Releases: fossas/fossa-cli
Releases · fossas/fossa-cli
Release list
v3.20.0
What's Changed
- [ANE-Bot] Make Gradle init script work with the configuration cache by @fossa-ane-bot in #1790
- [ANE-Bot] Accept Gopkg.lock/Gopkg.toml with no dependencies by @fossa-ane-bot in #1791
- [ANE-3140] Adapt the Conan strategy in the CLI to emit native Conan source units by @GauravB159 in #1775
- [ANE-3140] Update Conan docs by @GauravB159 in #1792
Full Changelog: v3.19.3...v3.20.0
v3.19.3
v3.19.2
What's Changed
- [ANE-Bot] Accept go.mod files whose module directive is not first by @fossa-ane-bot in #1787
- [ANE-Bot] Fail container test through diagnostics instead of exitFailure by @fossa-ane-bot in #1785
- Fix analyze stalling and failing on large custom license searches by @nficca in #1788
Full Changelog: v3.19.1...v3.19.2
v3.19.1
What's Changed
- Poetry:
pyproject.tomlfiles with a[tool.poetry.dependencies]entry that has no version, git, path or url (e.g. a source-onlypkg = { source = "private" }that adds settings to a dependency declared in PEP 621[project].dependencies) no longer fail analysis. (#1784) - uv:
uv.lockfiles that lock more than one version of a package (e.g. different versions for different Python versions) now report every version under the package that depends on it. Previously only one version was kept, and the other versions' dependencies were reported as direct dependencies. (#1782)
Full Changelog: v3.19.0...v3.19.1
v3.19.0
What's Changed
fossa analyze --x-workflow(experimental) no longer takes a path to the analyzer. ficus downloads the workflow analyzer itself, so the path was validated and then discarded; the flag is now a switch, and a path following it is read as the scan target. (#1781)- NuGet: project files (
.csproj,.fsproj,.vbproj, ...) containing<PackageReference>items that name no package (e.g.<PackageReference Remove="..." />) no longer fail analysis withMissing attribute at [Project.ItemGroup.PackageReference]; attrName: Update; such items are skipped. (#1780) - Swift:
Package.swiftmanifests declaring package-registry dependencies (.package(id: "scope.name", from: "1.0.0")and the otherid:forms introduced in SwiftPM 5.7) no longer fail analysis withunexpected "id: "" expecting "name:", "path:", or "url:"; the dependency is reported under its registry identifier. (#1773)
Full Changelog: v3.18.4...v3.19.0
v3.18.4
What's Changed
Full Changelog: v3.18.3...v3.18.4
v3.18.3
What's Changed
- Dart:
pubspec.yamlfiles using valid dependency forms the parser previously rejected no longer fail analysis withAeson exception: ... emptyorfailed parsing pub package's source!: a bare dependency with no value (any version), aversion:-only entry, thehosted: <url>shorthand introduced in Dart 2.15, ahosted:map without aversion, and agit:map without aref. (#1760) - Workflows:
fossa analyze --x-workflow <path>runs a dependency-usage workflow analyzer through the embedded ficus and records its result in the debug bundle. (#1761) - Workflows: the
--x-workflowresult is uploaded to FOSSA against the analyzed revision once the dependency upload succeeds;--outputruns still upload nothing. (#1762) - Diagnostics: When an error or warning group contains multiple errors, each error's
Traceback:header is now printed on its own line instead of being glued onto the last line of the preceding error message (e.g....none passed validationTraceback:). (#1758)
Full Changelog: v3.18.2...v3.18.3
v3.18.2
Maven: recover duplicate-resolved dependency edges from the depgraph …
v3.18.1
What's Changed
- [ANE-Bot] Stop warning about missing setup.py in requirements.txt-only projects by @fossa-ane-bot in #1749
- Handle traits argument in Swift package dependencies by @tjugdev in #1746
- [ANE-Bot] Tolerate package-lock.json without a dependencies key by @fossa-ane-bot in #1753
- [ANE-Bot] Support pnpm v11 multi-document pnpm-lock.yaml by @fossa-ane-bot in #1754
- [ANE-1349] Binary discovery support for whl files by @GauravB159 in #1750
- [ANE-1350] Binary discovery support for nupkg files by @GauravB159 in #1751
Full Changelog: v3.18.0...v3.18.1
v3.18.0
- Container scanning:
fossa container analyzenow reports Go module dependencies embedded in Go binaries (built with Go >= 1.18) found in container image layers as regular Go dependencies, supporting images without package manager metadata such asscratchand distroless images (#1740) - Bun: Dependencies reachable only through a
devDependenciesentry are now reported as development dependencies instead of production dependencies. - Analysis: JSON manifest files with a leading UTF-8 byte order mark (commonly written by Windows tooling, e.g. in NuGet
project.json) no longer fail to parse. - NuGet:
project.jsonfiles that are not NuGet manifests (e.g. Nx project configuration) are no longer claimed by the NuGet analyzer, so they no longer fail analysis withkey "dependencies" not found. - NuGet:
project.jsonmanifests may omit the top-leveldependencieskey. - NuGet:
project.jsondependencies declared per-framework underframeworksare now reported.