Skip to content

Releases: fossas/fossa-cli

v3.20.0

Choose a tag to compare

@github-actions github-actions released this 30 Sep 00:10
79e6733

What's Changed

Full Changelog: v3.19.3...v3.20.0

v3.19.3

Choose a tag to compare

@github-actions github-actions released this 24 Sep 21:56
bcb808f

What's Changed

Full Changelog: v3.19.2...v3.19.3

v3.19.2

Choose a tag to compare

@github-actions github-actions released this 24 Sep 11:56
d72c5a5

What's Changed

  • [ANE-Bot] Accept go.mod files whose module directive is not first by @fossa-ane-bot in #1787
  • [ANE-Bot] Fail container test through diagnostics instead of exitFailure by @fossa-ane-bot in #1785
  • Fix analyze stalling and failing on large custom license searches by @nficca in #1788

Full Changelog: v3.19.1...v3.19.2

v3.19.1

Choose a tag to compare

@github-actions github-actions released this 22 Sep 16:38
0c4aaf9

What's Changed

  • Poetry: pyproject.toml files with a [tool.poetry.dependencies] entry that has no version, git, path or url (e.g. a source-only pkg = { source = "private" } that adds settings to a dependency declared in PEP 621 [project].dependencies) no longer fail analysis. (#1784)
  • uv: uv.lock files that lock more than one version of a package (e.g. different versions for different Python versions) now report every version under the package that depends on it. Previously only one version was kept, and the other versions' dependencies were reported as direct dependencies. (#1782)

Full Changelog: v3.19.0...v3.19.1

v3.19.0

Choose a tag to compare

@github-actions github-actions released this 21 Sep 15:05
822cd8a

What's Changed

  • fossa analyze --x-workflow (experimental) no longer takes a path to the analyzer. ficus downloads the workflow analyzer itself, so the path was validated and then discarded; the flag is now a switch, and a path following it is read as the scan target. (#1781)
  • NuGet: project files (.csproj, .fsproj, .vbproj, ...) containing <PackageReference> items that name no package (e.g. <PackageReference Remove="..." />) no longer fail analysis with Missing attribute at [Project.ItemGroup.PackageReference]; attrName: Update; such items are skipped. (#1780)
  • Swift: Package.swift manifests declaring package-registry dependencies (.package(id: "scope.name", from: "1.0.0") and the other id: forms introduced in SwiftPM 5.7) no longer fail analysis with unexpected "id: "" expecting "name:", "path:", or "url:"; the dependency is reported under its registry identifier. (#1773)

Full Changelog: v3.18.4...v3.19.0

v3.18.4

Choose a tag to compare

@github-actions github-actions released this 09 Sep 17:32
cf077a0

What's Changed

  • Maven: report declared dependencies as direct in static analysis by @csasarak in #1770

Full Changelog: v3.18.3...v3.18.4

v3.18.3

Choose a tag to compare

@github-actions github-actions released this 08 Sep 18:52
cba7185

What's Changed

  • Dart: pubspec.yaml files using valid dependency forms the parser previously rejected no longer fail analysis with Aeson exception: ... empty or failed parsing pub package's source!: a bare dependency with no value (any version), a version:-only entry, the hosted: <url> shorthand introduced in Dart 2.15, a hosted: map without a version, and a git: map without a ref. (#1760)
  • Workflows: fossa analyze --x-workflow <path> runs a dependency-usage workflow analyzer through the embedded ficus and records its result in the debug bundle. (#1761)
  • Workflows: the --x-workflow result is uploaded to FOSSA against the analyzed revision once the dependency upload succeeds; --output runs still upload nothing. (#1762)
  • Diagnostics: When an error or warning group contains multiple errors, each error's Traceback: header is now printed on its own line instead of being glued onto the last line of the preceding error message (e.g. ...none passed validationTraceback:). (#1758)

Full Changelog: v3.18.2...v3.18.3

v3.18.2

Choose a tag to compare

@github-actions github-actions released this 25 Aug 20:21
ceade12
Maven: recover duplicate-resolved dependency edges from the depgraph …

v3.18.1

Choose a tag to compare

@github-actions github-actions released this 25 Aug 01:21
eff9dbd

What's Changed

Full Changelog: v3.18.0...v3.18.1

v3.18.0

Choose a tag to compare

@github-actions github-actions released this 20 Aug 15:22
4cce15e
  • Container scanning: fossa container analyze now reports Go module dependencies embedded in Go binaries (built with Go >= 1.18) found in container image layers as regular Go dependencies, supporting images without package manager metadata such as scratch and distroless images (#1740)
  • Bun: Dependencies reachable only through a devDependencies entry are now reported as development dependencies instead of production dependencies.
  • Analysis: JSON manifest files with a leading UTF-8 byte order mark (commonly written by Windows tooling, e.g. in NuGet project.json) no longer fail to parse.
  • NuGet: project.json files that are not NuGet manifests (e.g. Nx project configuration) are no longer claimed by the NuGet analyzer, so they no longer fail analysis with key "dependencies" not found.
  • NuGet: project.json manifests may omit the top-level dependencies key.
  • NuGet: project.json dependencies declared per-framework under frameworks are now reported.