das Scannen von Homebrew-Inventar und behebt Fehler, darunter die Bereinigung von Zeilenumbrüchen in Ausgaben zur Verhinderung von Workflow-Command-Injection in GitHub Actions.

Features:

  • Feature #2658 Support regex matching for package name overrides.
  • Feature #2510 Scan Homebrew inventory using git repository metadata.

Fixes:

  • Bug #2750 Sanitize \r/\n in default/table/vertical output to prevent GitHub Actions workflow command injection.
  • Bug #2641 Correctly output packages from osv-scanner.json source in spdx format.
  • Bug #2729 Increase color contrast of vulnerability stats.
  • Bug #2664 Remove second newline at end of vertical output.
  • Bug #2669 Sanitize \r in gh-annotations to prevent GitHub Actions workflow command injection.

Misc:

  • Update osv-scalibr to v0.4.6-0.20260428235529-7791e288d6c1.
  • Update Go version to 1.26.2 (#2706).

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum des passenden GitHub-Releases.

Erstmals gesehen am .

OSV Scanner von Google

OSV Scanner 2.3.3

Version 2.3.3 ergänzt das Flag --exclude zum Überspringen von Pfaden, einen pylock-Extractor und Basis-Image-Informationen im Header der Container-Scan-Ausgabe.

Features:

  • Feature #2458 Add --exclude flag to skip paths during scanning.
  • Feature #2477 Add pylock extractor.
  • Feature #2475 Add base image info to container scanning output header (in table, markdown and vertical formats).

Misc:

  • Update Go version to 1.25.7.
  • Update osv-scalibr from v0.4.1 to v0.4.2. Release note.
  • Refactor to better align with osv-scalibr plugins and inventory data structure.

Originalquelle(öffnet in neuem Tab)Problem melden

Angaben zum Datum

Datum des passenden GitHub-Releases.

Erstmals gesehen am .

OSV Scanner von Google

OSV Scanner 2.3.2

Version 2.3.2 verbessert die Leistung des lokalen Scannens durch geringeren Speicherverbrauch und behebt Fehler beim MCP-Tool get_vulnerability_details, bei Git-Abfragen in osv-scanner.json und bei der Nachverfolgung von Ignore-Einträgen.

This release includes performance improvements for local scanning, reducing memory usage and avoiding unnecessary advisory loading. It also fixes issues with MCP's get_vulnerability_details tool, git queries in osv-scanner.json, and ignore entry tracking, along with documentation updates.

Fixes:

  • Bug #2415 Add more PURL-to-ecosystem mappings
  • Bug #2422 MCP error for get_vulnerability_id because type definition is incorrect.
  • Bug #2460 Enable osv-scanner.json git queries
  • Bug #2456 Properly track if an ignore entry has been used
  • Bug #2450 Performance: Avoid loading the entire advisory unless it will actually be used
  • Bug #2445 Performance: Don't read the entire zip into memory
  • Bug #2433 Allow specifying user agent in v2 osvscanner package

Misc:

  • Misc #2453 Switch from gopkg.in/yaml.v3 to go.yaml.in/yaml/v3
  • Misc #2447 Include bun.lock as a supported lockfile
  • Misc #2444 Document GoVersionOverride in configuration.md

Originalquelle(öffnet in neuem Tab)Problem melden

Datum unbekanntAngaben zum Datum

Kein Datum in der Quelle. Der Eintrag stammt aus dem ersten Abruf der Quelle, der Tag der Aufnahme sagt nichts über das Erscheinen.

Erstmals gesehen am .

OSV Scanner von Google

OSV Scanner 2.3.4 (verworfen)

Version 2.3.4 wurde wegen Problemen im Release-Workflow verworfen, enthielt aber transitives Scannen für Python-requirements.txt über die deps.dev-API, die Möglichkeit unsichere Plugins zuzulassen sowie Fehlerbehebungen und ein osv-scalibr-Update auf v0.4.5.

[!NOTE] This release was abandoned, due to issues with the release workflow.

Features:

  • Feature #2571 Enable transitive scanning for Python requirements.txt files using the deps.dev API.
  • Feature #2649 Add ability to allow unsafe plugins, logging a warning when any unsafe plugin is enabled.

Fixes:

  • Bug #2630 Improve startup performance on Windows Terminal by updating lipgloss.
  • Bug #2599 Ensure the package deprecation enricher respects the same configuration as other plugins.
  • Bug #2600 Ensure the Java extractor plugin for call analysis respects the same configuration as other plugins.

Misc:

Originalquelle(öffnet in neuem Tab)Problem melden