Skip to content

osv-scanner 2.2.0#232624

Merged
BrewTestBot merged 2 commits into
mainfrom
bump-osv-scanner-2.2.0
Aug 7, 2025
Merged

osv-scanner 2.2.0#232624
BrewTestBot merged 2 commits into
mainfrom
bump-osv-scanner-2.2.0

Conversation

@BrewTestBot
Copy link
Copy Markdown
Contributor

Created by brew bump


Created with brew bump-formula-pr.

Details

release notes
# v2.2.0

OSV-Scanner now supports all OSV-Scalibr features behind experimental flags (--experimental-plugins, see details here)!

Features:

  • Feature #2146 Allow manual OSV-Scalibr plugin selection.
  • Feature #2144 Add OSV-Scalibr version to osv-scanner --version output.
  • Feature #2021 Add experimental support for running OSV-Scalibr detectors.
  • Feature #2079 Fall back to offline extractor if the transitive one fails, so at least direct dependencies are returned.
  • Feature #2032 Add summary section at the top of outputs and a 'Fixed Version' column.
  • Feature #2076 Support Ubuntu severity type.

Fixes:

  • Bug #2141 Fix OSV-Scanner json scans not matching with correct ecosystem.
  • Bug #2084 Show absolute paths when scanning containers.
  • Bug #2126 Log and preserve package count before continuing on db error.
  • Bug #2095 Pass through plugin capabilities correctly.
  • Bug #2051 Properly flag if running on Linux or Mac OSs for plugin compatibility.
  • Bug #2072 Add missing "text" property in description fields.
  • Bug #2068 Change links in output to go to the specific vulnerability page instead of the list page.
  • Bug #2064 Fix SARIF v3 output to include results.

API Changes:

New Contributors

Full Changelog: google/osv-scanner@v2.1.0...v2.2.0

View the full release notes at https://github.com/google/osv-scanner/releases/tag/v2.2.0.


@github-actions github-actions Bot added go Go use is a significant feature of the PR or issue bump-formula-pr PR was created using `brew bump-formula-pr` labels Aug 7, 2025
@github-actions
Copy link
Copy Markdown
Contributor

github-actions Bot commented Aug 7, 2025

🤖 An automated task has requested bottles to be published to this PR.

Caution

Please do not push to this PR branch before the bottle commits have been pushed, as this results in a state that is difficult to recover from. If you need to resolve a merge conflict, please use a merge commit. Do not force-push to this PR branch.

@github-actions github-actions Bot added the CI-published-bottle-commits The commits for the built bottles have been pushed to the PR branch. label Aug 7, 2025
@BrewTestBot BrewTestBot enabled auto-merge August 7, 2025 06:04
@BrewTestBot BrewTestBot added this pull request to the merge queue Aug 7, 2025
Merged via the queue into main with commit d3fbf41 Aug 7, 2025
22 checks passed
@BrewTestBot BrewTestBot deleted the bump-osv-scanner-2.2.0 branch August 7, 2025 06:13
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

bump-formula-pr PR was created using `brew bump-formula-pr` CI-published-bottle-commits The commits for the built bottles have been pushed to the PR branch. go Go use is a significant feature of the PR or issue

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants