Releases: anchore/vunnel
Releases · anchore/vunnel
v0.21.0
v0.20.0
v0.19.0
v0.19.0
Added Features
Bug Fixes
- remove sha256 verification for oval parser [#505 @spiffcs]
- Bump orjson from 3.9.13 to 3.9.14 [#483 @dependabot]
Additional Changes
- Use https for submodule [#501 @wagoodman]
- commit lint fix of poetry.lock [#499 @willmurphyscode]
- drop python-future [#492 @westonsteimel]
v0.18.5
v0.18.5
Bug Fixes
- improve the ubuntu provider to emit vuln rows for out of support entries [#477 @westonsteimel]
v0.18.4
v0.18.4
Bug Fixes
- Check download digest of rhel oval files [#462 @wagoodman]
Additional Changes
- change dependabot to auto-approve only [#458 @willmurphyscode]
v0.18.3
v0.18.3
Additional Changes
- disable auto merging of dependabot PRs [#456 @westonsteimel]
- Bump urllib3 from 2.0.5 to 2.0.7 (#454)
- Bump jinja2 from 3.1.2 to 3.1.3 (#455)
v0.18.2
v0.18.2
Bug Fixes
- update vulnerability urls [#451 @westonsteimel]
Additional changes
- hard-code severity for debian CVE-2023-44487 to inherit NVD severity [#448 @willmurphyscode]
v0.18.1
v0.18.1
Bug Fixes
- Redhat
package_name
with/
do not always reference modules [#443 #444 @westonsteimel]
v0.18.0
v0.18.0
Added Features
- extract description from Oracle Security Advisories [#437 @westonsteimel]
Bug Fixes
- Alleviate RHEL provider CVE-list race condition [#438 @wagoodman]
Additional Changes
- Load all schema url refs for offline validation [#436 @wagoodman]
- Check PR author login, instead of actor [#434 @willmurphyscode]
- Update dependabot-auto-merge to cancel itself on human push [#432 @willmurphyscode]
v0.17.12
v0.17.12
Bug Fixes
- update vulnerability reference links [#426 @westonsteimel]
- update vulnerability reference links [#425 @westonsteimel]
- improve parsing severity from priority [#419 @westonsteimel]