Releases: jeffmendoza/guac
Releases · jeffmendoza/guac
v0.6.0-betajeff
Changelog
- ede754a Add Deps.dev collector to guacone (guacsec#1661)
- c0e35bf Add GUAC Version to Logs (guacsec#1856)
- 2b196f5 Add Pagination to the Rest API (guacsec#1720)
- 89019ad Add a demo level docker compose yaml (guacsec#1747)
- 136ad62 Add guaccollect files option to set origin to blob path (guacsec#1811)
- ae3c1aa Add missing dev tools to nix shell (guacsec#1819)
- 37d720b Add standalone postgres compose
- d95860c Add the ability to specify HTTP headers for CLI commands (to support Auth proxies) (guacsec#1845)
- 42f945e Bump actions/cache from 3.3.3 to 4.0.0 (guacsec#1653)
- 642a10c Bump actions/cache from 4.0.0 to 4.0.1 (guacsec#1740)
- c6a5159 Bump actions/cache from 4.0.1 to 4.0.2 (guacsec#1782)
- a1b49c5 Bump actions/checkout from 4.1.1 to 4.1.2 (guacsec#1776)
- c6aaf87 Bump actions/checkout from 4.1.2 to 4.1.3 (guacsec#1861)
- 9686503 Bump actions/create-github-app-token from 1.6.3 to 1.6.4 (guacsec#1651)
- 9c3b5d0 Bump actions/create-github-app-token from 1.6.4 to 1.7.0 (guacsec#1667)
- 9e3cd9d Bump actions/create-github-app-token from 1.7.0 to 1.8.0 (guacsec#1704)
- ceb3192 Bump actions/create-github-app-token from 1.8.0 to 1.8.1 (guacsec#1724)
- 93887c6 Bump actions/create-github-app-token from 1.8.1 to 1.9.0 (guacsec#1741)
- 0620ad5 Bump actions/create-github-app-token from 1.9.0 to 1.9.1 (guacsec#1781)
- 3e827b8 Bump actions/create-github-app-token from 1.9.1 to 1.9.2 (guacsec#1802)
- eca2727 Bump actions/create-github-app-token from 1.9.2 to 1.9.3 (guacsec#1823)
- 5a048cd Bump actions/setup-python from 5.0.0 to 5.1.0 (guacsec#1801)
- 45356ea Bump anchore/sbom-action from 0.15.3 to 0.15.5 (guacsec#1652)
- c350930 Bump anchore/sbom-action from 0.15.5 to 0.15.6 (guacsec#1668)
- 3844bcf Bump anchore/sbom-action from 0.15.6 to 0.15.8 (guacsec#1691)
- 996f777 Bump anchore/sbom-action from 0.15.8 to 0.15.9 (guacsec#1767)
- ae9966c Bump anchore/sbom-action from 0.15.9 to 0.15.10 (guacsec#1803)
- a3c3690 Bump aquasecurity/trivy-action from 0.16.1 to 0.17.0 (guacsec#1703)
- 1b58cd4 Bump aquasecurity/trivy-action from 0.17.0 to 0.18.0 (guacsec#1742)
- 2dc06e2 Bump aquasecurity/trivy-action from 0.18.0 to 0.19.0 (guacsec#1804)
- a1fd412 Bump cloud.google.com/go/storage from 1.36.0 to 1.37.0 (guacsec#1687)
- 1770712 Bump cloud.google.com/go/storage from 1.37.0 to 1.38.0 (guacsec#1716)
- 033f281 Bump cloud.google.com/go/storage from 1.38.0 to 1.39.0 (guacsec#1744)
- bac5b6d Bump cloud.google.com/go/storage from 1.39.0 to 1.39.1 (guacsec#1763)
- 17e8bd7 Bump cloud.google.com/go/storage from 1.39.1 to 1.40.0 (guacsec#1799)
- b87ea96 Bump docker/login-action from 3.0.0 to 3.1.0 (guacsec#1775)
- d597f9e Bump entgo.io/ent v0.13.0 (guacsec#1707)
- 9e5d83d Bump github.com/99designs/gqlgen from 0.17.43 to 0.17.44 (guacsec#1715)
- eed71a5 Bump github.com/99designs/gqlgen from 0.17.44 to 0.17.45 (guacsec#1857)
- ade9c9e Bump github.com/Khan/genqlient from 0.6.0 to 0.7.0 (guacsec#1773)
- 36f1133 Bump github.com/arangodb/go-driver from 1.6.1 to 1.6.2 (guacsec#1826)
- 60210aa Bump github.com/aws/aws-sdk-go from 1.49.17 to 1.50.6 (guacsec#1672)
- f93a552 Bump github.com/aws/aws-sdk-go from 1.50.36 to 1.51.7 (guacsec#1787)
- f7bdab8 Bump github.com/aws/aws-sdk-go from 1.50.6 to 1.50.11 (guacsec#1689)
- 70babbd Bump github.com/aws/aws-sdk-go from 1.51.7 to 1.51.12 (guacsec#1798)
- 488b99e Bump github.com/aws/aws-sdk-go-v2 from 1.25.3 to 1.26.0 (guacsec#1772)
- 68230c5 Bump github.com/aws/aws-sdk-go-v2/config from 1.26.6 to 1.27.4 (guacsec#1725)
- b1c67c9 Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.48.0 to 1.48.1 (guacsec#1662)
- 5c5973f Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.48.1 to 1.51.4 (guacsec#1760)
- 5c56383 Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.51.4 to 1.53.0 (guacsec#1786)
- 9c1eb23 Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.53.0 to 1.53.1 (guacsec#1840)
- a895253 Bump github.com/aws/aws-sdk-go-v2/service/sqs from 1.29.7 to 1.31.2 (guacsec#1766)
- f0e44fd Bump github.com/aws/aws-sdk-go-v2/service/sqs from 1.31.2 to 1.31.4 (guacsec#1825)
- 590df02 Bump github.com/cloudevents/sdk-go/v2 from 2.10.1 to 2.15.0 (guacsec#1669)
- ce741a7 Bump github.com/cloudevents/sdk-go/v2 from 2.15.0 to 2.15.1 (guacsec#1728)
- c3efd23 Bump github.com/cloudevents/sdk-go/v2 from 2.15.1 to 2.15.2 (guacsec#1754)
- 5b8d7a9 Bump github.com/deepmap/oapi-codegen/v2 from 2.0.1-0.20240123090344-d326c01d279a to 2.1.0 (guacsec#1713)
- b6608f6 Bump github.com/docker/docker (guacsec#1778)
- 0919d31 Bump github.com/fsouza/fake-gcs-server from 1.47.7 to 1.47.8 (guacsec#1743)
- 13b5121 Bump github.com/getkin/kin-openapi from 0.122.0 to 0.123.0 (guacsec#1727)
- e283206 Bump github.com/go-chi/chi from 1.5.5 to 4.1.2+incompatible (guacsec#1761)
- fe4faee Bump github.com/go-chi/chi/v5 from 5.0.11 to 5.0.12 (guacsec#1788)
- 19506b6 Bump github.com/go-git/go-git/v5 from 5.11.0 to 5.12.0 (guacsec#1827)
- a6c67d3 Bump github.com/google/osv-scanner from 1.4.3 to 1.6.1 (guacsec#1657)
- 90fc632 Bump github.com/google/osv-scanner from 1.6.1 to 1.7.0 (guacsec#1755)
- 60d8dc8 Bump github.com/google/osv-scanner from 1.7.0 to 1.7.1 (guacsec#1824)
- b7e84b9 Bump github.com/jedib0t/go-pretty/v6 from 6.5.3 to 6.5.4 (guacsec#1673)
- 755c47e Bump github.com/klauspost/compress from 1.17.4 to 1.17.5 (guacsec#1671)
- efd46f3 Bump github.com/klauspost/compress from 1.17.5 to 1.17.6 (guacsec#1701)
- 6c45c18 Bump github.com/moby/buildkit from 0.12.2 to 0.12.5 (guacsec#1679)
- 59897f2 Bump github.com/nats-io/nats-server/v2 from 2.10.11 to 2.10.12 (guacsec#1774)
- e1d3451 Bump github.com/nats-io/nats-server/v2 from 2.10.9 to 2.10.10 (guacsec#1686)
- 32169e5 Bump github.com/nats-io/nats.go from 1.32.0 to 1.33.1 (guacsec#1726)
- 1857403 Bump github.com/nats-io/nats.go from 1.33.1 to 1.34.0 (guacsec#1800)
- cc5f59f Bump github.com/pitabwire/natspubsub from 0.1.1 to 0.1.2 (guacsec#1764)
- 282ea21 Bump github.com/pitabwire/natspubsub from 0.1.2 to 0.1.3 (guacsec#1843)
- 8eaa7ed Bump github.com/prometheus/client_golang from 1.18.0 to 1.19.0 (guacsec#1745)
- cf9ccd3 Bump github.com/redis/go-redis/v9 from 9.4.0 to 9.5.0 (guacsec#1714)
- 6a164f5 Bump github.com/redis/go-redis/v9 from 9.5.0 to 9.5.1 (guacsec#1841)
- 75a5ae7 Bump github.com/regclient/regclient from 0.5.5 to 0.5.6 (guacsec#1688)
- 644b493 Bump github.com/regclient/regclient from 0.5.6 to 0.5.7 (guacsec#1700)
- af5d83e Bump github.com/regclient/regclient from 0.5.7 to 0.6.0 (guacsec#1797)
- 91a9be2 Bump github.com/segmentio/kafka-go from 0.4.46 to 0.4.47 (guacsec#1655)
- 315dfef Bump github.com/sigstore/sigstore from 1.8.0 to 1.8.1 (guacsec#1654)
- b69464a Bump github.com/sigstore/sigstore from 1.8.1 to 1.8.2 (guacsec#1785)
- 1ea2819 Bump github.com/spdx/tools-golang from 0.5.3 to 0.5.4 (guacsec#1860)
- ec85ecd Bump github.com/stretchr/testify from 1.8.4 to 1.9.0 (guacsec#1746)
- 4adbf13 Bump github.com/swaggo/swag from 1.16.2 to 1.16.3 (guacsec#1698)
- 3100b05 Bump go.uber.org/zap from 1.26.0 to 1.27.0 (guacsec#1762)
- 5cccd5e Bump gocloud.dev from 0.36.0 to 0.37.0 (guacsec#1770)
- dcf7cef Bump gocloud.dev/pubsub/kafkapubsub from 0.36.0 to 0.37.0 (guacsec#1784)
- bb6b63d Bump gocloud.dev/pubsub/rabbitpubsub from 0.36.0 to 0.37.0 (guacsec#1842)
- 9317e44 Bump golang.org/x/net from 0.22.0 to 0.23.0 (guacsec#1853)
- 3b007a2 Bump golang.org/x/oauth2 from 0.17.0 to 0.18.0 (guacsec#1771)
- 694a8f2 Bump golangci/golangci-lint-action from 3.7.0 to 4.0.0 (guacsec#1702)
- 6e88dab Bump google.golang.org/api from 0.154.0 to 0.157.0 (guacsec#1656)
- 9db9b6a Bump google.golang.org/api from 0.157.0 to 0.160.0 (guacsec#1670)
- 9445fc0 Bump google.golang.org/api from 0.169.0 to 0.172.0 (guacsec#1796)
- a2c1206 Bump google.golang.org/api from 0.172.0 to 0.176.0 (guacsec#1858)
- abd5a73 Bump google.golang.org/grpc from 1.60.1 to 1.61.0 (guacsec#1685)
- e8e4c30 Bump google.golang.org/grpc from 1.62.1 to 1.63.2 (guacsec#1859)
- c85eb0e Bump gopkg.in/go-jose/go-jose.v2 from 2.6.1 to 2.6.3 (guacsec#1758)
- e023b46 Bump sigstore/cosign-installer from 3.3.0 to 3.4.0 (guacsec#1690)
- d3f8704 Bump sigstore/cosign-installer from 3.4.0 to 3.5.0 (guacsec#1839)
- 1357a7c Bump slsa-framework/slsa-github-generator from 1.9.0 to 1.10.0 (guacsec#1783)
- 755a8e8 Check DependencyType values in isDependency ingestion and queries (guacsec#1780)
- d5feab1 ENT - bulk ingestion and update to use
IDorInputSpec
(guacsec#1732) - 237ff8c Encoding guesser (guacsec#1472)
- f750549 Error and exit when initialization fails (guacsec#1674)
- 71c5547 Fix GitHub collector to accept explicit tag in urls (guacsec#1818)
- e9e3551 Fix License node ingestion when no LicenseListVersion provided. (guacsec#1738)
- 1381c07 Fix goreleaser flag deprecation warnings (guacsec#1814)
- db16cdc Fix the Overview Diagram (guacsec#1836)
- 431a286 Fix the incorrect
callingFuncName
in thegetNeighborIDFromCursor
(guacsec#1730) - 4428d22 Fixed flaky test (guacsec#1752)
- 652c333 Fixed typos (guacsec#1751)
- 52a55e4 Github Collector Enhancements (guacsec#1566)
- dbf92ad Gqlschemafix (guacsec#1683)
- 4741c1c Handle null SPDX relationship values without panicking (guacsec#1822)
- 5fbba0d Id or inputspec (guacsec#1708)
- 645dcbc Implemented key value search (guacsec#1711)
- e8ff763 Improve guac query vuln error message (guacsec#1695)
- 358205b Include a more descriptive debugger for the collector and processor (guacsec#1830)
- ac4c273 Include missing collectors (guacsec#1759)
- 249a6f5 Included Guacone Collect Github (guacsec#1677)
- d4a9a96 Included Polling for Github Collect (guacsec#1678)
- f8286dd Included Query for Scorecard (guacsec#1791)
- 638ba85 Included a README for guacrest (guacsec#1719)
- e2c8157 Included http middleware to measure the graphql response times using prometheus. (guacsec#1675)
- de3cd11 Included prometheus server for guacql (guacsec#1635)
- c628147 Move all arango tests to common integration test suite. (guacsec#1660)
- 3577d4d Populate SourceInformation.DocumentRef in collectors (guacsec#1847)
- 67e4664 README for the Github Collector (guacsec#1731)
- 1f9eb7c Remove empty depends_on that fails validation. (guacsec#1757)
- 3f124e3 Remove unused variable (guacsec#1851)
- ef4658e Run the guacgql HTTP server on only one port (guacsec#1805)
- 693be1a Support image references by digest in the OCI collector (guacsec#1779)
- 2169376 Update CONTRIBUTING.md about DCO and CLA. (guacsec#1723)
- b0969e3 Update default
blob-addr
to use filesystem (for docker-compose and k8s) (guacsec#1666) - d0c51f5 Update error handling on ingestion (guacsec#1832)
- 6638a53 Update gql, parser and backends to add new
documentRef
field (guacsec#1844) - a0a0a82 Update graphQL schema to add documentRef field to all verbs (guacsec#1834)
- d861241 Update graphQL, resolvers and add backend stubs for pagination (guacsec#1862)
- f6e9f46 Use filename as qualifier for SBOM file referen...
v0.5.0-betajeff2
Changelog
- ede754a Add Deps.dev collector to guacone (guacsec#1661)
- 0a929ee Add a demo level docker compose yaml
- 42f945e Bump actions/cache from 3.3.3 to 4.0.0 (guacsec#1653)
- 9686503 Bump actions/create-github-app-token from 1.6.3 to 1.6.4 (guacsec#1651)
- 9c3b5d0 Bump actions/create-github-app-token from 1.6.4 to 1.7.0 (guacsec#1667)
- 9e3cd9d Bump actions/create-github-app-token from 1.7.0 to 1.8.0 (guacsec#1704)
- ceb3192 Bump actions/create-github-app-token from 1.8.0 to 1.8.1 (guacsec#1724)
- 45356ea Bump anchore/sbom-action from 0.15.3 to 0.15.5 (guacsec#1652)
- c350930 Bump anchore/sbom-action from 0.15.5 to 0.15.6 (guacsec#1668)
- 3844bcf Bump anchore/sbom-action from 0.15.6 to 0.15.8 (guacsec#1691)
- a3c3690 Bump aquasecurity/trivy-action from 0.16.1 to 0.17.0 (guacsec#1703)
- a1fd412 Bump cloud.google.com/go/storage from 1.36.0 to 1.37.0 (guacsec#1687)
- 1770712 Bump cloud.google.com/go/storage from 1.37.0 to 1.38.0 (guacsec#1716)
- d597f9e Bump entgo.io/ent v0.13.0 (guacsec#1707)
- 9e5d83d Bump github.com/99designs/gqlgen from 0.17.43 to 0.17.44 (guacsec#1715)
- 60210aa Bump github.com/aws/aws-sdk-go from 1.49.17 to 1.50.6 (guacsec#1672)
- f7bdab8 Bump github.com/aws/aws-sdk-go from 1.50.6 to 1.50.11 (guacsec#1689)
- 68230c5 Bump github.com/aws/aws-sdk-go-v2/config from 1.26.6 to 1.27.4 (guacsec#1725)
- b1c67c9 Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.48.0 to 1.48.1 (guacsec#1662)
- 590df02 Bump github.com/cloudevents/sdk-go/v2 from 2.10.1 to 2.15.0 (guacsec#1669)
- ce741a7 Bump github.com/cloudevents/sdk-go/v2 from 2.15.0 to 2.15.1 (guacsec#1728)
- 5b8d7a9 Bump github.com/deepmap/oapi-codegen/v2 from 2.0.1-0.20240123090344-d326c01d279a to 2.1.0 (guacsec#1713)
- 13b5121 Bump github.com/getkin/kin-openapi from 0.122.0 to 0.123.0 (guacsec#1727)
- a6c67d3 Bump github.com/google/osv-scanner from 1.4.3 to 1.6.1 (guacsec#1657)
- b7e84b9 Bump github.com/jedib0t/go-pretty/v6 from 6.5.3 to 6.5.4 (guacsec#1673)
- 755c47e Bump github.com/klauspost/compress from 1.17.4 to 1.17.5 (guacsec#1671)
- efd46f3 Bump github.com/klauspost/compress from 1.17.5 to 1.17.6 (guacsec#1701)
- 6c45c18 Bump github.com/moby/buildkit from 0.12.2 to 0.12.5 (guacsec#1679)
- e1d3451 Bump github.com/nats-io/nats-server/v2 from 2.10.9 to 2.10.10 (guacsec#1686)
- 32169e5 Bump github.com/nats-io/nats.go from 1.32.0 to 1.33.1 (guacsec#1726)
- cf9ccd3 Bump github.com/redis/go-redis/v9 from 9.4.0 to 9.5.0 (guacsec#1714)
- 75a5ae7 Bump github.com/regclient/regclient from 0.5.5 to 0.5.6 (guacsec#1688)
- 644b493 Bump github.com/regclient/regclient from 0.5.6 to 0.5.7 (guacsec#1700)
- 91a9be2 Bump github.com/segmentio/kafka-go from 0.4.46 to 0.4.47 (guacsec#1655)
- 315dfef Bump github.com/sigstore/sigstore from 1.8.0 to 1.8.1 (guacsec#1654)
- 4adbf13 Bump github.com/swaggo/swag from 1.16.2 to 1.16.3 (guacsec#1698)
- 694a8f2 Bump golangci/golangci-lint-action from 3.7.0 to 4.0.0 (guacsec#1702)
- 6e88dab Bump google.golang.org/api from 0.154.0 to 0.157.0 (guacsec#1656)
- 9db9b6a Bump google.golang.org/api from 0.157.0 to 0.160.0 (guacsec#1670)
- abd5a73 Bump google.golang.org/grpc from 1.60.1 to 1.61.0 (guacsec#1685)
- e023b46 Bump sigstore/cosign-installer from 3.3.0 to 3.4.0 (guacsec#1690)
- d5feab1 ENT - bulk ingestion and update to use
IDorInputSpec
(guacsec#1732) - 237ff8c Encoding guesser (guacsec#1472)
- f750549 Error and exit when initialization fails (guacsec#1674)
- e9e3551 Fix License node ingestion when no LicenseListVersion provided. (guacsec#1738)
- 431a286 Fix the incorrect
callingFuncName
in thegetNeighborIDFromCursor
(guacsec#1730) - 52a55e4 Github Collector Enhancements (guacsec#1566)
- dbf92ad Gqlschemafix (guacsec#1683)
- 5fbba0d Id or inputspec (guacsec#1708)
- 645dcbc Implemented key value search (guacsec#1711)
- e8ff763 Improve guac query vuln error message (guacsec#1695)
- e2c8157 Included http middleware to measure the graphql response times using prometheus. (guacsec#1675)
- de3cd11 Included prometheus server for guacql (guacsec#1635)
- c628147 Move all arango tests to common integration test suite. (guacsec#1660)
- 2169376 Update CONTRIBUTING.md about DCO and CLA. (guacsec#1723)
- b0969e3 Update default
blob-addr
to use filesystem (for docker-compose and k8s) (guacsec#1666) - f6e9f46 Use filename as qualifier for SBOM file references (guacsec#1546)
- f393612 Use graphql.HasOperationContext in arangodb assembler (guacsec#1659)
- db84270 Utilize gocloud and blob store to work around pubsub message size (guacsec#1630)
- 2b3b18e [Rest API] Adds the initial API Spec and guacrest cli. (guacsec#1665)
- eee82ba abstract pubsub service via gocloud (guacsec#1664)
- 3f2ef06 add purl helper to convert from allPkgTree fragment (guacsec#1681)
- 99a4d54 attempt to fix golangci-lint issues (guacsec#1735)
- 8c27a44 feature: Verify the DSSE envelope if the verifier-key-path and verifier-key-id are provided. Fail the provenance ingestion if the document is not verified. (guacsec#1712)
- 1e337e3 fix: s3 collector (guacsec#1658)
- f1703bd fix[update-arango-graph] - creates a missing collection in already pr… (guacsec#1649)
- db6cfcc removing MAX_CONCURRENT_JOBS (guacsec#1682)
- ef4c295 save qualifiers from golang loop semantics (guacsec#1684)
- 753e57b separate software IDs into packages and artifacts for hasSBOM ingestion (guacsec#1718)
- c3464f8 update dsse processor to not guess unpacked payload (guacsec#1647)
v0.5.0-betajeff
Changelog
- ede754a Add Deps.dev collector to guacone (guacsec#1661)
- d9963ac Add a demo level docker compose yaml
- 42f945e Bump actions/cache from 3.3.3 to 4.0.0 (guacsec#1653)
- 9686503 Bump actions/create-github-app-token from 1.6.3 to 1.6.4 (guacsec#1651)
- 9c3b5d0 Bump actions/create-github-app-token from 1.6.4 to 1.7.0 (guacsec#1667)
- 9e3cd9d Bump actions/create-github-app-token from 1.7.0 to 1.8.0 (guacsec#1704)
- ceb3192 Bump actions/create-github-app-token from 1.8.0 to 1.8.1 (guacsec#1724)
- 45356ea Bump anchore/sbom-action from 0.15.3 to 0.15.5 (guacsec#1652)
- c350930 Bump anchore/sbom-action from 0.15.5 to 0.15.6 (guacsec#1668)
- 3844bcf Bump anchore/sbom-action from 0.15.6 to 0.15.8 (guacsec#1691)
- a3c3690 Bump aquasecurity/trivy-action from 0.16.1 to 0.17.0 (guacsec#1703)
- a1fd412 Bump cloud.google.com/go/storage from 1.36.0 to 1.37.0 (guacsec#1687)
- 1770712 Bump cloud.google.com/go/storage from 1.37.0 to 1.38.0 (guacsec#1716)
- d597f9e Bump entgo.io/ent v0.13.0 (guacsec#1707)
- 9e5d83d Bump github.com/99designs/gqlgen from 0.17.43 to 0.17.44 (guacsec#1715)
- 60210aa Bump github.com/aws/aws-sdk-go from 1.49.17 to 1.50.6 (guacsec#1672)
- f7bdab8 Bump github.com/aws/aws-sdk-go from 1.50.6 to 1.50.11 (guacsec#1689)
- 68230c5 Bump github.com/aws/aws-sdk-go-v2/config from 1.26.6 to 1.27.4 (guacsec#1725)
- b1c67c9 Bump github.com/aws/aws-sdk-go-v2/service/s3 from 1.48.0 to 1.48.1 (guacsec#1662)
- 590df02 Bump github.com/cloudevents/sdk-go/v2 from 2.10.1 to 2.15.0 (guacsec#1669)
- ce741a7 Bump github.com/cloudevents/sdk-go/v2 from 2.15.0 to 2.15.1 (guacsec#1728)
- 5b8d7a9 Bump github.com/deepmap/oapi-codegen/v2 from 2.0.1-0.20240123090344-d326c01d279a to 2.1.0 (guacsec#1713)
- 13b5121 Bump github.com/getkin/kin-openapi from 0.122.0 to 0.123.0 (guacsec#1727)
- a6c67d3 Bump github.com/google/osv-scanner from 1.4.3 to 1.6.1 (guacsec#1657)
- b7e84b9 Bump github.com/jedib0t/go-pretty/v6 from 6.5.3 to 6.5.4 (guacsec#1673)
- 755c47e Bump github.com/klauspost/compress from 1.17.4 to 1.17.5 (guacsec#1671)
- efd46f3 Bump github.com/klauspost/compress from 1.17.5 to 1.17.6 (guacsec#1701)
- 6c45c18 Bump github.com/moby/buildkit from 0.12.2 to 0.12.5 (guacsec#1679)
- e1d3451 Bump github.com/nats-io/nats-server/v2 from 2.10.9 to 2.10.10 (guacsec#1686)
- 32169e5 Bump github.com/nats-io/nats.go from 1.32.0 to 1.33.1 (guacsec#1726)
- cf9ccd3 Bump github.com/redis/go-redis/v9 from 9.4.0 to 9.5.0 (guacsec#1714)
- 75a5ae7 Bump github.com/regclient/regclient from 0.5.5 to 0.5.6 (guacsec#1688)
- 644b493 Bump github.com/regclient/regclient from 0.5.6 to 0.5.7 (guacsec#1700)
- 91a9be2 Bump github.com/segmentio/kafka-go from 0.4.46 to 0.4.47 (guacsec#1655)
- 315dfef Bump github.com/sigstore/sigstore from 1.8.0 to 1.8.1 (guacsec#1654)
- 4adbf13 Bump github.com/swaggo/swag from 1.16.2 to 1.16.3 (guacsec#1698)
- 694a8f2 Bump golangci/golangci-lint-action from 3.7.0 to 4.0.0 (guacsec#1702)
- 6e88dab Bump google.golang.org/api from 0.154.0 to 0.157.0 (guacsec#1656)
- 9db9b6a Bump google.golang.org/api from 0.157.0 to 0.160.0 (guacsec#1670)
- abd5a73 Bump google.golang.org/grpc from 1.60.1 to 1.61.0 (guacsec#1685)
- e023b46 Bump sigstore/cosign-installer from 3.3.0 to 3.4.0 (guacsec#1690)
- d5feab1 ENT - bulk ingestion and update to use
IDorInputSpec
(guacsec#1732) - 237ff8c Encoding guesser (guacsec#1472)
- f750549 Error and exit when initialization fails (guacsec#1674)
- e9e3551 Fix License node ingestion when no LicenseListVersion provided. (guacsec#1738)
- 431a286 Fix the incorrect
callingFuncName
in thegetNeighborIDFromCursor
(guacsec#1730) - 52a55e4 Github Collector Enhancements (guacsec#1566)
- dbf92ad Gqlschemafix (guacsec#1683)
- 5fbba0d Id or inputspec (guacsec#1708)
- 645dcbc Implemented key value search (guacsec#1711)
- e8ff763 Improve guac query vuln error message (guacsec#1695)
- e2c8157 Included http middleware to measure the graphql response times using prometheus. (guacsec#1675)
- de3cd11 Included prometheus server for guacql (guacsec#1635)
- c628147 Move all arango tests to common integration test suite. (guacsec#1660)
- 2169376 Update CONTRIBUTING.md about DCO and CLA. (guacsec#1723)
- b0969e3 Update default
blob-addr
to use filesystem (for docker-compose and k8s) (guacsec#1666) - f6e9f46 Use filename as qualifier for SBOM file references (guacsec#1546)
- f393612 Use graphql.HasOperationContext in arangodb assembler (guacsec#1659)
- db84270 Utilize gocloud and blob store to work around pubsub message size (guacsec#1630)
- 2b3b18e [Rest API] Adds the initial API Spec and guacrest cli. (guacsec#1665)
- eee82ba abstract pubsub service via gocloud (guacsec#1664)
- 3f2ef06 add purl helper to convert from allPkgTree fragment (guacsec#1681)
- 99a4d54 attempt to fix golangci-lint issues (guacsec#1735)
- 8c27a44 feature: Verify the DSSE envelope if the verifier-key-path and verifier-key-id are provided. Fail the provenance ingestion if the document is not verified. (guacsec#1712)
- 1e337e3 fix: s3 collector (guacsec#1658)
- f1703bd fix[update-arango-graph] - creates a missing collection in already pr… (guacsec#1649)
- db6cfcc removing MAX_CONCURRENT_JOBS (guacsec#1682)
- ef4c295 save qualifiers from golang loop semantics (guacsec#1684)
- 753e57b separate software IDs into packages and artifacts for hasSBOM ingestion (guacsec#1718)
- c3464f8 update dsse processor to not guess unpacked payload (guacsec#1647)
v0.1.1-jeff4
Changelog
- a16ea62 Update compose.yml for podman compatibility.
v0.1.1-jeff3
Changelog
- 9279015 Add CVE, GHSA and OSV tries GraphQL schema (guacsec#399)
- 13b9a49 Add Certifier cmd to guacone (guacsec#246)
- 649c204 Add Certify bad query and re-org the query CLI (guacsec#807)
- 035bf1f Add CertifyGood as a copy of CertifyBad (guacsec#652)
- f407e04 Add CertifyPkg schema with testing backend (guacsec#455)
- ad806a2 Add DSSE processor
- 3c59c1e Add Github Collector (guacsec#498)
- 3bc26e4 Add GraphQL documentation doc. (guacsec#785)
- ddabdf6 Add HasMetadata operations and inmem implementation (guacsec#1023)
- bf20b1a Add HasSBOM attestation with testing backend (guacsec#452)
- acad3d7 Add Hash equal schema for GraphQL (guacsec#442)
- 4c14629 Add ID and backedges for certifyPkg. (guacsec#628)
- df08235 Add IDs and back edges for certify vex and certify bad (guacsec#626)
- 5234d9b Add IsOccurrence to GraphQL Schema (guacsec#447)
- 354783c Add Luke to TAM (guacsec#271)
- 43f3e34 Add Neo4j Backend queries (guacsec#417)
- 6ab04cd Add NoKnownVuln node and related operations. (guacsec#673)
- f3e8991 Add Node query (guacsec#679)
- a7180a4 Add Nodes query needed for UI. (guacsec#812)
- 696557b Add POC to setup.md (guacsec#162)
- 08bfd91 Add PkgEqual and HashEqual predictaes -- testing + code planning (guacsec#1069)
- 37fde17 Add SETUP-new.md and supporting query and script files. (guacsec#662)
- e3add68 Add WhichVersionMatchesfunction implementation (guacsec#796)
- 2aeb88c Add
CONTRIBUTING.md
- 57d60ea Add a CI step to run current go tests.
- 794cf66 Add a CI workflow using neo4j.
- 663b076 Add a collectsub client type Datasource for collectors (guacsec#403)
- 9cc17ad Add ability to add ingestPredicates documents for ingestion (guacsec#1051)
- 09db2dc Add additional DSSE tests
- cf8ab73 Add artifact and builder graphQL schema (guacsec#400)
- 4936a26 Add back testing utils
- b93696d Add bot configurations (guacsec#85)
- cda3a6b Add collectsub service and OCI collector to all-in-one deployment (guacsec#430)
- 314850a Add compose tarball to release workflow.
- f4a1e53 Add contributor ladder process. (guacsec#750)
- 4cd1e8c Add deps.dev cmd implementation of collector subscriber (guacsec#660)
- 14be5a3 Add deps.dev collector, processor and parser (guacsec#654)
- debb811 Add developer documentation (guacsec#126)
- b0490b1 Add edges
- 58cfe73 Add end to end test (guacsec#685)
- 3d2f3da Add file collector (guacsec#79)
- 3b51228 Add graphql query examples (guacsec#473)
- fc6860d Add identity verifier interface
- 9a33cd4 Add ingestion for sources, on both backends (guacsec#481)
- 7b31843 Add ingestion mutation for SLSA (guacsec#553)
- b5db2c1 Add initial graphdb package
- 3587e04 Add initial nodes for arangoDB backend implementation (guacsec#911)
- b515708 Add instructions to start docker with apoc (guacsec#174)
- 02968d0 Add maintainers and governance
- af5516a Add markdown format check to ci (guacsec#686)
- 4fb814c Add more error checking for inmem backend. (guacsec#700)
- 3f9016b Add mutation to ingest artifacts (guacsec#485)
- caa8efd Add mutation to ingest builders (guacsec#491)
- 0917297 Add neighbors and path GraphQL queries. (guacsec#624)
- 70f291d Add nodes for attestations, artifacts and builders
- 2a96e7f Add package qualifiers to package trie and query spec (guacsec#394)
- 7eced3b Add package trie GraphQL schema (before qualifiers) (guacsec#391)
- 3885c0e Add packages to shell.nix (guacsec#1025)
- 7334096 Add processorInput structs
- b0659a8 Add query vulnerability CLI demo documentation (guacsec#742)
- 48acf14 Add reachability testdata (guacsec#609)
- d0fe467 Add resolvers based on selected fields (guacsec#422)
- 599889c Add scorecard guesser/processor (guacsec#127)
- 2050d84 Add scorecard parser integration (guacsec#521)
- d29cbb8 Add search gql (guacsec#998)
- 3d815f8 Add shell.nix
- 2b3ded4 Add simple SLSA identifier strings and provide integration with ingestor (guacsec#449)
- c3f4279 Add single happy path test for isOccurrence (guacsec#620)
- 7ce905f Add source trie GraphQL schema (guacsec#398)
- 290c1c3 Add support for ingesting VEX documents in the CSAF format (guacsec#729)
- f4eeb7b Add templates for issues and PRs (guacsec#789)
- fb56b16 Add user agent to osv.dev calls. (guacsec#808)
- a51c634 Add vulnerability CLI to query if package is vulnerable (guacsec#696)
- f5bbd58 Add warning to readme to warn users of broken functionality (guacsec#561)
- 62ba43f Added Certify VEX statement schema and testing backend (guacsec#468)
- d18489f Added CertifyBad Schema and updated to use Union Type (guacsec#457)
- 5e47768 Added HasSLSA schema along with testing backend (guacsec#471)
- a349cd2 Added Ingest isOccurrence (guacsec#535)
- 21c586b Added IsVulnerability schema and backend testing (guacsec#467)
- 8b8b6be Added checks for isDependency and certifyPkg (guacsec#486)
- 37ff3a2 Added direct/indirect/unknown enum for IsDependency and update deps.dev collector/parser (guacsec#778)
- c208ac4 Added hasSourceAt schema and testing backend implementation (guacsec#456)
- 85fe624 Added ingest Vulnerability for both backends and cmd test data (guacsec#536)
- eeebb43 Allow filtering neighbors and paths on GUAC verbs (guacsec#681)
- 1ad4a4d Avoid stack overflow error for root_package (guacsec#404)
- 5c65ece Backend cleanup and rename (guacsec#630)
- 66e4d87 Bug#206: Parse and include dependencies of CDX format (guacsec#224)
- d58480e Bulldoze existing integration from ingestor to assembler to make way for graphQL (guacsec#507)
- a61422c Bump actions/checkout from 3.0.2 to 3.1.0 (guacsec#141)
- 1b93c03 Bump actions/checkout from 3.1.0 to 3.2.0 (guacsec#278)
- 1c646a2 Bump actions/checkout from 3.1.0 to 3.5.2 (guacsec#841)
- ba4a8a7 Bump actions/checkout from 3.2.0 to 3.3.0 (guacsec#308)
- f2c447f Bump actions/checkout from 3.3.0 to 3.4.0 (guacsec#615)
- edf648b Bump actions/checkout from 3.4.0 to 3.5.0 (guacsec#637)
- f6ffd4e Bump actions/checkout from 3.5.0 to 3.5.2 (guacsec#734)
- 06fec9c Bump actions/checkout from 3.5.2 to 3.5.3 (guacsec#951)
- 7efa858 Bump actions/setup-go from 3.2.1 to 3.3.0 (guacsec#87)
- 480c53e Bump actions/setup-go from 3.3.0 to 3.3.1 (guacsec#189)
- edf2b51 Bump actions/setup-go from 3.3.1 to 3.4.0 (guacsec#258)
- 90b9fb3 Bump actions/setup-go from 3.4.0 to 3.5.0 (guacsec#285)
- 72d3530 Bump actions/setup-go from 3.5.0 to 4.0.0 (guacsec#616)
- aea6430 Bump actions/setup-go from 4.0.0 to 4.0.1 (guacsec#840)
- f71b9ba Bump actions/setup-python from 4.4.0 to 4.5.0 (guacsec#702)
- f43729a Bump actions/setup-python from 4.5.0 to 4.6.0 (guacsec#773)
- bd619a7 Bump actions/setup-python from 4.6.0 to 4.6.1 (guacsec#890)
- e92f4ff Bump actions/setup-python from 4.6.1 to 4.7.0 (guacsec#1061)
- 73a14fe Bump actions/upload-artifact from 3.1.0 to 3.1.2 (guacsec#861)
- 4692cde Bump anchore/sbom-action from 0.14.2 to 0.14.3 (guacsec#981)
- 4bb77e7 Bump anchore/sbom-action from 0.7.0 to 0.14.2 (guacsec#933)
- f58d03b Bump aquasecurity/trivy-action from 0.10.0 to 0.11.0 (guacsec#912)
- 6fdf14c Bump aquasecurity/trivy-action from 0.10.0 to 0.11.2 (guacsec#952)
- df23960 Bump buildpacks/github-actions from 5.0.0 to 5.1.0 (guacsec#735)
- 4b79109 Bump buildpacks/github-actions from 5.1.0 to 5.2.0 (guacsec#843)
- 7b6b4c4 Bump cloud.google.com/go/storage from 1.26.0 to 1.27.0 (guacsec#120)
- 8982d47 Bump cloud.google.com/go/storage from 1.27.0 to 1.28.0 (guacsec#202)
- 7972e95 Bump cloud.google.com/go/storage from 1.28.0 to 1.28.1 (guacsec#259)
- 2965325 Bump cloud.google.com/go/storage from 1.28.1 to 1.29.0 (guacsec#346)
- 44f7a27 Bump cloud.google.com/go/storage from 1.29.0 to 1.30.0 (guacsec#611)
- 7bed608 Bump cloud.google.com/go/storage from 1.30.0 to 1.30.1 (guacsec#705)
- e1b0475 Bump cloud.google.com/go/storage from 1.30.1 to 1.31.0 (guacsec#1040)
- 92b5a2e Bump docker/login-action from 2.1.0 to 2.2.0 (guacsec#932)
- bfa131e Bump github.com/99designs/gqlgen from 0.17.22 to 0.17.24 (guacsec#368)
- 6757007 Bump github.com/99designs/gqlgen from 0.17.24 to 0.17.25 (guacsec#511)
- 85265c2 Bump github.com/99designs/gqlgen from 0.17.25 to 0.17.26 (guacsec#575)
- 11bd0eb Bump github.com/99designs/gqlgen from 0.17.26 to 0.17.27 (guacsec#618)
- dece78a Bump github.com/99designs/gqlgen from 0.17.28 to 0.17.30 (guacsec#805)
- 2629e6c Bump github.com/99designs/gqlgen from 0.17.32 to 0.17.33 (guacsec#953)
- 7c9bf1e Bump github.com/99designs/gqlgen from 0.17.33 to 0.17.34 (guacsec#984)
- 74cc02e Bump github.com/99designs/gqlgen from 0.17.34 to 0.17.35 (guacsec#1066)
- dcdcfd2 Bump github.com/CycloneDX/cyclonedx-go from 0.7.0 to 0.7.1 (guacsec#664)
- 23c716a Bump github.com/Khan/genqlient from 0.5.0 to 0.6.0 (guacsec#845)
- b100ecb Bump github.com/fsouza/fake-gcs-server from 1.39.0 to 1.40.1 (guacsec#91)
- 88d3555 Bump github.com/fsouza/fake-gcs-server from 1.40.1 to 1.40.2 (guacsec#121)
- 93ff80b Bump github.com/fsouza/fake-gcs-server from 1.40.2 to 1.40.3 (guacsec#196)
- 689cd3b Bump github.com/fsouza/fake-gcs-server from 1.40.3 to 1.42.0 (guacsec#203)
- f59f74f Bump github.com/fsouza/fake-gcs-server from 1.42.0 to 1.42.1 (guacsec#227)
- 0cb7121 Bump github.com/fsouza/fake-gcs-server from 1.42.1 to 1.42.2 (guacsec#252)
- b4e74fc Bump github.com/fsouza/fake-gcs-server from 1.42.2 to 1.43.0 (guacsec#290)
- 09bf389 Bump github.com/fsouza/fake-gcs-server from 1.43.0 to 1.44.0 (guacsec#317)
- ece1a40 Bump github.com/fsouza/fake-gcs-server from 1.44.0 to 1.44.1 (guacsec#641)
- f5b45ba Bump github.com/fsouza/fake-gcs-server from 1.44.1 to 1.44.2 (guacsec#704)
- 97816e0 Bump github.com/fsouza/fake-gcs-server from 1.44.2 to 1.45.1 (guacsec#844)
- 484051c Bump github.com/fsouza/fake-gcs-server from 1.45.1 to 1.45.2 (guacsec#938)
- 975a745 Bump github.com/go-git/go-git/v5 from 5.4.2 to 5.5.1 (guacsec#286)
- ebc4f19 Bump github.com/go-git/go-git/v5 from 5.5.1 to 5.5.2 (guacsec#301)
- d9d5734 Bump github.com/go-git/go-git/v5 from 5.5.2 to 5.6.0 (guacsec#509)
- 15d4189 Bump github.com/go-git/go-git/v5 from 5.6.0 to 5.6.1 (guacsec#613)
- 7a87726 Bump github.com/go-git/go-git/v5 from 5.6.1 to 5.7.0 (guacsec#893)
- 6fc7de1 Bump github.com/google/go-github/v50 from 50.1.0 to 50.2.0 (guacsec#614)
- a7dcf8e Bump github.com/google/osv-scanner (guacsec#540)
- 0e13915 Bump github.com/google/osv-scanner (guacsec#667)
- 7d69a5c Bump github.com/google/osv-scanner from 1.3.1 to 1.3.2 (guacsec#806)
- 8a37528 Bump github.com/google/osv-scanner from 1.3.3 to 1.3.4 (guacsec#936)
- bf5c0d9 Bump github.com/google/osv-scanner from 1.3.4 to 1.3.5 (guacsec#1064)
- fc490e0 Bump github.com/in-toto/in-toto-golang from 0.7.0 to 0.7.1 (guacsec#777)
- b0de22d Bump github.com/in-toto/in-toto-golang from 0.7.1 to 0.8.0 (guacsec#803)
- 2458aa7 Bump github.com/in-toto/in-toto-golang from 0.8.0 to 0.9.0 (guacsec#824)
- d79b515 Bump github.com/nats-io/nats-server/v2 from 2.9.10 to 2.9.11 (guacsec#309)
- f0781ba Bump github.com/nats-io/nats-server/v2 from 2.9.11 to 2.9.14 (guacsec#413)
- f377b5b Bump github.com/nats-io/nats-server/v2 from 2.9.14 to 2.9.15 (guacsec#541)
- 847ab2b Bump github.com/nats-io/nats-server/v2 from 2.9.15 to 2.9.16 (guacsec#736)
...
v0.1.1-jeff2
Changelog
- 9279015 Add CVE, GHSA and OSV tries GraphQL schema (guacsec#399)
- 13b9a49 Add Certifier cmd to guacone (guacsec#246)
- 649c204 Add Certify bad query and re-org the query CLI (guacsec#807)
- 035bf1f Add CertifyGood as a copy of CertifyBad (guacsec#652)
- f407e04 Add CertifyPkg schema with testing backend (guacsec#455)
- ad806a2 Add DSSE processor
- 3c59c1e Add Github Collector (guacsec#498)
- 3bc26e4 Add GraphQL documentation doc. (guacsec#785)
- ddabdf6 Add HasMetadata operations and inmem implementation (guacsec#1023)
- bf20b1a Add HasSBOM attestation with testing backend (guacsec#452)
- acad3d7 Add Hash equal schema for GraphQL (guacsec#442)
- 4c14629 Add ID and backedges for certifyPkg. (guacsec#628)
- df08235 Add IDs and back edges for certify vex and certify bad (guacsec#626)
- 5234d9b Add IsOccurrence to GraphQL Schema (guacsec#447)
- 354783c Add Luke to TAM (guacsec#271)
- 43f3e34 Add Neo4j Backend queries (guacsec#417)
- 6ab04cd Add NoKnownVuln node and related operations. (guacsec#673)
- f3e8991 Add Node query (guacsec#679)
- a7180a4 Add Nodes query needed for UI. (guacsec#812)
- 696557b Add POC to setup.md (guacsec#162)
- 08bfd91 Add PkgEqual and HashEqual predictaes -- testing + code planning (guacsec#1069)
- 37fde17 Add SETUP-new.md and supporting query and script files. (guacsec#662)
- e3add68 Add WhichVersionMatchesfunction implementation (guacsec#796)
- 2aeb88c Add
CONTRIBUTING.md
- 57d60ea Add a CI step to run current go tests.
- 794cf66 Add a CI workflow using neo4j.
- 663b076 Add a collectsub client type Datasource for collectors (guacsec#403)
- 9cc17ad Add ability to add ingestPredicates documents for ingestion (guacsec#1051)
- 09db2dc Add additional DSSE tests
- cf8ab73 Add artifact and builder graphQL schema (guacsec#400)
- 4936a26 Add back testing utils
- b93696d Add bot configurations (guacsec#85)
- cda3a6b Add collectsub service and OCI collector to all-in-one deployment (guacsec#430)
- 31cc947 Add compose tarball to release workflow.
- f4a1e53 Add contributor ladder process. (guacsec#750)
- 4cd1e8c Add deps.dev cmd implementation of collector subscriber (guacsec#660)
- 14be5a3 Add deps.dev collector, processor and parser (guacsec#654)
- debb811 Add developer documentation (guacsec#126)
- b0490b1 Add edges
- 58cfe73 Add end to end test (guacsec#685)
- 3d2f3da Add file collector (guacsec#79)
- 3b51228 Add graphql query examples (guacsec#473)
- fc6860d Add identity verifier interface
- 9a33cd4 Add ingestion for sources, on both backends (guacsec#481)
- 7b31843 Add ingestion mutation for SLSA (guacsec#553)
- b5db2c1 Add initial graphdb package
- 3587e04 Add initial nodes for arangoDB backend implementation (guacsec#911)
- b515708 Add instructions to start docker with apoc (guacsec#174)
- 02968d0 Add maintainers and governance
- af5516a Add markdown format check to ci (guacsec#686)
- 4fb814c Add more error checking for inmem backend. (guacsec#700)
- 3f9016b Add mutation to ingest artifacts (guacsec#485)
- caa8efd Add mutation to ingest builders (guacsec#491)
- 0917297 Add neighbors and path GraphQL queries. (guacsec#624)
- 70f291d Add nodes for attestations, artifacts and builders
- 2a96e7f Add package qualifiers to package trie and query spec (guacsec#394)
- 7eced3b Add package trie GraphQL schema (before qualifiers) (guacsec#391)
- 3885c0e Add packages to shell.nix (guacsec#1025)
- 7334096 Add processorInput structs
- b0659a8 Add query vulnerability CLI demo documentation (guacsec#742)
- 48acf14 Add reachability testdata (guacsec#609)
- d0fe467 Add resolvers based on selected fields (guacsec#422)
- 599889c Add scorecard guesser/processor (guacsec#127)
- 2050d84 Add scorecard parser integration (guacsec#521)
- d29cbb8 Add search gql (guacsec#998)
- 3d815f8 Add shell.nix
- 2b3ded4 Add simple SLSA identifier strings and provide integration with ingestor (guacsec#449)
- c3f4279 Add single happy path test for isOccurrence (guacsec#620)
- 7ce905f Add source trie GraphQL schema (guacsec#398)
- 290c1c3 Add support for ingesting VEX documents in the CSAF format (guacsec#729)
- f4eeb7b Add templates for issues and PRs (guacsec#789)
- fb56b16 Add user agent to osv.dev calls. (guacsec#808)
- a51c634 Add vulnerability CLI to query if package is vulnerable (guacsec#696)
- f5bbd58 Add warning to readme to warn users of broken functionality (guacsec#561)
- 62ba43f Added Certify VEX statement schema and testing backend (guacsec#468)
- d18489f Added CertifyBad Schema and updated to use Union Type (guacsec#457)
- 5e47768 Added HasSLSA schema along with testing backend (guacsec#471)
- a349cd2 Added Ingest isOccurrence (guacsec#535)
- 21c586b Added IsVulnerability schema and backend testing (guacsec#467)
- 8b8b6be Added checks for isDependency and certifyPkg (guacsec#486)
- 37ff3a2 Added direct/indirect/unknown enum for IsDependency and update deps.dev collector/parser (guacsec#778)
- c208ac4 Added hasSourceAt schema and testing backend implementation (guacsec#456)
- 85fe624 Added ingest Vulnerability for both backends and cmd test data (guacsec#536)
- eeebb43 Allow filtering neighbors and paths on GUAC verbs (guacsec#681)
- 1ad4a4d Avoid stack overflow error for root_package (guacsec#404)
- 5c65ece Backend cleanup and rename (guacsec#630)
- 66e4d87 Bug#206: Parse and include dependencies of CDX format (guacsec#224)
- d58480e Bulldoze existing integration from ingestor to assembler to make way for graphQL (guacsec#507)
- a61422c Bump actions/checkout from 3.0.2 to 3.1.0 (guacsec#141)
- 1b93c03 Bump actions/checkout from 3.1.0 to 3.2.0 (guacsec#278)
- 1c646a2 Bump actions/checkout from 3.1.0 to 3.5.2 (guacsec#841)
- ba4a8a7 Bump actions/checkout from 3.2.0 to 3.3.0 (guacsec#308)
- f2c447f Bump actions/checkout from 3.3.0 to 3.4.0 (guacsec#615)
- edf648b Bump actions/checkout from 3.4.0 to 3.5.0 (guacsec#637)
- f6ffd4e Bump actions/checkout from 3.5.0 to 3.5.2 (guacsec#734)
- 06fec9c Bump actions/checkout from 3.5.2 to 3.5.3 (guacsec#951)
- 7efa858 Bump actions/setup-go from 3.2.1 to 3.3.0 (guacsec#87)
- 480c53e Bump actions/setup-go from 3.3.0 to 3.3.1 (guacsec#189)
- edf2b51 Bump actions/setup-go from 3.3.1 to 3.4.0 (guacsec#258)
- 90b9fb3 Bump actions/setup-go from 3.4.0 to 3.5.0 (guacsec#285)
- 72d3530 Bump actions/setup-go from 3.5.0 to 4.0.0 (guacsec#616)
- aea6430 Bump actions/setup-go from 4.0.0 to 4.0.1 (guacsec#840)
- f71b9ba Bump actions/setup-python from 4.4.0 to 4.5.0 (guacsec#702)
- f43729a Bump actions/setup-python from 4.5.0 to 4.6.0 (guacsec#773)
- bd619a7 Bump actions/setup-python from 4.6.0 to 4.6.1 (guacsec#890)
- e92f4ff Bump actions/setup-python from 4.6.1 to 4.7.0 (guacsec#1061)
- 73a14fe Bump actions/upload-artifact from 3.1.0 to 3.1.2 (guacsec#861)
- 4692cde Bump anchore/sbom-action from 0.14.2 to 0.14.3 (guacsec#981)
- 4bb77e7 Bump anchore/sbom-action from 0.7.0 to 0.14.2 (guacsec#933)
- f58d03b Bump aquasecurity/trivy-action from 0.10.0 to 0.11.0 (guacsec#912)
- 6fdf14c Bump aquasecurity/trivy-action from 0.10.0 to 0.11.2 (guacsec#952)
- df23960 Bump buildpacks/github-actions from 5.0.0 to 5.1.0 (guacsec#735)
- 4b79109 Bump buildpacks/github-actions from 5.1.0 to 5.2.0 (guacsec#843)
- 7b6b4c4 Bump cloud.google.com/go/storage from 1.26.0 to 1.27.0 (guacsec#120)
- 8982d47 Bump cloud.google.com/go/storage from 1.27.0 to 1.28.0 (guacsec#202)
- 7972e95 Bump cloud.google.com/go/storage from 1.28.0 to 1.28.1 (guacsec#259)
- 2965325 Bump cloud.google.com/go/storage from 1.28.1 to 1.29.0 (guacsec#346)
- 44f7a27 Bump cloud.google.com/go/storage from 1.29.0 to 1.30.0 (guacsec#611)
- 7bed608 Bump cloud.google.com/go/storage from 1.30.0 to 1.30.1 (guacsec#705)
- e1b0475 Bump cloud.google.com/go/storage from 1.30.1 to 1.31.0 (guacsec#1040)
- 92b5a2e Bump docker/login-action from 2.1.0 to 2.2.0 (guacsec#932)
- bfa131e Bump github.com/99designs/gqlgen from 0.17.22 to 0.17.24 (guacsec#368)
- 6757007 Bump github.com/99designs/gqlgen from 0.17.24 to 0.17.25 (guacsec#511)
- 85265c2 Bump github.com/99designs/gqlgen from 0.17.25 to 0.17.26 (guacsec#575)
- 11bd0eb Bump github.com/99designs/gqlgen from 0.17.26 to 0.17.27 (guacsec#618)
- dece78a Bump github.com/99designs/gqlgen from 0.17.28 to 0.17.30 (guacsec#805)
- 2629e6c Bump github.com/99designs/gqlgen from 0.17.32 to 0.17.33 (guacsec#953)
- 7c9bf1e Bump github.com/99designs/gqlgen from 0.17.33 to 0.17.34 (guacsec#984)
- 74cc02e Bump github.com/99designs/gqlgen from 0.17.34 to 0.17.35 (guacsec#1066)
- dcdcfd2 Bump github.com/CycloneDX/cyclonedx-go from 0.7.0 to 0.7.1 (guacsec#664)
- 23c716a Bump github.com/Khan/genqlient from 0.5.0 to 0.6.0 (guacsec#845)
- b100ecb Bump github.com/fsouza/fake-gcs-server from 1.39.0 to 1.40.1 (guacsec#91)
- 88d3555 Bump github.com/fsouza/fake-gcs-server from 1.40.1 to 1.40.2 (guacsec#121)
- 93ff80b Bump github.com/fsouza/fake-gcs-server from 1.40.2 to 1.40.3 (guacsec#196)
- 689cd3b Bump github.com/fsouza/fake-gcs-server from 1.40.3 to 1.42.0 (guacsec#203)
- f59f74f Bump github.com/fsouza/fake-gcs-server from 1.42.0 to 1.42.1 (guacsec#227)
- 0cb7121 Bump github.com/fsouza/fake-gcs-server from 1.42.1 to 1.42.2 (guacsec#252)
- b4e74fc Bump github.com/fsouza/fake-gcs-server from 1.42.2 to 1.43.0 (guacsec#290)
- 09bf389 Bump github.com/fsouza/fake-gcs-server from 1.43.0 to 1.44.0 (guacsec#317)
- ece1a40 Bump github.com/fsouza/fake-gcs-server from 1.44.0 to 1.44.1 (guacsec#641)
- f5b45ba Bump github.com/fsouza/fake-gcs-server from 1.44.1 to 1.44.2 (guacsec#704)
- 97816e0 Bump github.com/fsouza/fake-gcs-server from 1.44.2 to 1.45.1 (guacsec#844)
- 484051c Bump github.com/fsouza/fake-gcs-server from 1.45.1 to 1.45.2 (guacsec#938)
- 975a745 Bump github.com/go-git/go-git/v5 from 5.4.2 to 5.5.1 (guacsec#286)
- ebc4f19 Bump github.com/go-git/go-git/v5 from 5.5.1 to 5.5.2 (guacsec#301)
- d9d5734 Bump github.com/go-git/go-git/v5 from 5.5.2 to 5.6.0 (guacsec#509)
- 15d4189 Bump github.com/go-git/go-git/v5 from 5.6.0 to 5.6.1 (guacsec#613)
- 7a87726 Bump github.com/go-git/go-git/v5 from 5.6.1 to 5.7.0 (guacsec#893)
- 6fc7de1 Bump github.com/google/go-github/v50 from 50.1.0 to 50.2.0 (guacsec#614)
- a7dcf8e Bump github.com/google/osv-scanner (guacsec#540)
- 0e13915 Bump github.com/google/osv-scanner (guacsec#667)
- 7d69a5c Bump github.com/google/osv-scanner from 1.3.1 to 1.3.2 (guacsec#806)
- 8a37528 Bump github.com/google/osv-scanner from 1.3.3 to 1.3.4 (guacsec#936)
- bf5c0d9 Bump github.com/google/osv-scanner from 1.3.4 to 1.3.5 (guacsec#1064)
- fc490e0 Bump github.com/in-toto/in-toto-golang from 0.7.0 to 0.7.1 (guacsec#777)
- b0de22d Bump github.com/in-toto/in-toto-golang from 0.7.1 to 0.8.0 (guacsec#803)
- 2458aa7 Bump github.com/in-toto/in-toto-golang from 0.8.0 to 0.9.0 (guacsec#824)
- d79b515 Bump github.com/nats-io/nats-server/v2 from 2.9.10 to 2.9.11 (guacsec#309)
- f0781ba Bump github.com/nats-io/nats-server/v2 from 2.9.11 to 2.9.14 (guacsec#413)
- f377b5b Bump github.com/nats-io/nats-server/v2 from 2.9.14 to 2.9.15 (guacsec#541)
- 847ab2b Bump github.com/nats-io/nats-server/v2 from 2.9.15 to 2.9.16 (guacsec#736)
...