Skip to content

Releases: coinbase/salus

2.17.6 (2022-04-05)

05 Apr 19:50
Compare
Choose a tag to compare

Changed

#554 - Upgraded Go and Gosec

2.17.5 (2021-03-23)

24 Mar 00:35
f64b5ab
Compare
Choose a tag to compare

Added

#567 Expanded Package Version Scanner to support blocking specific package versions.
#571 Package Version Scanner now supports Ruby (RubyPackageScanner).
#569 Package Version Scanner now supports Go (GoPackageScanner).
Package Version Scanner Documentation.

Changed

#567 - Bug fix for base package scanner class.

2.17.4 (2022-03-21)

21 Mar 19:38
7c551cc
Compare
Choose a tag to compare

Added

#563 Gradle CVE Scanner
#564 Python CVE Scanner

Changed

#563 Modified shell command used by Gradle Dependency Reporter.

2.17.3 (2021-03-10)

10 Mar 22:10
70d51a2
Compare
Choose a tag to compare

Added

#558 Golang CVE Scanner using OSV Database.
#562 Maven CVE Scanner using OSV Database.

Changed

#565 Update Golang Dependency Reporter to use a common parser.
#562 Update Maven Dependency Reporter to use a common parser.

2.17.2 (2021-02-25)

25 Feb 17:37
aad632b
Compare
Choose a tag to compare

Added
545 - Configuration parameter include_dev_deps now supported for node modules. CycloneDX scope parameter added
549 - Cascade configuration support for array override logic

Changed
552 - Insures all transitive dependencies are reported for NPM
550 - Updates to CycloneDX format for Dependency Track ingestion

2.17.1 (2022-02-15)

15 Feb 17:36
c138fd3
Compare
Choose a tag to compare
2.17.1 (2022-02-15) Pre-release
Pre-release

Added

#519 Maven Dependency Reporter
#527 Gradle Dependency Reporter
#538 NPM Package Version Scanning
#541 Bower Dependency Reporting

Changed

#523 Upgrade Gosec to 2.8.1
#526 Maven Dep Update
#532 Sorted report output

Fixed

#548 NPM Pacakge version scanner mix

2.17.0 (2022-01-20)

21 Jan 03:31
cb12aaf
Compare
Choose a tag to compare
2.17.0 (2022-01-20) Pre-release
Pre-release

New language versions scanners, concurrent scanning, bug fixes bundler update

Added

#485
Allow production option to npm audit command

#491
Update unit tests

#491
add line of code for bundle audit CVEs

#492
upgrade bundler to 2.3.1

#493
Add a new scanner for checking language version

#503
Support for files and not-followed-within in PatternSearch config

#508
add bugsnag logging if scanner_config has unexpected type

#512
Concurrent Scanning

#513
Set the Release Stage of Bugsnag based on a SALUS_ENVIRONMENT Envar

#515
upgrade bundler to 2.3.1 in Dockerfile

Fixed

#484
Add details for config.yaml error

#487
Fix CycloneDX error

#506
Fix typos

#506
Prevent NPMAudit From Adding Allowlisted Vulns to the SARIF Results List

#509
fix incorrect rule indexes for diff'd vuls

#514
Fix warning related SCANNERS constant

2.16.0 (2021-12-06)

06 Dec 18:31
a9157a5
Compare
Choose a tag to compare

Added

  • #475, #478, #482, #480 Support for filtering of sarif results with --sarif_diff_full ... --git_diff. It filters out sarif diff results that are likely not included in the git diff.
  • #481 Support for new scanner configuration settings to support recursive scanning.

2.15.0 (2021-11-17)

17 Nov 19:37
1937902
Compare
Choose a tag to compare

Added

#471 Added --reports CLI Flag to Filter Reports

Fixed

#472 NPMAudit Specs

2.14.0 (2021-11-03)

03 Nov 19:15
1e6cfc2
Compare
Choose a tag to compare

Changes:
#473 Golang 1.16 is now used for gosec scanning