This repository has been archived by the owner on Jan 27, 2023. It is now read-only.
-
Notifications
You must be signed in to change notification settings - Fork 271
Bump Syft/Grype dependencies #1392
Open
brennoo
wants to merge
7
commits into
anchore:master
Choose a base branch
from
brennoo:bump_grype_syft_dependencies
base: master
Could not load branches
Branch not found: {{ refName }}
Loading
Could not load tags
Nothing to show
Loading
Are you sure you want to change the base?
Some commits from the old base branch may be removed from the timeline,
and old review comments may become outdated.
Open
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Signed-off-by: Brenno Oliveira <[email protected]>
brennoo
force-pushed
the
bump_grype_syft_dependencies
branch
from
September 28, 2022 15:43
eb7884d
to
c36d94b
Compare
javad-hajiani
approved these changes
Sep 28, 2022
Signed-off-by: Brenno Oliveira <[email protected]>
Signed-off-by: Brenno Oliveira <[email protected]>
Signed-off-by: Brenno Oliveira <[email protected]>
Signed-off-by: Brenno Oliveira <[email protected]>
brennoo
force-pushed
the
bump_grype_syft_dependencies
branch
from
September 30, 2022 14:35
b833569
to
6c51609
Compare
Signed-off-by: Brenno Oliveira <[email protected]>
Signed-off-by: Brenno Oliveira <[email protected]>
tuxerrante
reviewed
Jan 19, 2023
ENV SYFT_VERSION=v0.33.0 | ||
ENV GRYPE_VERSION=v0.27.3 | ||
ENV SYFT_VERSION=v0.57.0 | ||
ENV GRYPE_VERSION=v0.50.2 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
This could be already bumped to 0.55
Suggested change
ENV GRYPE_VERSION=v0.50.2 | |
ENV GRYPE_VERSION=v0.55.0 |
Sign up for free
to subscribe to this conversation on GitHub.
Already have an account?
Sign in.
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
What this PR does / why we need it: Bump Syft, Grype dependencies. I understand that there is no active development on anchore-engine but these dependencies need to get updated to address issues that are affecting anchore-engine.
Which issue this PR fixes : some false positives/negatives, examples: anchore/grype#504 anchore/grype#917 as well other recent improvements they received.
Special notes: