Repository navigation
chore(deps): update module osv-scanner to v2.6.0 - #40
Merged
Merged
Conversation
|
Important Review skippedBot user detected. To trigger a single review, invoke the ⚙️ Run configurationConfiguration used: defaults Review profile: CHILL Plan: Advanced Run ID: You can disable this status message by setting the Use the checkbox below for a quick retry:
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
1 task
BergCyrill
approved these changes
Sep 17, 2026
BergCyrill
left a comment
Collaborator
There was a problem hiding this comment.
lgtm, corresponding workflow action was merged just now to bump to same version
renovate
Bot
force-pushed
the
renovate/osv-scanner-2.x
branch
from
September 17, 2026 14:06
6ab3da2 to
7b2f2bb
Compare
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
v2.3.8→v2.6.0Release Notes
google/osv-scanner (osv-scanner)
v2.6.0Compare Source
Features:
linux/arm64) image forosv-scanner-action.osv-scalibr:package-lock.json,yarn.lock,pnpm-lock.yaml,bun.lock).pkg:gitPURL type to Git commit-pinned dependencies across JS and Cargo lockfiles to avoid false positives against registry packages (#2863).osv-scalibr:--experimental-pluginsflag. See "Supported Inventory Types" for the extractor name.Fixes:
resultsproperty in JSON output is an empty array[]instead ofnullwhen scanning with--allow-no-lockfilesand no lockfiles are found.log.Fatalf) when anrlibarchive has no object file during Rust source analysis.DoContainerScanwhenScannerActions.Imageis empty instead of panicking.osv-scalibr:/go(e.g.pkg:golang/github.com/json-iterator/go) (#3017).os.Rootto prevent path traversal attacks (google/osv-scalibr#2363)..deps.jsonfiles that don't have an object as their root indotnet/depsjsonextractor (google/osv-scalibr#2423).Misc:
osv-scalibrtov0.5.3-0.20260911142458-3090dbb7aaa2(#3079).golangci-lintto v2.13 (#3046).google.golang.org/grpcto v1.83.2 (#3062).v2.5.1Compare Source
Fixes:
OSV_SCANNER_LOCAL_DB_CACHE_DIRECTORYenvironment variable (fixes #2983).--offline-vulnerabilities) not working when network capability isNetworkOnline.v2.5.0Compare Source
Features & Refactors:
Full OSV-Scalibr pipeline: Migrated scanning, filtering, and matching in
osv-scannerto useosv-scalibrend-to-end, so most plugins that's supported in osv-scalibr should be supported via the--experimental-pluginsflag (#2935).New extractors and ecosystem support via
osv-scalibr:javascript/vsixextractor to support scanning VS Code extension (.vsix) packages.PURL Type Resolution: Updated
osvscannerjsonextractor to map ecosystem names to valid PURL types (golang, gem, cargo, npm, etc.).Fixes:
osv-scalibr, specifically regular expressions used to extract package names and per-requirement options (Fixes #2940, #2931)osv-scalibr, separating package namespace (scope) from package namev2.4.0Compare Source
Features:
cyclonedx-goto v0.11.0)..csprojand Central Package Management (nugetcpm) source scanning plugins by default.Alpine:v3.17,Alpine:edge) from PURLdistroqualifiers to scan packages under their respective Alpine ecosystems.swift/packageresolvedplugin by default to support SwiftURL vulnerability scans..pre-commit-hooks.yamlto avoid local compilation.ScanGoModVersion(disabled by default) to avoid parsing toolchain version directives directly fromgo.mod, preventing misleading warnings.os/chiselextractor plugin.Fixes:
--offline-vulnerabilitiesflag.GitHub Actionsecosystem) by avoiding parsing errors when checking version ranges.0when--helpor-his explicitly requested.Misc:
osv-scalibrtov0.4.6-0.20260612031204-164402d9140e.:v2) to allow users to pin to a major version (#2857).Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
🔕 Ignore: Close this PR and you won't be reminded about this update again.
This PR was generated by Mend Renovate. View the repository job log.