Skip to content
New issue

Have a question about this project? # for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “#”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? # to your account

chore(deps): update Syft to v1.4.1 #465

Merged
merged 2 commits into from
May 20, 2024
Merged

chore(deps): update Syft to v1.4.1 #465

merged 2 commits into from
May 20, 2024

Conversation

anchore-actions-token-generator[bot]
Copy link
Contributor

Update Syft to v1.4.1

@anchore-actions-token-generator anchore-actions-token-generator bot added the dependencies Pull requests that update a dependency file label May 10, 2024
@willmurphyscode willmurphyscode self-assigned this May 14, 2024
ExternalRef: PACKAGE-MANAGER purl pkg:oci/localhost:5000/match-coverage/debian@sha256:redacted?arch=amd64&tag=latest

##### Package: apt

PackageName: apt

PackageVersion: 1.8.2
PackageSupplier: Person: APT Development Team <deity@lists.debian.org>
PackageOriginator: Person: APT Development Team <deity@lists.debian.org>
PackageSupplier: NOASSERTION
Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This is a bit surprising. Why did we stop asserting the package supplier?

Copy link
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

I suspect it's due to this PR: anchore/syft#2822, but it's not entirely clear offhand why

Signed-off-by: github-actions[bot] <41898282+github-actions[bot]@users.noreply.github.com>
Signed-off-by: Keith Zantow <kzantow@gmail.com>
@kzantow kzantow merged commit e8d2a69 into main May 20, 2024
6 checks passed
@kzantow kzantow deleted the auto/latest-syft branch May 20, 2024 14:22
# for free to join this conversation on GitHub. Already have an account? # to comment
Labels
dependencies Pull requests that update a dependency file
Projects
Archived in project
Development

Successfully merging this pull request may close these issues.

2 participants