chore(deps): update all github action dependencies (main) - #2057
Open
renovate[bot] wants to merge 1 commit into
Open
renovate[bot] wants to merge 1 commit into
renovate[bot] wants to merge 1 commit into
Conversation
Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>
This branch has not been deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
This PR contains the following updates:
1c5b675→2892aa5v0.7.1→v0.8.0Release Notes
kubernetes-sigs/bom (kubernetes-sigs/bom)
v0.8.0Compare Source
Changes by Kind
Deprecation
--format tag-valuefor the previous default. Pipelines that consumebom generateoutput without specifying a format will see JSON where they used to see tag-value.bom document outline,bom document queryandbom validateaccept CycloneDX 1.3–1.7 JSON and SPDX 2.2/2.3 in both tag-value and JSON encodings.go.mod/go.sumthrough the module proxy rather than by shelling out togo list, so a Go toolchain is no longer required to scan a Go codebase.--offlineflag scans without reaching the network. The document then lists every module a Go codebase requires in itsgo.mod, direct and indirect, but not the modules that appear only ingo.sum— the test-only and pruned dependencies of dependencies — and dependency licenses go unresolved. Scanning an image reference is refused outright, as pulling one needs a registry; image archives on disk are unaffected.pkg:ocipurl.spdxVersion, or with package originators that are neitherNOASSERTIONnor aPerson:/Organization:value, will fail to open.+renders as%2B— so purls match those produced by other SBOM tools byte for byte.pkg/spdxcompatibility layer now use the same classifier, where previously they could disagree. Edge-case classifications may differ from previous releases.bomno longer reads or writes a license cache to classify files; a license list is fetched only when something asks for one explicitly. TheCheckEmbeddedDataandUpdateEmbeddedDatamage targets that maintained the embedded archive are gone.externalDocumentRefs, and relationships pointing into another document, are dropped on parse. Support is planned upstream.--license,--no-gomod,--scan-imagesand--analyze-imagesare still accepted but no longer do anything, and warn when used. Reading a codebase's dependencies and a container image's packages are part of every scan now, deep image layer analysis has no equivalent in the new pipeline, and--licensenever had an effect. They are hidden from--helpand will be removed in a future major version.pkg/bompackage.bom.Generate(ctx, *GenerateOptions)runs the new engine and returns a protobom*sbom.Documentdirectly.pkg/spdxgained the convertersFromProtobomandToProtobom, andOpenProtobomto read any supported SBOM into a protobom document.DocGenerateOptionsgained anOfflinefield.pkg/queryis rewritten over protobom.Engine.Documentis now a protobom*sbom.Document,FilterResults.Objectsamap[string]*sbom.Node, andFilter.Apply,MatcherFunctionandObjectCycleroperate on protobom nodes and take the newquery.Graph. The query language and filter semantics are unchanged.spdx.DocBuilderImplementationinterface replacedCreateDocument,CreateSPDXClientand the fiveScan*methods with a singleGenerateDocument. The interface was never injectable from outside the package.cmd/bom/cmdfollow thepkg/queryrewrite:Printer.PrintObjectListnow takes protobom nodes.pkg/license's reader keeps its API, but licenses it returns from classification now carry only their SPDX identifier, not the metadata published in the license list — the classifier reports which license a file holds, not what that license says. Look an identifier up in aCatalogif you need the full record. For the same reasonReaderOptions'ConfidenceThreshold,CacheDir,LicenseDirandLicenseListVersionno longer affect classification, andReaderDefaultImpl.ClassifierandReaderDefaultImpl.Catalogreturn nil.DocGenerateOptionsfields the new engine does not implement are inert:Format,OutputFile,ProcessGoModules,LicenseandScanImagesare ignored, andAnalyseLayerswarns and does nothing. The format arguments tospdx.NewDocBuilderandspdx.WithFormatalready had no effect.pkg/bom.Generateorspdx.DocBuilder.Generateinstead.spdx.SPDX's generation methods:PackageFromDirectory,PackageFromImageTarball,PackageFromArchive,ImageRefToPackage,AnalyzeImageLayer,ExtractTarballTmp,PullImagesToArchivespdx.PullImageToArchivespdx.GoModule,spdx.NewGoModule,spdx.NewGoModuleFromPath,spdx.GoModImplementation,spdx.GoModDefaultImpland their supporting typesspdx.ImageAnalyzer,spdx.NewImageAnalyzer,spdx.ContainerLayerAnalyzer,spdx.ContainerLayerAnalyzerOptionspkg/osinfopackage, superseded by unpack's system decomposerspkg/spdx/json/v2.2package--no-gitignorenow works. The flag was declared and parsed but its value never reached the generator, so.gitignorefiles were always read.--no-transientnow works, and in the direction its help text describes. It was both dropped before reaching the generator and inverted on the way, so asking for direct dependencies only would have requested the opposite.bom validateand name filtering on JSON input.urn:uuid:. (#680, @puerco) [SIG Release]API Change
Feature
Open,ParseandWritetosigs.k8s.io/bom/pkg/bomand deprecatedspdx.DocBuilderandspdx.OpenDoc. Queries match multi-segment purl namespaces and reach relationship cycles,bom validate -dworks on Go module directories, and documents accepted by v0.7.1 can be read again. (#705, @saschagrunert) [SIG Release]bom document dotto export the relationship graph of an SPDX or CycloneDX SBOM in Graphviz DOT format. (#702, @saschagrunert) [SIG Release]bom generate --format spdx3-json. (#706, @saschagrunert) [SIG Release]bom generatelists Go binaries in images and files passed with--filetogether with the Go modules recorded in their build information. (#700, @saschagrunert) [SIG Release]Bug or Regression
--no-gomodworks again andSOURCE_DATE_EPOCHis honored. (#704, @saschagrunert) [SIG Release]Other (Cleanup or Flake)
Dependencies
Added
5032544Changed
Removed
1f47c86Configuration
📅 Schedule: (UTC)
🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.
♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.
👻 Immortal: This PR will be recreated if closed unmerged. Get config help if that's undesired.
This PR was generated by Mend Renovate. View the repository job log.