Skip to content

chore(deps): update dependency osv-scanner to v2.3.8#720

Open
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/osv-scanner-2.x
Open

chore(deps): update dependency osv-scanner to v2.3.8#720
renovate[bot] wants to merge 1 commit into
mainfrom
renovate/osv-scanner-2.x

Conversation

@renovate
Copy link
Copy Markdown
Contributor

@renovate renovate Bot commented Apr 29, 2026

This PR contains the following updates:

Package Update Change
osv-scanner patch 2.3.32.3.8

Release Notes

google/osv-scanner (osv-scanner)

v2.3.8

Compare Source

Fixes:
  • Fix installation issues with go install due to dependency conflicts (downgrade containerd/cgroups/v3, moby/buildkit and opencontainers/runtime-spec).
  • Bug #​2762 Skip packages with short commit hashes instead of aborting scan.
  • Bug #​2781 Secure file path handling with os.OpenRoot.
  • Bug #​2766 Correct typos across docs, configs, and Go source.
Misc:
  • Update osv-scalibr to v0.4.6-0.20260504042738-9293bfa4f86f.
  • Remove replace directive (#​2782).
  • Update contributing.md (#​2779).

v2.3.7

Compare Source

Fixes:
  • Fix installation issues with go install due to dependency conflicts (downgrade containerd/cgroups/v3, moby/buildkit and opencontainers/runtime-spec).
  • Bug #​2762 Skip packages with short commit hashes instead of aborting scan.
  • Bug #​2781 Secure file path handling with os.OpenRoot.
  • Bug #​2766 Correct typos across docs, configs, and Go source.
Misc:
  • Update osv-scalibr to v0.4.6-0.20260504042738-9293bfa4f86f.
  • Remove replace directive (#​2782).
  • Update contributing.md (#​2779).

v2.3.6

Compare Source

Features:
Fixes:
  • Bug #​2750 Sanitize \r/\n in default/table/vertical output to prevent GitHub Actions workflow command injection.
  • Bug #​2641 Correctly output packages from osv-scanner.json source in spdx format.
  • Bug #​2729 Increase color contrast of vulnerability stats.
  • Bug #​2664 Remove second newline at end of vertical output.
  • Bug #​2669 Sanitize \r in gh-annotations to prevent GitHub Actions workflow command injection.
Misc:
  • Update osv-scalibr to v0.4.6-0.20260428235529-7791e288d6c1.
  • Update Go version to 1.26.2 (#​2706).

v2.3.5

Compare Source

Misc:
  • Fix broken release workflow.

v2.3.4

Compare Source

[!NOTE] This release was abandoned, due to issues with the release workflow.

Features:
  • Feature #​2571 Enable transitive scanning for Python requirements.txt files using the deps.dev API.
  • Feature #​2649 Add ability to allow unsafe plugins, logging a warning when any unsafe plugin is enabled.
Fixes:
  • Bug #​2630 Improve startup performance on Windows Terminal by updating lipgloss.
  • Bug #​2599 Ensure the package deprecation enricher respects the same configuration as other plugins.
  • Bug #​2600 Ensure the Java extractor plugin for call analysis respects the same configuration as other plugins.
Misc:

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot changed the title chore(deps): update dependency osv-scanner to v2.3.5 chore(deps): update dependency osv-scanner to v2.3.6 May 1, 2026
@renovate renovate Bot force-pushed the renovate/osv-scanner-2.x branch 2 times, most recently from 0449860 to 608fc52 Compare May 7, 2026 05:29
@renovate renovate Bot changed the title chore(deps): update dependency osv-scanner to v2.3.6 chore(deps): update dependency osv-scanner to v2.3.7 May 7, 2026
@renovate renovate Bot force-pushed the renovate/osv-scanner-2.x branch from 608fc52 to 3d9c253 Compare May 8, 2026 05:58
@renovate renovate Bot changed the title chore(deps): update dependency osv-scanner to v2.3.7 chore(deps): update dependency osv-scanner to v2.3.8 May 8, 2026
@renovate renovate Bot force-pushed the renovate/osv-scanner-2.x branch from 3d9c253 to 7d0f910 Compare May 14, 2026 16:41
@renovate renovate Bot force-pushed the renovate/osv-scanner-2.x branch from 7d0f910 to 0b2d08c Compare May 22, 2026 19:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants