v0.5.0
Notable changes
- 🔧 Adds support for scanner integrations via plugins. Please see scanner plugin template for a quick start template.
- 📤 Adds support for VEX output.
- 📝 Support for buildkit source policies for replacing tooling image.
- 🔐 Support for remote buildkit mTLS-over-TCP.
- 🗜️ Support for Azure Linux RPM zstd compression switch.
Changelog
- 67c7e29 chore: bump github.com/moby/buildkit from 0.12.2 to 0.12.3 (#386)
- b592060 chore: bump google.golang.org/grpc from 1.58.3 to 1.59.0 (#385)
- d67c582 chore: bump the all group with 2 updates (#384)
- f8af3e9 docs: update issue template with contribution details (#379)
- 89eddc6 ci: add govulncheck (#382)
- dd45fe1 docs: add plugin docs (#360)
- 013c118 chore: bump the all group with 1 update (#371)
- 5bca058 chore: bump @babel/traverse from 7.20.12 to 7.23.2 in /website (#378)
- c42fa8f chore: bump google.golang.org/grpc from 1.58.2 to 1.58.3 (#374)
- f14392d chore: bump github.com/containerd/containerd from 1.7.6 to 1.7.7 (#372)
- 4eacf06 feat: add modular scanners (#261)
- d514256 chore: bump golang.org/x/net from 0.15.0 to 0.17.0 (#367)
- f893559 fix: move openvex packages as subcomponents (#366)
- 1a7c070 fix: migrate to yumdownloader (#377)
- ff4fb01 ci: ignore centos CVE-2020-22218 and CVE-2023-3341 (#369)
- ed77375 fix: ignore cache for "apt update" (#364)
- 949d6c2 docs: update versioned docs faq (#363)
- b840d42 chore: bump the all group with 2 updates (#362)
- 912b3a4 chore: bump github.com/spf13/viper from 1.16.0 to 1.17.0 (#356)
- e87aec9 docs: update faq with not patch (#347)
- 462fb5a chore: remove qualys parser (#350)
- 9aa25ec ci: add gha and npm groups (#359)
- 0237956 chore: bump github/codeql-action from 2.21.9 to 2.22.0 (#353)
- 7be1028 chore: bump golang.org/x/sync from 0.3.0 to 0.4.0 (#348)
- 7e2dca5 chore: bump github.com/distribution/distribution from 2.8.2+incompatible to 2.8.3+incompatible (#345)
- 4dd928e feat: add source policy (#341)
- d3082c5 chore: bump postcss from 8.4.21 to 8.4.31 in /website (#344)
- 76efad1 chore: bump step-security/harden-runner from 2.5.1 to 2.6.0 (#343)
- f587cbb chore: bump github.com/distribution/distribution from 2.8.2+incompatible to 2.8.3+incompatible (#342)
- 35b54ca chore: bump prism-react-renderer from 2.0.6 to 2.1.0 in /website (#340)
- 3ba01ef fix: add release and github action pages to sidebar (#338)
- dff7b28 docs: document copa github action (#334)
- fbad7d1 docs: add release doc (#333)
- d2b0447 chore: bump github/codeql-action from 2.21.8 to 2.21.9 (#331)
- 58c4020 docs: add fossa badge (#328)
- 28191f1 docs: Fix typo in quick-start.md (#327)
- e6a6b76 docs(website): add logo (#319)
- ed7d690 chore: bump @docusaurus/module-type-aliases from 2.4.1 to 2.4.3 in /website (#325)
- bf2f197 chore: bump @docusaurus/core from 2.4.1 to 2.4.3 in /website (#324)
- 0eea4ea chore: bump actions/checkout from 4.0.0 to 4.1.0 (#326)
- b124fa8 chore: bump @docusaurus/preset-classic from 2.4.1 to 2.4.3 in /website (#323)
- e8b5e13 chore: bump github.com/antchfx/xmlquery from 1.3.17 to 1.3.18 (#322)
- eba1ba5 fix: add package permissions (#317)
- 3886cb8 docs: cncf onboarding items (#312)
- 141363d chore: bump google.golang.org/grpc from 1.58.1 to 1.58.2 (#313)
- 22f060a docs(website): update favicon (#311)
- 6396212 chore: bump github/codeql-action from 2.21.7 to 2.21.8 (#310)
- a4c4abe feat: mTLS-over-TCP buildkit (#284)
- 6a8afc2 chore: bump @tsconfig/docusaurus from 2.0.0 to 2.0.1 in /website (#309)
- b376b87 chore: bump github.com/aquasecurity/trivy from 0.45.0 to 0.45.1 (#308)
- deeae56 docs: switch to apache license for CNCF compliance (#304)
- 751ebf9 chore: bump github/codeql-action from 2.21.6 to 2.21.7 (#307)
- 13e3b39 chore: bump github.com/opencontainers/image-spec from 1.1.0-rc4 to 1.1.0-rc5 (#306)
- 10fb6ef chore: bump google.golang.org/grpc from 1.58.0 to 1.58.1 (#305)
- 62c9adf chore: bump github/codeql-action from 2.21.5 to 2.21.6 (#303)
- 2df832f chore: bump github.com/containerd/containerd from 1.7.3 to 1.7.6 (#302)
- da9de7a chore: bump goreleaser/goreleaser-action from 4.6.0 to 5.0.0 (#301)
- 0040674 chore: bump docker/setup-qemu-action from 2.2.0 to 3.0.0 (#300)
- 8c24605 chore: bump docker/setup-buildx-action from 2.10.0 to 3.0.0 (#299)
- 466ac55 chore: bump actions/cache from 3.3.1 to 3.3.2 (#297)
- 075d4eb chore: bump actions/dependency-review-action from 3.0.8 to 3.1.0 (#296)
- 72a2b81 chore: bump github.com/aquasecurity/trivy from 0.44.1 to 0.45.0 (#280)
- 9632d7d chore: bump github.com/docker/cli from 24.0.5+incompatible to 24.0.6+incompatible (#286)
- 9703f57 chore: bump google.golang.org/grpc from 1.57.0 to 1.58.0 (#290)
- a0605d3 chore: bump github.com/cyphar/filepath-securejoin from 0.2.3 to 0.2.4 (#292)
- 45604af chore: bump goreleaser/goreleaser-action from 4.4.0 to 4.6.0 (#287)
- 1b26c46 chore: bump actions/checkout from 3.6.0 to 4.0.0 (#282)
- 5a9cdf3 chore: bump actions/upload-artifact from 3.1.2 to 3.1.3 (#291)
- edcf49e docs: add slack and meeting info (#289)
- d89e401 fix: handle mariner zstd compression (#295)
- 013f758 docs: add faq section to docs (#281)
- 88b36ca docs: use dockerhub instead of mcr (#267)
- 4182a4c chore: bump github/codeql-action from 2.21.4 to 2.21.5 (#279)
- dee4ad6 chore: bump github.com/moby/buildkit from 0.12.1 to 0.12.2 (#271)
- aa80538 chore: bump actions/checkout from 3.5.3 to 3.6.0 (#274)
- a72c494 feat: vex output (#272)
- 67e8932 chore: bump docker/setup-buildx-action from 2.9.1 to 2.10.0 (#277)
- 4b79dfe chore: bump typescript from 5.1.6 to 5.2.2 in /website (#278)
- dbdcbfa docs: generate v0.4.x docs and fix doc gen (#265)
New Contributors
- @RealHarshThakur made their first contribution in #284
- @tomdev made their first contribution in #327
Full Changelog: v0.4.0...v0.5.0