Skip to content

Releases: anchore/scan-action

Release v2.0.2

11 Nov 19:42
Compare
Choose a tag to compare

Minor bug-fix release:

Release v2.0.1

02 Nov 21:22
Compare
Choose a tag to compare

Minor bug-fix release.

Fixes:

  • Removes unnecessary constraint in deduplication for SARIF reporting
  • Allows defining and referencing the location of the SARIF report file
  • Fixes multiple instances where undefined items in the reporting would break scanning

Release v2.0.0

30 Sep 06:48
c2212d9
Compare
Choose a tag to compare

New major version of scan action based on new Grype tool from Anchore that is much faster for scanning compared to v1.x and adds some new capabilities and more metadata about the matches.

  • Significantly faster performance for scans
  • New vulnerabilities output format is the JSON output from Grype directly
  • Adds support for scanning directories as well as Docker containers, so you can do the same checks pre-and post-build of the container.
  • Supports Automatic Code Scanning/SARIF for exposing results via your repository's Security tab.

This is a breaking change from v1.x, as indicated by the major version revision:

  1. Use image input parameter Instead of image-reference
  2. dockerfile-path is no longer supported and not necessary for the vulnerability scans
  3. custom-policy-path is no longer supported
  4. include-app-packages is no longer necessary or supported. Application packages are on by default and will receive vulnerability matches.
  5. Outputs:
    1. billofmaterials is no longer output. V2 is focused on vulnerability scanning and another action may be introduced for BoM support with its own options/config.
    2. policycheck is no longer output

Release v1.0.9

02 Sep 19:32
5c18729
Compare
Choose a tag to compare

Update to Anchore Engine 0.8.1

Release v1.0.8

12 Aug 19:58
618cb77
Compare
Choose a tag to compare

Update to Anchore Engine 0.8.0

Release v1.0.7

10 Jul 00:16
2eb156f
Compare
Choose a tag to compare

Update to Anchore Engine 0.7.3

Release v1.0.6

09 Jun 17:58
7e648bc
Compare
Choose a tag to compare

Adds optional support for integration with GitHub code scanning.

v1.0.5 Release

08 Jun 20:27
642e59b
Compare
Choose a tag to compare

Update Anchore Engine to v0.7.2

v1.0.4 Release

04 May 19:50
cb690d8
Compare
Choose a tag to compare
Update v0.7.1 (#28)

* update dependencies
* update to engine v0.7.1

Signed-off-by: Brady Todhunter <bradyt@anchore.com>

v1.0.3 Release

02 Apr 18:11
1a2b817
Compare
Choose a tag to compare
check if failBuild is set specifically to true, not just a value (#24)

Signed-off-by: Brady Todhunter <bradyt@anchore.com>