Skip to content

build(deps): bump the gomod-minor group across 1 directory with 2 updates - #8

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/gomod-minor-6c19b4571e
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/gomod-minor-6c19b4571e

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Sep 12, 2026 •

Copy link
Copy Markdown

Bumps the gomod-minor group with 2 updates in the / directory: github.com/anchore/grype and github.com/anchore/syft.

Updates github.com/anchore/grype from 0.117.0 to 0.118.0

Release notes

Sourced from github.com/anchore/grype's releases.

v0.118.0

Added Features

Bug Fixes

  • prevent panic on portage versions without digits [PR #3655 @​ashvinctrl]
  • grype vex does not match oci purl with repository_url [Issue #3657] [PR #3659 @​spiffcs]
  • Old JVM version comparisons sometimes incorrect [Issue #2701] [PR #3583 @​Eljees]
  • CVSSv4 calculation can produce incorrect vulnerability severity [Issue #3656]
  • Grype 0.90.0 DB update failed [Issue #3629]

Dependencies

72 dependency changes (70 updated, 1 added, 1 removed). 3 vulnerabilities remediated.

🟢 Remediated (3)

  • cel.dev/expr v0.25.1 → v0.25.2
  • cloud.google.com/go/auth v0.18.2 → v0.22.0
  • cloud.google.com/go/iam v1.5.3 → v1.11.0
  • cloud.google.com/go/logging v1.13.1 → v1.18.0
  • cloud.google.com/go/longrunning v0.8.0 → v1.2.0
  • cloud.google.com/go/monitoring v1.24.3 → v1.29.0
  • cloud.google.com/go/storage v1.61.3 → v1.64.0
  • cloud.google.com/go/trace v1.11.7 → v1.16.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.32.0 → v1.33.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.55.0 → v0.57.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock v0.55.0 → v0.57.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0 → v0.57.0
  • github.com/anchore/stereoscope v0.3.0 → v0.3.1
  • github.com/anchore/syft v1.51.0 → v1.51.1
  • github.com/aws/aws-sdk-go-v2 v1.41.5 → v1.43.4
  • github.com/aws/aws-sdk-go-v2/aws/protocol/eventstream v1.7.8 → v1.7.16
  • github.com/aws/aws-sdk-go-v2/config v1.32.12 → v1.32.35
  • github.com/aws/aws-sdk-go-v2/credentials v1.19.12 → v1.19.34
  • github.com/aws/aws-sdk-go-v2/feature/ec2/imds v1.18.20 → v1.18.35
  • github.com/aws/aws-sdk-go-v2/internal/configsources v1.4.21 → v1.4.35
  • github.com/aws/aws-sdk-go-v2/internal/endpoints/v2 v2.7.21 → v2.7.35
  • github.com/aws/aws-sdk-go-v2/internal/v4a v1.4.22 → v1.4.36
  • github.com/aws/aws-sdk-go-v2/service/internal/accept-encoding v1.13.7 → v1.13.15
  • github.com/aws/aws-sdk-go-v2/service/internal/checksum v1.9.13 → v1.9.28

... (truncated)

Commits
  • 756eb9a chore(deps): update anchore dependencies (#3648)
  • 9963eb7 fix(bug): package_url mismatchs vex document on namespace/name (#3659)
  • 8b1354c fix: normalize "u" update shorthand in pre-JEP 223 JVM versions (#3583)
  • 0f57388 feat(apk/matcher): apk matcher does alias aware aggregation (#3634)
  • 0ee65de fix(version): prevent panic on portage versions without digits (#3655)
  • 2739bfa chore: update the stdin subprocess tests (#3661)
  • ab6707d chore(deps): bump golang.org/x/text from 0.40.0 to 0.41.0 (#3668)
  • ffbca56 chore(deps): bump github.com/google/go-containerregistry (#3651)
  • fd366aa chore(deps): bump zizmorcore/zizmor-action from 0.6.0 to 0.6.2 (#3650)
  • See full diff in compare view

Updates github.com/anchore/syft from 1.51.0 to 1.51.1

Release notes

Sourced from github.com/anchore/syft's releases.

v1.51.1

Bug Fixes

Additional Changes

  • gzip binary classifier reports false-positive GNU gzip from BusyBox multicall binary via applet symlink [Issue #5171] [PR #5202 @​spiffcs]
  • pnpm v5 lockfile: underscore peer-dep suffixes are not stripped from package versions [Issue #5174] [PR #5175 @​codeAnqiang-ma]
  • pnpm cataloger reads only the first YAML document: SBOM contains pnpm's own binaries and no project dependencies [Issue #5168] [PR #5188 @​hamodywe]

Dependencies

72 dependency changes (70 updated, 1 added, 1 removed). 3 vulnerabilities remediated.

🟢 Remediated (3)

  • cel.dev/expr v0.25.1 → v0.25.2
  • cloud.google.com/go/auth v0.18.2 → v0.22.0
  • cloud.google.com/go/iam v1.5.3 → v1.11.0
  • cloud.google.com/go/logging v1.13.1 → v1.18.0
  • cloud.google.com/go/longrunning v0.8.0 → v1.2.0
  • cloud.google.com/go/monitoring v1.24.3 → v1.29.0
  • cloud.google.com/go/storage v1.61.3 → v1.64.0
  • cloud.google.com/go/trace v1.11.7 → v1.16.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.32.0 → v1.33.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.55.0 → v0.57.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock v0.55.0 → v0.57.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0 → v0.57.0
  • github.com/anchore/stereoscope v0.3.0 → v0.3.1

... (truncated)

Commits
  • 91a0032 chore(deps): update anchore dependencies (#5085)
  • f91bf45 fix: correct Apache Derby group ID in purl generation (#5090)
  • c5fc699 chore(deps): update CPE dictionary index (#5221)
  • d3734dd fix(binary): detect grafana security-patch release versions (#5213)
  • bf82010 fix(lua): skip rockspec with no package name (#4825)
  • 7ca1f22 fix(dotnet): correct inverted dependency-of relationship direction in package...
  • 93cf893 fix(rpm): keep the epoch when parsing RPM manifest packages (#5201)
  • 34ef7dc chore(deps): bump golang.org/x/mod from 0.39.0 to 0.40.0 (#5208)
  • 29edf90 chore(deps): bump github.com/hashicorp/go-getter from 1.8.6 to 1.8.8 (#5207)
  • 766907e chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0 (#5206)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Sep 12, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/gomod-minor-6c19b4571e branch 3 times, most recently from a5da8fd to 394e76d Compare September 16, 2026 15:15
…ates

Bumps the gomod-minor group with 2 updates in the / directory: [github.com/anchore/grype](https://github.com/anchore/grype) and [github.com/anchore/syft](https://github.com/anchore/syft).


Updates `github.com/anchore/grype` from 0.117.0 to 0.118.0
- [Release notes](https://github.com/anchore/grype/releases)
- [Changelog](https://github.com/anchore/grype/blob/main/RELEASE.md)
- [Commits](anchore/grype@v0.117.0...v0.118.0)

Updates `github.com/anchore/syft` from 1.51.0 to 1.51.1
- [Release notes](https://github.com/anchore/syft/releases)
- [Changelog](https://github.com/anchore/syft/blob/main/RELEASE.md)
- [Commits](anchore/syft@v1.51.0...v1.51.1)

---
updated-dependencies:
- dependency-name: github.com/anchore/grype
  dependency-version: 0.118.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: gomod-minor
- dependency-name: github.com/anchore/syft
  dependency-version: 1.51.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: gomod-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/gomod-minor-6c19b4571e branch from 394e76d to 59e306a Compare September 19, 2026 09:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants