Skip to content

Releases: microsoft/component-detection

v4.2.2

05 Mar 03:11
1eea9ac
Compare
Choose a tag to compare

⚙️ Changes

  • Resolve vulnerabilities in transitive dep by @grvillic (#1023)
  • chore(deps): update github/codeql-action action to v3.24.6 by @renovate (#988)
  • Support development dependencies for the Gradle detector by @joakley-msft (#878)

v4.2.1

24 Feb 01:10
0b8a2e6
Compare
Choose a tag to compare

⚙️ Changes

  • Update RustCLI processing to handle virtual manifests / skip over vendor packages by @FernandoRojo (#1015)

🐛 Bug Fixes

  • Catch version spec failures in Python detection by @cobya (#1006)

🧰 Maintenance

  • build(deps): bump github/codeql-action from 3.23.2 to 3.24.1 by @dependabot (#1007)

v4.2.0

01 Feb 21:28
349ef7a
Compare
Choose a tag to compare

⚙️ Changes

🚀 New Features

  • Get ancestor for displaying dependency tree in relationships by @tarun06 (#927)

🐛 Bug Fixes

  • remove category usage from the poetry detector by @tofay (#991)

🧰 Maintenance

  • build(deps): bump codecov/codecov-action from 3.1.4 to 4.0.0 by @dependabot (#993)
  • build(deps): bump actions/upload-artifact from 4.2.0 to 4.3.0 by @dependabot (#984)
  • build(deps): bump github/codeql-action from 3.23.1 to 3.23.2 by @dependabot (#989)

v4.1.2

31 Jan 23:39
715078c
Compare
Choose a tag to compare

⚙️ Changes

v4.1.1

31 Jan 22:35
45431f1
Compare
Choose a tag to compare

⚙️ Changes

  • Add fallback logic for rust CLI detector and additional telemetry by @FernandoRojo (#990)
  • chore(deps): update spectre-console monorepo to v0.48.0 by @renovate (#925)
  • chore(deps): update dependency serilog.sinks.console to v5 by @renovate (#896)
  • chore(deps): update dependency faker.net to v2.0.163 by @renovate (#981)

v4.1.0

19 Jan 23:43
94d8c55
Compare
Choose a tag to compare

⚙️ Changes

  • Bump Syft from 0.74.0 to 0.100.0 by @JamieMagee (#960)
  • chore(deps): update github/codeql-action action to v3.23.1 by @renovate (#955)
  • Move Set scope to avoid cross-root conflicts by @FernandoRojo (#978)
  • Add hashtable to resolve circular rust dependencies by @FernandoRojo (#975)
  • chore(deps): update dependency polly to v8.2.1 by @renovate (#951)
  • chore(deps): update dependency stylecop.analyzers to v1.2.0-beta.556 by @renovate (#945)
  • chore(deps): update mcr.microsoft.com/dotnet/runtime-deps:6.0-cbl-mariner2.0 docker digest to 7b8cfde by @renovate (#943)
  • chore(deps): update dependency microsoft.visualstudio.threading.analyzers to v17.8.14 by @renovate (#905)
  • chore(deps): update nuget monorepo to v6.8.0 by @renovate (#911)
  • chore(deps): update dependency morelinq to v4.1.0 by @renovate (#922)
  • chore(deps): update dependency tomlyn.signed to v0.17.0 by @renovate (#923)

📝 Documentation

  • Fix link to the latest release by @50Wliu (#947)

🚀 New Features

🐛 Bug Fixes

  • Make Python detection more resilient to unexpected failure cases by @cobya (#962)

🧰 Maintenance

  • build(deps): bump actions/upload-artifact from 4.0.0 to 4.2.0 by @dependabot (#979)
  • build(deps): bump actions/upload-artifact from 3.1.3 to 4.0.0 by @dependabot (#935)
  • build(deps): bump actions/setup-dotnet from 3.2.0 to 4.0.0 by @dependabot (#926)
  • build(deps): bump github/codeql-action from 3.22.11 to 3.22.12 by @dependabot (#941)

v4.0.11

20 Dec 00:01
cf78e59
Compare
Choose a tag to compare

⚙️ Changes

  • Removed experiments on released detectors: NPM Lockfile V3 and Nuget by @grvillic (#939)

🧰 Maintenance

  • build(deps): bump github/codeql-action from 2.22.8 to 3.22.11 by @dependabot (#933)

v4.0.10

19 Dec 21:25
293fc60
Compare
Choose a tag to compare

⚙️ Changes

🚀 New Features

v4.0.9

08 Dec 23:44
ae7438f
Compare
Choose a tag to compare

⚙️ Changes

v4.0.8

01 Dec 22:27
5f21f73
Compare
Choose a tag to compare

⚙️ Changes

  • Promote NPM Lockfile v3 detector to run by default by @grvillic (#924)
  • chore(deps): update dotnet monorepo by @renovate (#892)
  • chore(deps): update actions/github-script action to v7 by @renovate (#898)
  • Skip detection of workspace projects in Yarn detector by @MLoughry (#915)
  • Update documentation for detector arguments by @sailro (#918)
  • Add a parameter to disable the summary display by @sailro (#917)
  • chore(deps): update dependency microsoft.sourcelink.github to v8 by @renovate (#907)
  • chore(deps): update dependency microsoft.net.test.sdk to v17.8.0 by @renovate (#893)
  • chore(deps): update dependency polly to v8.2.0 by @renovate (#902)
  • chore(deps): update dependency serilog to v3.1.1 by @renovate (#895)
  • Add --all-features per issue #894 by @RobJellinghaus (#897)

🐛 Bug Fixes

  • Resolve Pip TryAdd exception on duplicates by @cobya (#920)

🧰 Maintenance

  • build(deps): bump github/codeql-action from 2.22.6 to 2.22.8 by @dependabot (#913)
  • build(deps): bump github/codeql-action from 2.22.5 to 2.22.6 by @dependabot (#903)