Skip to content

Releases: owasp-dep-scan/dep-scan

Release v5.3.2

07 Apr 21:38
523e60c
Compare
Choose a tag to compare

What's Changed

  • Added generic cdxgen_args that can be passed as an environment variable or argument to depscan itself. by @deleterepo in #292
  • Update cdxgen to bring go purl compatibility fixes by @prabhu in #297

Full Changelog: v5.3.1...v5.3.2

Release v5.3.1

04 Apr 21:27
a27b6ec
Compare
Choose a tag to compare

What's Changed

Full Changelog: v5.3.0...v5.3.1

Release v5.3.0

02 Apr 10:33
82d0fd9
Compare
Choose a tag to compare

From this release, deprecated packages would always get flagged regardless of the score with risk audit. For PyPI, we look for couple of strings in the description since not every vendor follows the procedure to yank the packages correctly.

Full Changelog: v5.2.15...v5.3.0

Release v5.2.15

01 Apr 20:11
c6893f5
Compare
Choose a tag to compare

What's Changed

Full Changelog: v5.2.14...v5.2.15

Release v5.2.14

29 Mar 11:26
db71fc1
Compare
Choose a tag to compare

Update cdxgen to bring dotnet packages.lock.json fix

Full Changelog: v5.2.13...v5.2.14

Release v5.2.13

27 Mar 21:06
dd4d03e
Compare
Choose a tag to compare

Fix cdxgen version in container image to 10.2.5

What's Changed

Full Changelog: v5.2.12...v5.2.13

Release v5.2.12

12 Mar 17:50
e969ed5
Compare
Choose a tag to compare

What's Changed

Full Changelog: v5.2.11...v5.2.12

Release v5.2.11

27 Feb 20:17
b0ffcd3
Compare
Choose a tag to compare

What's Changed

Full Changelog: v5.2.10...v5.2.11

Release v5.2.10

25 Feb 14:29
7990d18
Compare
Choose a tag to compare

What's Changed

  • Handle zero scores from npm with vdb 5.6.3 by @prabhu in #258
  • Fixes #259 by ignoring pysec feeds with matching github advisory id

Full Changelog: v5.2.9...v5.2.10

Release v5.2.9

14 Feb 18:59
5a098fc
Compare
Choose a tag to compare

What's Changed

  • Support for gem with platform name in the version number by @prabhu in #252

Full Changelog: v5.2.8...v5.2.9