Skip to content

chore(deps): update module osv-scanner to v2.6.0 - #40

Merged
BergCyrill merged 1 commit into
mainfrom
renovate/osv-scanner-2.x
Sep 17, 2026
Merged

BergCyrill merged 1 commit into
mainfrom
renovate/osv-scanner-2.x

Conversation

@renovate

@renovate renovate Bot commented Sep 16, 2026 •

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
osv-scanner v2.3.8 → v2.6.0 age confidence

Release Notes

google/osv-scanner (osv-scanner)

v2.6.0

Compare Source

Features:
  • Feature #​2888 Publish multi-arch (linux/arm64) image for osv-scanner-action.
  • Feature #​3066 Configure retry policy with exponential backoff for transient gRPC errors in scalibr plugins.
  • Dependency scanning & lockfile improvements via osv-scalibr:
    • Extract Git repository URLs and support local OSV tag matching for Git-based dependencies in JavaScript lockfiles (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock).
    • Assign pkg:git PURL type to Git commit-pinned dependencies across JS and Cargo lockfiles to avoid false positives against registry packages (#​2863).
    • Retain packages without a version or PURL in SPDX output (google/osv-scalibr#2375) and merge related packages based on lineage relationships.
  • New extractors and plugin support via osv-scalibr:
    • Many additional filetypes are supported. These are not enabled by default yet, so if you need a particular new filetype, use --experimental-plugins flag. See "Supported Inventory Types" for the extractor name.
Fixes:
  • Bug #​3075 Ensure results property in JSON output is an empty array [] instead of null when scanning with --allow-no-lockfiles and no lockfiles are found.
  • Bug #​3071 Preserve valid UTF-8 sequences when truncating multibyte text in vertical output.
  • Bug #​2919 Add filter to show packages with license violations but no vulnerabilities in the HTML report.
  • Bug #​3049 Keep filter dropdown checklist open when clicking options in the HTML report.
  • Bug #​3023 Guard against panic on empty or whitespace-only license expressions in SPDX license evaluation.
  • Bug #​3032 Bound recursion depth when parsing SPDX license expressions to prevent stack overflow on deeply nested expressions.
  • Bug #​3061 Remove purl caching in scan filtering to avoid dropping SBOM packages without purls.
  • Bug #​3063 Log plugin and enricher errors during container scans instead of failing silently.
  • Bug #​2977 Return an error instead of aborting the process (log.Fatalf) when an rlib archive has no object file during Rust source analysis.
  • Bug #​3083 Return a descriptive error from DoContainerScan when ScannerActions.Image is empty instead of panicking.
  • Fixes via osv-scalibr:
    • Fix false-positive Go standard library matches for packages with module paths ending in /go (e.g. pkg:golang/github.com/json-iterator/go) (#​3017).
    • Secure guided remediation file operations with os.Root to prevent path traversal attacks (google/osv-scalibr#2363).
    • Prevent OOM and disk exhaustion issues with tar bombs during archive extraction.
    • Strip platform suffix from RubyGems versions in CycloneDX (google/osv-scalibr#2313).
    • Ignore .deps.json files that don't have an object as their root in dotnet/depsjson extractor (google/osv-scalibr#2423).
Misc:
  • Update osv-scalibr to v0.5.3-0.20260911142458-3090dbb7aaa2 (#​3079).
  • Update Go to v1.27 and golangci-lint to v2.13 (#​3046).
    • This now supports call analysis on go v1.27 projects.
  • Update google.golang.org/grpc to v1.83.2 (#​3062).

v2.5.1

Compare Source

Fixes:
  • Preserve package namespaces when querying osv.dev API (fixes #​2978).
  • Re-add support for the OSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY environment variable (fixes #​2983).
  • Fix local vulnerability matching (--offline-vulnerabilities) not working when network capability is NetworkOnline.

v2.5.0

Compare Source

Features & Refactors:
  • Full OSV-Scalibr pipeline: Migrated scanning, filtering, and matching in osv-scanner to use osv-scalibr end-to-end, so most plugins that's supported in osv-scalibr should be supported via the --experimental-plugins flag (#​2935).

  • New extractors and ecosystem support via osv-scalibr:

    • Add javascript/vsix extractor to support scanning VS Code extension (.vsix) packages.
    • Extend ecosystem mapping for:
      • SUSE
      • Azure Linux / Mariner
      • Alpaquita
      • Mageia
      • openSUSE Leap
      • Debian and Ubuntu PURL
  • PURL Type Resolution: Updated osvscannerjson extractor to map ecosystem names to valid PURL types (golang, gem, cargo, npm, etc.).

Fixes:
  • Bug #​2915 Fix issue where osv-scanner reported already-fixed advisories as unfixed for RHEL-family RPM packages (Red Hat, AlmaLinux, Rocky Linux) with epochs by sending epoch-qualified versions.
  • Fix Python requirements.txt extractor in osv-scalibr, specifically regular expressions used to extract package names and per-requirement options (Fixes #​2940, #​2931)
  • Fix NPM and Composer PURL generation in osv-scalibr, separating package namespace (scope) from package name

v2.4.0

Compare Source

Features:
  • Feature #​2815 Add support for the CycloneDX 1.7 specification (bumps cyclonedx-go to v0.11.0).
  • Feature #​2799 Enable .csproj and Central Package Management (nugetcpm) source scanning plugins by default.
  • Feature #​2871 Extract and parse Alpine OS distro version (e.g. Alpine:v3.17, Alpine:edge) from PURL distro qualifiers to scan packages under their respective Alpine ecosystems.
  • Feature #​2801 Enable the swift/packageresolved plugin by default to support SwiftURL vulnerability scans.
  • Feature #​2666 Add a Docker-based variant of the pre-commit hook in .pre-commit-hooks.yaml to avoid local compilation.
  • Feature #​2637 Add a new configuration setting ScanGoModVersion (disabled by default) to avoid parsing toolchain version directives directly from go.mod, preventing misleading warnings.
  • Feature #​2772 Scan container images built with Canonical Chisel by enabling the os/chisel extractor plugin.
Fixes:
  • Bug #​2807 Sanitize package name, source, and version fields in the vertical output format to prevent GitHub Actions workflow command injection vulnerabilities from crafted lock files.
  • Bug #​2876 Improve HTML scan report usability by supporting standard click modifiers (Ctrl/Cmd/middle click) to open vulnerabilities in new tabs, and preserving scroll position when switching tabs.
  • Bug #​2783 Keep transitive dependency scanning enabled when specifying the --offline-vulnerabilities flag.
  • Bug #​2808 Deduplicate equivalent OSV matcher requests before executing bulk queries to reduce API overhead.
  • Bug #​2837 Prevent panics during offline matcher scans (e.g. on unsupported GitHub Actions ecosystem) by avoiding parsing errors when checking version ranges.
  • Bug #​2836 Ensure the scanner returns an exit code of 0 when --help or -h is explicitly requested.
Misc:
  • Update Go version to 1.26.4.
  • Update osv-scalibr to v0.4.6-0.20260612031204-164402d9140e.
  • Tag built Docker and GitHub Action images with the major version (e.g. :v2) to allow users to pin to a major version (#​2857).

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate
renovate Bot requested a review from a team September 16, 2026 00:55
@coderabbitai

coderabbitai Bot commented Sep 16, 2026 •

Copy link
Copy Markdown

Important

Review skipped

Bot user detected.

To trigger a single review, invoke the @coderabbitai review command.

⚙️ Run configuration

Configuration used: defaults

Review profile: CHILL

Plan: Advanced

Run ID: 3267ed98-421a-4933-901d-a372c6b4a89f

You can disable this status message by setting the reviews.review_status to false in the CodeRabbit configuration file.

Use the checkbox below for a quick retry:

  • 🔍 Trigger review

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@BergCyrill BergCyrill left a comment

Copy link
Copy Markdown
Collaborator

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

lgtm, corresponding workflow action was merged just now to bump to same version

@renovate
renovate Bot force-pushed the renovate/osv-scanner-2.x branch from 6ab3da2 to 7b2f2bb Compare September 17, 2026 14:06
@BergCyrill
BergCyrill merged commit d4d932d into main Sep 17, 2026
12 checks passed
@renovate
renovate Bot deleted the renovate/osv-scanner-2.x branch September 17, 2026 14:16
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant