Skip to content

Bump github.com/anchore/syft from 1.46.0 to 1.50.0 in the syft group across 1 directory - #321

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/syft-6dad0011f7
Open

Bump github.com/anchore/syft from 1.46.0 to 1.50.0 in the syft group across 1 directory#321
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/syft-6dad0011f7

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 4, 2026

Copy link
Copy Markdown
Contributor

Bumps the syft group with 1 update in the / directory: github.com/anchore/syft.

Updates github.com/anchore/syft from 1.46.0 to 1.50.0

Release notes

Sourced from github.com/anchore/syft's releases.

v1.50.0

Added Features

Bug Fixes

Additional Changes

  • package-lock.json v1: nested dependencies entries are never cataloged (flat top-level iteration only) [Issue #5101] [PR #5108 @​Eljees]
  • consider vendored golang packages in module attribution [PR #5093 @​kzantow]
  • Fix inverted bounds check dropping every Erlang string with a backslash [PR #5110 @​arpitjain099]

Dependencies

14 dependency changes (14 updated). 1 vulnerability remediated.

🟢 Remediated (1)

  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.31.0v1.32.0
  • github.com/cncf/xds/go v0.0.0-ee656c7v0.0.0-dba9d58
  • github.com/envoyproxy/go-control-plane/envoy v1.36.0v1.37.0
  • github.com/envoyproxy/protoc-gen-validate v1.3.0v1.3.3
  • github.com/gpustack/gguf-parser-go v0.24.1v0.25.0
  • go.opentelemetry.io/contrib/detectors/gcp v1.39.0v1.43.0
  • google.golang.org/genproto/googleapis/api v0.0.0-9d38bb4v0.0.0-afd174a
  • google.golang.org/genproto/googleapis/rpc v0.0.0-6f92a3bv0.0.0-afd174a
  • google.golang.org/grpc v1.80.0v1.82.1 (🟢 remediated GHSA-hrxh-6v49-42gf)
  • modernc.org/cc/v4 v4.28.4v4.29.0
  • modernc.org/ccgo/v4 v4.34.4v4.34.6
  • modernc.org/gc/v3 v3.1.3v3.1.4
  • modernc.org/libc v1.73.4v1.74.1
  • modernc.org/sqlite v1.53.0v1.54.0

(Full Changelog)

v1.49.0

Added Features

... (truncated)

Commits
  • 16223e6 fix: consider vendored golang packages in module attribution (#5093)
  • 1286689 Fix missing nested packages in package-lock.json v1 (#5108)
  • 2954549 fix: strip publisher URL from RPM CPE vendor (#5081)
  • 86baeeb fix(rust): omit Cargo PURLs for local packages (#5105)
  • 2dcf516 fix(apk): allow large installed db fields (#5100)
  • 12b8ba4 Fix inverted bounds check dropping every Erlang string with a backslash (#5110)
  • 138d9ce added bun binary classifier (#5103)
  • 8a229b1 chore(deps): update CPE dictionary index (#5109)
  • 9af0098 chore(deps): bump google.golang.org/grpc from 1.80.0 to 1.82.1 (#5099)
  • 2840ea6 chore(deps): bump modernc.org/sqlite from 1.53.0 to 1.54.0 (#5098)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Aug 4, 2026
Bumps the syft group with 1 update in the / directory: [github.com/anchore/syft](https://github.com/anchore/syft).


Updates `github.com/anchore/syft` from 1.46.0 to 1.50.0
- [Release notes](https://github.com/anchore/syft/releases)
- [Changelog](https://github.com/anchore/syft/blob/main/RELEASE.md)
- [Commits](anchore/syft@v1.46.0...v1.50.0)

---
updated-dependencies:
- dependency-name: github.com/anchore/syft
  dependency-version: 1.50.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
  dependency-group: syft
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot changed the title Bump github.com/anchore/syft from 1.46.0 to 1.50.0 in the syft group Bump github.com/anchore/syft from 1.46.0 to 1.50.0 in the syft group across 1 directory Aug 12, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/syft-6dad0011f7 branch from 42d2bb4 to 9dc73da Compare August 12, 2026 17:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants