Skip to content

[updatecli] Bump anchore/syft version to v1.50.0 - #288

Open
github-actions[bot] wants to merge 4 commits into
mainfrom
updatecli_main_06629c727631ead9d59d398175d9c1ab73d29ea86dc2914410206bab924892fb
Open

[updatecli] Bump anchore/syft version to v1.50.0#288
github-actions[bot] wants to merge 4 commits into
mainfrom
updatecli_main_06629c727631ead9d59d398175d9c1ab73d29ea86dc2914410206bab924892fb

Conversation

@github-actions

@github-actions github-actions Bot commented Jun 26, 2026

Copy link
Copy Markdown
Contributor

Bump anchore/syft version

Update version in aqua.yaml

1 file(s) updated with "${1}v1.50.0": * aqua.yaml

v1.50.0
### Added Features

- Add bun binary classifier [PR [#5103](https://github.com/anchore/syft/pull/5103) @rezmoss]

### Bug Fixes

- Fix Cargo PURLs for local workspace packages [PR [#5105](https://github.com/anchore/syft/pull/5105) @3nesdeniz]
- Decode golang symbols [PR [#5089](https://github.com/anchore/syft/pull/5089) @wagoodman]
- CPE vendor field incorrectly includes publisher URL for SUSE RPM packages [Issue [#5073](https://github.com/anchore/syft/issues/5073)] [PR [#5081](https://github.com/anchore/syft/pull/5081) @Eljees]
- apk-db-cataloger silently drops the entire APK catalog when one installed-DB field exceeds 64 KB [Issue [#5094](https://github.com/anchore/syft/issues/5094)] [PR [#5100](https://github.com/anchore/syft/pull/5100) @cyphercodes]

### Additional Changes

- package-lock.json v1: nested dependencies entries are never cataloged (flat top-level iteration only) [Issue [#5101](https://github.com/anchore/syft/issues/5101)] [PR [#5108](https://github.com/anchore/syft/pull/5108) @Eljees]
- consider vendored golang packages in module attribution [PR [#5093](https://github.com/anchore/syft/pull/5093) @kzantow]
- Fix inverted bounds check dropping every Erlang string with a backslash [PR [#5110](https://github.com/anchore/syft/pull/5110) @arpitjain099]

### Dependencies

14 dependency changes (14 updated). 1 vulnerability remediated.

**🟢 Remediated (1)**

- [GHSA-hrxh-6v49-42gf](https://github.com/advisories/GHSA-hrxh-6v49-42gf) (High) — google.golang.org/grpc

<details>
<summary>Updated (14 packages)</summary>

- github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp `v1.31.0` → `v1.32.0`
- github.com/cncf/xds/go `v0.0.0-ee656c7` → `v0.0.0-dba9d58`
- github.com/envoyproxy/go-control-plane/envoy `v1.36.0` → `v1.37.0`
- github.com/envoyproxy/protoc-gen-validate `v1.3.0` → `v1.3.3`
- github.com/gpustack/gguf-parser-go `v0.24.1` → `v0.25.0`
- go.opentelemetry.io/contrib/detectors/gcp `v1.39.0` → `v1.43.0`
- google.golang.org/genproto/googleapis/api `v0.0.0-9d38bb4` → `v0.0.0-afd174a`
- google.golang.org/genproto/googleapis/rpc `v0.0.0-6f92a3b` → `v0.0.0-afd174a`
- google.golang.org/grpc `v1.80.0` → `v1.82.1` **(🟢 remediated [GHSA-hrxh-6v49-42gf](https://github.com/advisories/GHSA-hrxh-6v49-42gf))**
- modernc.org/cc/v4 `v4.28.4` → `v4.29.0`
- modernc.org/ccgo/v4 `v4.34.4` → `v4.34.6`
- modernc.org/gc/v3 `v3.1.3` → `v3.1.4`
- modernc.org/libc `v1.73.4` → `v1.74.1`
- modernc.org/sqlite `v1.53.0` → `v1.54.0`
</details>

**[(Full Changelog)](https://github.com/anchore/syft/compare/v1.49.0...v1.50.0)**

v1.49.0
### Added Features

- Support for `application/vnd.oci.image.index.v1+json` manifests in root OCI layout [Issue [#1545](https://github.com/anchore/syft/issues/1545)] [PR [#5074](https://github.com/anchore/syft/pull/5074) @jasonpaulos]

### Bug Fixes

- Misinterpretation of Multiple replace Directives in Golang [Issue [#2721](https://github.com/anchore/syft/issues/2721)] [PR [#5069](https://github.com/anchore/syft/pull/5069) @ychampion]

### Dependencies

16 dependency changes (16 updated).

<details>
<summary>Updated (16 packages)</summary>

- github.com/anchore/go-rpmdb `v0.1.0` → `v0.2.0`
- github.com/anchore/stereoscope `v0.2.2` → `v0.3.0`
- github.com/containerd/containerd/v2 `v2.3.2` → `v2.3.3`
- github.com/docker/cli `v29.5.3+incompatible` → `v29.6.1+incompatible`
- github.com/gkampitakis/go-snaps `v0.5.22` → `v0.5.23`
- github.com/moby/moby/api `v1.54.2` → `v1.55.0`
- github.com/moby/moby/client `v0.4.1` → `v0.5.0`
- github.com/pelletier/go-toml/v2 `v2.3.1` → `v2.4.3`
- golang.org/x/crypto `v0.53.0` → `v0.54.0`
- golang.org/x/mod `v0.37.0` → `v0.38.0`
- golang.org/x/net `v0.56.0` → `v0.57.0`
- golang.org/x/sync `v0.21.0` → `v0.22.0`
- golang.org/x/sys `v0.46.0` → `v0.47.0`
- golang.org/x/term `v0.44.0` → `v0.45.0`
- golang.org/x/text `v0.38.0` → `v0.40.0`
- golang.org/x/tools `v0.47.0` → `v0.48.0`
</details>

**[(Full Changelog)](https://github.com/anchore/syft/compare/v1.48.0...v1.49.0)**

v1.48.0
### Added Features

- emit dependency relationships from mix.lock [PR [#4985](https://github.com/anchore/syft/pull/4985) @cgreeno]
- add safe tensor model type to SBOM output [PR [#4844](https://github.com/anchore/syft/pull/4844) @spiffcs]
- Capture golang binary symbols [PR [#4988](https://github.com/anchore/syft/pull/4988) @spiffcs]
- Detect Ubuntu Pro/ESM extended support [PR [#5028](https://github.com/anchore/syft/pull/5028) @wagoodman]
- Add scan duration timer to Syft [Issue [#4587](https://github.com/anchore/syft/issues/4587)] [PR [#4858](https://github.com/anchore/syft/pull/4858) @ChrisJr404]
- Support for `vcpkg` [Issue [#2110](https://github.com/anchore/syft/issues/2110)] [PR [#4081](https://github.com/anchore/syft/pull/4081) @gabetrau]
- Add macOS `.app` cataloger [Issue [#4010](https://github.com/anchore/syft/issues/4010)] [PR [#4490](https://github.com/anchore/syft/pull/4490) @rezmoss]
- Add support for Kerberos 5 library cataloging [Issue [#4780](https://github.com/anchore/syft/issues/4780)] [PR [#4781](https://github.com/anchore/syft/pull/4781) @nadimz]
- Include date of scan in results [Issue [#3910](https://github.com/anchore/syft/issues/3910)]

### Bug Fixes

- use printf instead of echo to fix ANSI color output [PR [#4978](https://github.com/anchore/syft/pull/4978) @Jouini-Mohamed-Chaker]
- Strip peer-dep suffix from deno.lock npm keys [PR [#5055](https://github.com/anchore/syft/pull/5055) @Synvoya]
- Allow more PEP440-compliant characters in python versions [PR [#4964](https://github.com/anchore/syft/pull/4964) @kzantow]
- PE case-insensitive extensions (Win32/ISO 9660 compatibility) [PR [#4996](https://github.com/anchore/syft/pull/4996) @activeobd]
- Fix panic parsing a rockspec comment that ends at EOF [PR [#5053](https://github.com/anchore/syft/pull/5053) @arpitjain099]
- Fix Debian point release detection [PR [#4997](https://github.com/anchore/syft/pull/4997) @OsamaSE]
- Fix `mix.lock` git/path deps mislabeled as hex.pm packages with bogus PURLs [PR [#5041](https://github.com/anchore/syft/pull/5041) @Synvoya]
- npm redis client generates no CPE [Issue [#5011](https://github.com/anchore/syft/issues/5011)] [PR [#5012](https://github.com/anchore/syft/pull/5012) @rezmoss]
- Debug Docker images are running as nonroot user [Issue [#4113](https://github.com/anchore/syft/issues/4113)] [PR [#4608](https://github.com/anchore/syft/pull/4608) @spiffcs]
- libxml2 gets the wrong cpe vendor [Issue [#5015](https://github.com/anchore/syft/issues/5015)] [PR [#5016](https://github.com/anchore/syft/pull/5016) @rezmoss]
- wrong purl for spring-ldap-core dependency [Issue [#4030](https://github.com/anchore/syft/issues/4030)] [PR [#4908](https://github.com/anchore/syft/pull/4908) @jonasboos]
- Swift: CVEs missed by Grype when using Syft-generated SBOMs – missing group field breaks PURL matching [Issue [#3961](https://github.com/anchore/syft/issues/3961)] [PR [#4785](https://github.com/anchore/syft/pull/4785) @SAY-5]
- conanfile.txt: dependencies after a comment line in [requires] are not detected [Issue [#5017](https://github.com/anchore/syft/issues/5017)] [PR [#5020](https://github.com/anchore/syft/pull/5020) @jfjrh2014]
- dotnet cataloger can't find packages from deps.json in linux elf single-file bundles [Issue [#4514](https://github.com/anchore/syft/issues/4514)] [PR [#4517](https://github.com/anchore/syft/pull/4517) @rezmoss]
- Go template sprig date functions not defined [Issue [#2372](https://github.com/anchore/syft/issues/2372)] [PR [#4644](https://github.com/anchore/syft/pull/4644) @sputnik-mac]
- CycloneDX BOM contains invalid externalReferences URL from unresolved Ruby gemspec interpolation (e.g. #{s.name}) [Issue [#4720](https://github.com/anchore/syft/issues/4720)] [PR [#4782](https://github.com/anchore/syft/pull/4782) @SAY-5]

### Dependencies

9 dependency changes (8 updated, 1 added).

<details>
<summary>Updated (8 packages)</summary>

- github.com/bmatcuk/doublestar `v1.3.1` → `v8.8.8`
- github.com/klauspost/compress `v1.18.6` → `v1.19.0`
- golang.org/x/tools `v0.46.0` → `v0.47.0`
- modernc.org/cc/v4 `v4.28.2` → `v4.28.4`
- modernc.org/ccgo/v4 `v4.34.0` → `v4.34.4`
- modernc.org/gc/v3 `v3.1.2` → `v3.1.3`
- modernc.org/libc `v1.72.3` → `v1.73.4`
- modernc.org/sqlite `v1.51.0` → `v1.53.0`
</details>

<details>
<summary>Added (1 package)</summary>

- howett.net/plist `v1.0.1`
</details>

**[(Full Changelog)](https://github.com/anchore/syft/compare/v1.46.0...v1.47.1)**

v1.46.0
### Added Features

- Add purl types to cataloger info cmd [PR [#4984](https://github.com/anchore/syft/pull/4984) @wagoodman]
- Python cataloger misses uv PEP 723 script lockfiles (`*.py.lock`) [Issue [#4949](https://github.com/anchore/syft/issues/4949)] [PR [#4950](https://github.com/anchore/syft/pull/4950) @ktopcuoglu]
- Add bin classifier for Elastic agen [Issue [#4973](https://github.com/anchore/syft/issues/4973)] [PR [#4968](https://github.com/anchore/syft/pull/4968) @rezmoss]
- SPDX 3 Support [Issue [#4250](https://github.com/anchore/syft/issues/4250)] [PR [#4269](https://github.com/anchore/syft/pull/4269) @kzantow]
- Add Deno support [Issue [#4417](https://github.com/anchore/syft/issues/4417)] [PR [#4523](https://github.com/anchore/syft/pull/4523) @rezmoss]
- Catalog Elastic Beats binary [Issue [#4961](https://github.com/anchore/syft/issues/4961)] [PR [#4969](https://github.com/anchore/syft/pull/4969) @rezmoss]
- Add binary classifiers for Elastic Beats [Issue [#4972](https://github.com/anchore/syft/issues/4972)] [PR [#4969](https://github.com/anchore/syft/pull/4969) @rezmoss]
- Catalog elastic-agent binary [Issue [#4962](https://github.com/anchore/syft/issues/4962)]
- Add support for Bun lockfile (bun.lock) [Issue [#4617](https://github.com/anchore/syft/issues/4617)] [PR [#4625](https://github.com/anchore/syft/pull/4625) @hnnynh]
- Add .bpl file support to the PE / DLL cataloger [Issue [#4664](https://github.com/anchore/syft/issues/4664)] [PR [#4954](https://github.com/anchore/syft/pull/4954) @jfjrh2014]

### Bug Fixes

- respect arch qualifier [PR [#4987](https://github.com/anchore/syft/pull/4987) @willmurphyscode]
- Preserve dependency edges when a compliance stub changes a package ID [PR [#4993](https://github.com/anchore/syft/pull/4993) @wagoodman]
- Support envoy binary various versions [Issue [#4590](https://github.com/anchore/syft/issues/4590)] [PR [#4605](https://github.com/anchore/syft/pull/4605) @rezmoss]
- .net deps.json cataloger shows phantom pkgs for reference assembly library entries [Issue [#4970](https://github.com/anchore/syft/issues/4970)] [PR [#4971](https://github.com/anchore/syft/pull/4971) @rezmoss]
- Syft does not extract package licenses from opkg manager [Issue [#4940](https://github.com/anchore/syft/issues/4940)] [PR [#4963](https://github.com/anchore/syft/pull/4963) @Dashtid]
- squashfs breaks with godisk-fs 1.8.0 [Issue [#4718](https://github.com/anchore/syft/issues/4718)]
- requirements.txt cataloger silently drops PEP 440 local version identifiers, producing incorrect PURL [Issue [#4958](https://github.com/anchore/syft/issues/4958)] [PR [#4959](https://github.com/anchore/syft/pull/4959) @kzantow]

### Dependencies

34 dependency changes (31 updated, 3 added). 5 vulnerabilities remediated.

**🟢 Remediated (5)**

- [GHSA-33vj-92qq-66hc](https://github.com/advisories/GHSA-33vj-92qq-66hc) (High) — github.com/containerd/containerd/v2
- [GHSA-cvxm-645q-p574](https://github.com/advisories/GHSA-cvxm-645q-p574) (Medium) — github.com/containerd/containerd/v2
- [GHSA-jpcc-p29g-p8mq](https://github.com/advisories/GHSA-jpcc-p29g-p8mq) (Medium) — github.com/containerd/containerd/v2
- [GHSA-rgh6-rfwx-v388](https://github.com/advisories/GHSA-rgh6-rfwx-v388) (High) — github.com/containerd/containerd/v2
- [GHSA-xhf5-7wjv-pqxp](https://github.com/advisories/GHSA-xhf5-7wjv-pqxp) (High) — github.com/containerd/containerd/v2

<details>
<summary>Updated (31 packages)</summary>

- github.com/ProtonMail/go-crypto `v1.4.0` → `v1.4.1`
- github.com/anchore/bubbly `v0.2.0` → `v0.2.1`
- github.com/anchore/clio `v0.1.0` → `v0.1.1`
- github.com/anchore/fangs `v0.1.0` → `v0.1.1`
- github.com/anchore/go-collections `v0.1.0` → `v0.1.1`
- github.com/anchore/go-homedir `v0.1.0` → `v0.1.1`
- github.com/anchore/go-logger `v0.1.0` → `v0.1.1`
- github.com/anchore/go-lzo `v0.1.0` → `v0.1.1`
- github.com/anchore/go-macholibre `v0.1.0` → `v0.1.1`
- github.com/anchore/go-make `v0.5.0` → `v0.8.0`
- github.com/anchore/go-struct-converter `v0.1.0` → `v0.2.0-rc2`
- github.com/anchore/go-sync `v0.1.0` → `v0.1.1`
- github.com/anchore/stereoscope `v0.2.1` → `v0.2.2`
- github.com/charmbracelet/colorprofile `v0.4.1` → `v0.4.3`
- github.com/clipperhouse/displaywidth `v0.10.0` → `v0.11.0`
- github.com/clipperhouse/uax29/v2 `v2.6.0` → `v2.7.0`
- github.com/containerd/containerd/v2 `v2.3.1` → `v2.3.2` **(🟢 remediated [GHSA-33vj-92qq-66hc](https://github.com/advisories/GHSA-33vj-92qq-66hc), [GHSA-cvxm-645q-p574](https://github.com/advisories/GHSA-cvxm-645q-p574), [GHSA-jpcc-p29g-p8mq](https://github.com/advisories/GHSA-jpcc-p29g-p8mq), [GHSA-rgh6-rfwx-v388](https://github.com/advisories/GHSA-rgh6-rfwx-v388), [GHSA-xhf5-7wjv-pqxp](https://github.com/advisories/GHSA-xhf5-7wjv-pqxp))**
- github.com/docker/cli `v29.4.3+incompatible` → `v29.5.3+incompatible`
- github.com/google/go-containerregistry `v0.21.6` → `v0.21.7`
- github.com/jedib0t/go-pretty/v6 `v6.7.10` → `v6.8.1`
- github.com/mattn/go-runewidth `v0.0.19` → `v0.0.21`
- github.com/spdx/tools-golang `v0.5.7` → `v0.6.0-rc4`
- github.com/sylabs/sif/v2 `v2.24.0` → `v2.24.1`
- golang.org/x/crypto `v0.52.0` → `v0.53.0`
- golang.org/x/mod `v0.36.0` → `v0.37.0`
- golang.org/x/net `v0.55.0` → `v0.56.0`
- golang.org/x/sync `v0.20.0` → `v0.21.0`
- golang.org/x/sys `v0.45.0` → `v0.46.0`
- golang.org/x/term `v0.43.0` → `v0.44.0`
- golang.org/x/text `v0.37.0` → `v0.38.0`
- golang.org/x/tools `v0.45.0` → `v0.46.0`
</details>

<details>
<summary>Added (3 packages)</summary>

- github.com/piprate/json-gold `v0.7.0`
- github.com/pquerna/cachecontrol `v0.0.0-1555304`
- github.com/tailscale/hujson `v0.0.0-ecc657c`
</details>

**[(Full Changelog)](https://github.com/anchore/syft/compare/v1.45.1...v1.46.0)**

GitHub Action workflow link
Updatecli logo

Created automatically by Updatecli

Options:

Most of Updatecli configuration is done via its manifest(s).

  • If you close this pull request, Updatecli will automatically reopen it, the next time it runs.
  • If you close this pull request and delete the base branch, Updatecli will automatically recreate it, erasing all previous commits made.

Feel free to report any issues at github.com/updatecli/updatecli.
If you find this tool useful, do not hesitate to star our GitHub repository as a sign of appreciation, and/or to tell us directly on our chat!

Made with ❤️️ by updatecli
@github-actions github-actions Bot added the dependencies Pull requests that update a dependency file label Jun 26, 2026
Made with ❤️️ by updatecli
@github-actions github-actions Bot changed the title [updatecli] Bump anchore/syft version to v1.46.0 [updatecli] Bump anchore/syft version to v1.48.0 Jul 16, 2026
Made with ❤️️ by updatecli
@github-actions github-actions Bot changed the title [updatecli] Bump anchore/syft version to v1.48.0 [updatecli] Bump anchore/syft version to v1.49.0 Jul 21, 2026
Made with ❤️️ by updatecli
@github-actions github-actions Bot changed the title [updatecli] Bump anchore/syft version to v1.49.0 [updatecli] Bump anchore/syft version to v1.50.0 Jul 28, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants