Skip to content

chore(deps): update module osv-scanner to v2.6.0 - #42

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/osv-scanner-2.x
Open

renovate[bot] wants to merge 1 commit into
mainfrom
renovate/osv-scanner-2.x

Conversation

@renovate

@renovate renovate Bot commented Sep 15, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Change Age Confidence
osv-scanner v2.5.1 → v2.6.0 age confidence

Release Notes

google/osv-scanner (osv-scanner)

v2.6.0

Compare Source

Features:
  • Feature #​2888 Publish multi-arch (linux/arm64) image for osv-scanner-action.
  • Feature #​3066 Configure retry policy with exponential backoff for transient gRPC errors in scalibr plugins.
  • Dependency scanning & lockfile improvements via osv-scalibr:
    • Extract Git repository URLs and support local OSV tag matching for Git-based dependencies in JavaScript lockfiles (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock).
    • Assign pkg:git PURL type to Git commit-pinned dependencies across JS and Cargo lockfiles to avoid false positives against registry packages (#​2863).
    • Retain packages without a version or PURL in SPDX output (google/osv-scalibr#2375) and merge related packages based on lineage relationships.
  • New extractors and plugin support via osv-scalibr:
    • Many additional filetypes are supported. These are not enabled by default yet, so if you need a particular new filetype, use --experimental-plugins flag. See "Supported Inventory Types" for the extractor name.
Fixes:
  • Bug #​3075 Ensure results property in JSON output is an empty array [] instead of null when scanning with --allow-no-lockfiles and no lockfiles are found.
  • Bug #​3071 Preserve valid UTF-8 sequences when truncating multibyte text in vertical output.
  • Bug #​2919 Add filter to show packages with license violations but no vulnerabilities in the HTML report.
  • Bug #​3049 Keep filter dropdown checklist open when clicking options in the HTML report.
  • Bug #​3023 Guard against panic on empty or whitespace-only license expressions in SPDX license evaluation.
  • Bug #​3032 Bound recursion depth when parsing SPDX license expressions to prevent stack overflow on deeply nested expressions.
  • Bug #​3061 Remove purl caching in scan filtering to avoid dropping SBOM packages without purls.
  • Bug #​3063 Log plugin and enricher errors during container scans instead of failing silently.
  • Bug #​2977 Return an error instead of aborting the process (log.Fatalf) when an rlib archive has no object file during Rust source analysis.
  • Bug #​3083 Return a descriptive error from DoContainerScan when ScannerActions.Image is empty instead of panicking.
  • Fixes via osv-scalibr:
    • Fix false-positive Go standard library matches for packages with module paths ending in /go (e.g. pkg:golang/github.com/json-iterator/go) (#​3017).
    • Secure guided remediation file operations with os.Root to prevent path traversal attacks (google/osv-scalibr#2363).
    • Prevent OOM and disk exhaustion issues with tar bombs during archive extraction.
    • Strip platform suffix from RubyGems versions in CycloneDX (google/osv-scalibr#2313).
    • Ignore .deps.json files that don't have an object as their root in dotnet/depsjson extractor (google/osv-scalibr#2423).
Misc:
  • Update osv-scalibr to v0.5.3-0.20260911142458-3090dbb7aaa2 (#​3079).
  • Update Go to v1.27 and golangci-lint to v2.13 (#​3046).
    • This now supports call analysis on go v1.27 projects.
  • Update google.golang.org/grpc to v1.83.2 (#​3062).

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants