Граф коммитов

679 Коммитов

Автор SHA1 Сообщение Дата
renovate[bot] 5aa622761b
chore(deps): update dependency faker.net to v2.0.163 (#981)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2024-01-22 21:11:38 +00:00
Jamie Magee 94d8c55a61
Bump Syft from `0.74.0` to `0.100.0` (#960)
* Bump Syft from `0.74.0` to `0.100.0`

* Test fixes
2024-01-19 15:28:10 -08:00
dependabot[bot] 5b44b1218e
build(deps): bump actions/upload-artifact from 4.0.0 to 4.2.0 (#979)
Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 4.0.0 to 4.2.0.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](c7d193f32e...694cdabd8b)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2024-01-19 09:41:30 -08:00
renovate[bot] 6c9d841de0
chore(deps): update github/codeql-action action to v3.23.1 (#955)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Coby Allred <cobyallred@gmail.com>
2024-01-19 09:40:39 -08:00
Fernando Rojo 3aa0f06025
Move Set scope to avoid cross-root conflicts (#978) 2024-01-19 09:25:00 -08:00
Coby Allred 9ea2b3c253
Make Python detection more resilient to unexpected failure cases (#962)
* Make Python detection more resilient to unexpected cases

* Add Pip tests

* PR comments

---------

Co-authored-by: Coby Allred <coallred@microsoft.com>
2024-01-19 09:24:28 -08:00
Fernando Rojo b65fa8a7d1
Add hashtable to resolve circular rust dependencies (#975) 2024-01-17 13:38:16 -08:00
renovate[bot] d38bde52d9
chore(deps): update dependency polly to v8.2.1 (#951)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2024-01-12 11:46:22 -08:00
Sebastian Gomez 2b824d2876
Add Supplier/License info to RustCli Cargo Components. (#940)
* Add Supplier/License info to RustCli Cargo Components.

* Address feedback.

* Fix input for test

* Add extra check for empty array of authors.

---------

Co-authored-by: Sebastian Gomez <segomez@microsoft.com>
2024-01-10 13:53:11 -08:00
renovate[bot] 0923d09ec0
chore(deps): update dependency stylecop.analyzers to v1.2.0-beta.556 (#945)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Coby Allred <cobyallred@gmail.com>
2023-12-29 09:38:41 -08:00
renovate[bot] 3beb1afd13
chore(deps): update mcr.microsoft.com/dotnet/runtime-deps:6.0-cbl-mariner2.0 docker digest to 7b8cfde (#943)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-12-29 08:25:44 -08:00
Winston Liu 4b5500c5f4
Fix link to downloads (#947) 2023-12-28 12:37:19 -08:00
Sebastian Gomez 809ef0b94c
Adds supplier/license info to pip components. (#938)
* Adds supplier/license info to pip components.

* Rename GetReleasesAsync to GetProjectAsync

* Address feedback

---------

Co-authored-by: Sebastian Gomez <segomez@microsoft.com>
2023-12-28 12:35:06 -08:00
renovate[bot] 710273b6c8
chore(deps): update dependency microsoft.visualstudio.threading.analyzers to v17.8.14 (#905)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Coby Allred <cobyallred@gmail.com>
2023-12-28 10:05:58 -08:00
dependabot[bot] 2418e5f747
build(deps): bump actions/upload-artifact from 3.1.3 to 4.0.0 (#935)
* build(deps): bump actions/upload-artifact from 3.1.3 to 4.0.0

Bumps [actions/upload-artifact](https://github.com/actions/upload-artifact) from 3.1.3 to 4.0.0.
- [Release notes](https://github.com/actions/upload-artifact/releases)
- [Commits](a8a3f3ad30...c7d193f32e)

---
updated-dependencies:
- dependency-name: actions/upload-artifact
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update snapshot-publish.yml

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Coby Allred <cobyallred@gmail.com>
2023-12-28 09:51:35 -08:00
renovate[bot] 0db3692950
chore(deps): update nuget monorepo to v6.8.0 (#911)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Coby Allred <cobyallred@gmail.com>
2023-12-28 09:35:50 -08:00
dependabot[bot] 62bbeb5570
build(deps): bump actions/setup-dotnet from 3.2.0 to 4.0.0 (#926)
* build(deps): bump actions/setup-dotnet from 3.2.0 to 4.0.0

Bumps [actions/setup-dotnet](https://github.com/actions/setup-dotnet) from 3.2.0 to 4.0.0.
- [Release notes](https://github.com/actions/setup-dotnet/releases)
- [Commits](3447fd6a9f...4d6c8fcf3c)

---
updated-dependencies:
- dependency-name: actions/setup-dotnet
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>

* Update build.yml

* Update gen-docs.yml

* Update release.yml

* Update snapshot-publish.yml

* Update snapshot-verify.yml

---------

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Coby Allred <cobyallred@gmail.com>
2023-12-28 09:33:40 -08:00
renovate[bot] 33197c1254
chore(deps): update dependency morelinq to v4.1.0 (#922)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-12-28 09:08:53 -08:00
renovate[bot] 2977229a7a
chore(deps): update dependency tomlyn.signed to v0.17.0 (#923)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
Co-authored-by: Coby Allred <cobyallred@gmail.com>
2023-12-28 09:02:58 -08:00
dependabot[bot] f210c3e707
build(deps): bump github/codeql-action from 3.22.11 to 3.22.12 (#941)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 3.22.11 to 3.22.12.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](b374143c11...012739e508)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-12-28 08:51:51 -08:00
Greg Villicana cf78e59a30
Removed experiments on released detectors: NPM Lockfile V3 and Nuget (#939)
* Removed experiments on released detectors: NPM Lockfile V3 and Nuget
2023-12-19 15:55:49 -08:00
dependabot[bot] 6da19768e5
build(deps): bump github/codeql-action from 2.22.8 to 3.22.11 (#933)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.22.8 to 3.22.11.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](407ffafae6...b374143c11)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-major
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Coby Allred <cobyallred@gmail.com>
2023-12-19 14:56:37 -08:00
Sebastian Gomez 293fc608ed
Add Author/License to LinuxComponent (#934)
* Add Author/License to LinuxComponent

* Add unit test. Remove comment

* Increase coverage.

* Feedback

* Fix. Only Author and License are nullable.

---------

Co-authored-by: Sebastian Gomez <segomez@microsoft.com>
2023-12-19 11:53:19 -08:00
Sebastian Gomez ce76f5df26
Adds an entry point for the sbom-tool use the ScanCommand class. (#936)
* Add Author/License to LinuxComponent

* Add method to scan that returns a ScanResult Object

* Revert "Add Author/License to LinuxComponent"

This reverts commit 643dc09393.

* Add unit tests

---------

Co-authored-by: Sebastian Gomez <segomez@microsoft.com>
2023-12-19 11:17:37 -08:00
Fernando Rojo d4ca976992
Fix exit code check and virtual manifest parsing (RustCli) (#937)
* Fix exit code check and virtual manifest break

* Update test
2023-12-19 10:25:49 -08:00
Fernando Rojo ae7438f86c
Enable Experimental Rust and update telemetry (#931)
* Enable Experimental Rust and update telemetry
2023-12-07 22:07:42 -07:00
Greg Villicana 5f21f73f73
Promote NPM Lockfile v3 detector to run by default (#924) 2023-12-01 14:25:33 -08:00
renovate[bot] 4eb61d8c37
chore(deps): update dotnet monorepo (#892)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-12-01 21:39:24 +00:00
renovate[bot] 33e6eb334b
chore(deps): update actions/github-script action to v7 (#898)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-12-01 21:30:01 +00:00
Coby Allred b4def4c25b
Resolve Pip TryAdd exception on duplicates (#920)
Co-authored-by: Coby Allred <coallred@microsoft.com>
2023-12-01 08:54:37 -08:00
dependabot[bot] 5b5df20cfb
build(deps): bump github/codeql-action from 2.22.6 to 2.22.8 (#913)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.22.6 to 2.22.8.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](689fdc5193...407ffafae6)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
Co-authored-by: Coby Allred <cobyallred@gmail.com>
2023-11-30 18:59:34 +00:00
Michael Loughry 2455e9bd35
Skip detection of workspace projects in Yarn detector (#915)
* Potential fix for very large monorepos with yarn berry

* Update detector version

* Rename YarnLockVersion.V2 to YarnLockVersion.Berry

* Update CONTRIBUTING.md

* Add functional tests

---------

Co-authored-by: OWA Framework <owaframe@microsoft.com>
2023-11-30 08:56:52 -08:00
Sebastien Lebreton 46cbc8733e
Update detector-arguments.md (#918) 2023-11-29 11:58:58 -08:00
Sebastien Lebreton 2b8468b206
Add a parameter to disable the summary display (#917) 2023-11-29 11:33:07 -08:00
renovate[bot] 2bd065b51f
chore(deps): update dependency microsoft.sourcelink.github to v8 (#907)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-11-15 22:45:16 +00:00
renovate[bot] 6b8e481f29
chore(deps): update dependency microsoft.net.test.sdk to v17.8.0 (#893)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-11-15 22:02:29 +00:00
dependabot[bot] 16b87e382a
build(deps): bump github/codeql-action from 2.22.5 to 2.22.6 (#903)
Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2.22.5 to 2.22.6.
- [Release notes](https://github.com/github/codeql-action/releases)
- [Changelog](https://github.com/github/codeql-action/blob/main/CHANGELOG.md)
- [Commits](74483a38d3...689fdc5193)

---
updated-dependencies:
- dependency-name: github/codeql-action
  dependency-type: direct:production
  update-type: version-update:semver-patch
...

Signed-off-by: dependabot[bot] <support@github.com>
Co-authored-by: dependabot[bot] <49699333+dependabot[bot]@users.noreply.github.com>
2023-11-15 22:01:54 +00:00
renovate[bot] 8fd8eb7009
chore(deps): update dependency polly to v8.2.0 (#902)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-11-15 06:11:14 -08:00
renovate[bot] 454842ee6f
chore(deps): update dependency serilog to v3.1.1 (#895)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-11-15 06:07:47 -08:00
Rob Jellinghaus 03a561ac9c
Add --all-features per issue #894 (#897)
* Add --all-features per issue #894

* Fix formatting.

---------

Co-authored-by: Rob Jellinghaus <rjelling@microsoft.com>
2023-11-13 14:15:56 -06:00
Justin Perez 2701804770
fix(rust): don't mark build deps as dev deps (#889) 2023-11-06 13:22:47 -06:00
Amitla Vannikumar f42b36b1f8
Removing VCPKG Properties (#890)
* removing the VCPKG properties because they do not need to be in CD public

* changes

---------

Co-authored-by: Amitla Vannikumar <avannikumar@microsoft.com>
2023-11-06 11:21:29 -08:00
Jamie Magee b61d0ec02c
Remove `Microsoft.AspNet.WebApi.Client` (#886) 2023-11-01 18:10:07 +00:00
renovate[bot] 6d7c9b2768
chore(deps): update actions/checkout digest to b4ffde6 (#870)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-11-01 18:00:06 +00:00
renovate[bot] 097bb71836
chore(deps): update dependency morelinq to v4 (#882)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-11-01 17:51:27 +00:00
renovate[bot] 8f96a4f383
chore(deps): update actions/checkout action to v4.1.1 (#863)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-11-01 10:39:05 -07:00
renovate[bot] 283b996177
chore(deps): update dependency yamldotnet to v13.7.1 (#846)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-11-01 17:38:19 +00:00
renovate[bot] d380f4d1cc
chore(deps): update dependency spectre.console.cli.extensions.dependencyinjection to v0.2.0 (#884)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-11-01 17:37:44 +00:00
renovate[bot] 6701090145
chore(deps): update dependency polly to v8.1.0 (#885)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-10-31 14:12:21 -07:00
renovate[bot] 15e9b60f82
chore(deps): update dependency fluentassertions.analyzers to v0.26.0 (#881)
Co-authored-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
2023-10-30 09:24:16 -07:00