Skip to content
This repository has been archived by the owner on Jan 27, 2023. It is now read-only.

Bump Syft/Grype dependencies #1392

Open
wants to merge 7 commits into
base: master
Choose a base branch
from

Conversation

brennoo
Copy link

@brennoo brennoo commented Sep 28, 2022

What this PR does / why we need it: Bump Syft, Grype dependencies. I understand that there is no active development on anchore-engine but these dependencies need to get updated to address issues that are affecting anchore-engine.

Which issue this PR fixes : some false positives/negatives, examples: anchore/grype#504 anchore/grype#917 as well other recent improvements they received.

Special notes:

Signed-off-by: Brenno Oliveira <brenno@bsd.com.br>
@kzantow kzantow closed this Sep 28, 2022
@kzantow kzantow reopened this Sep 28, 2022
Signed-off-by: Brenno Oliveira <brenno@bsd.com.br>
Signed-off-by: Brenno Oliveira <brenno@bsd.com.br>
Signed-off-by: Brenno Oliveira <brenno@bsd.com.br>
@kzantow kzantow closed this Sep 30, 2022
@kzantow kzantow reopened this Sep 30, 2022
Signed-off-by: Brenno Oliveira <brenno@bsd.com.br>
Signed-off-by: Brenno Oliveira <brenno@bsd.com.br>
@kzantow kzantow closed this Sep 30, 2022
@kzantow kzantow reopened this Sep 30, 2022
Signed-off-by: Brenno Oliveira <brenno@bsd.com.br>
@kzantow kzantow closed this Sep 30, 2022
@kzantow kzantow reopened this Sep 30, 2022
@kzantow kzantow added the dependencies Pull requests that update a dependency file label Nov 23, 2022
ENV SYFT_VERSION=v0.33.0
ENV GRYPE_VERSION=v0.27.3
ENV SYFT_VERSION=v0.57.0
ENV GRYPE_VERSION=v0.50.2

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This could be already bumped to 0.55

Suggested change
ENV GRYPE_VERSION=v0.50.2
ENV GRYPE_VERSION=v0.55.0

Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
dependencies Pull requests that update a dependency file
Projects
None yet
Development

Successfully merging this pull request may close these issues.

None yet

4 participants