This release adds 6 notable features for engineering teams evaluating rollout.
✓ No known CVEs patched in this version
Topics
+5 more
Summary
AI summaryBroad release touches Bug Fixes, Added Features, https://github.com/anchore/grype/pull/3509, and https://github.com/anchore/grype/pull/3542.
Changes in this release
| Type | Severity | Summary | CVE |
|---|---|---|---|
| Feature | Medium |
Duplicate RHSAs to all applicable RHEL minor versions. Duplicate RHSAs to all applicable RHEL minor versions. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Add Chainguard OSV transformer. Add Chainguard OSV transformer. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Populate package architecture for matching. Populate package architecture for matching. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Add lightweight reachability analysis to reduce Golang false positives. Add lightweight reachability analysis to reduce Golang false positives. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Deduplicate Go matches that are aliases of each other. Deduplicate Go matches that are aliases of each other. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Feature | Medium |
Support Ubuntu ESM. Support Ubuntu ESM. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Regenerate v6.1.8 blob and SQL schemas. Regenerate v6.1.8 blob and SQL schemas. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Fix RHEL version streams handling. Fix RHEL version streams handling. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Ensure Grype matches u-boot in SBOM when type is firmware. Ensure Grype matches u-boot in SBOM when type is firmware. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Medium |
Ignore Go compiler‑affecting CVE when Docker image only contains a binary compiled with Go. Ignore Go compiler‑affecting CVE when Docker image only contains a binary compiled with Go. Source: llm_adapter@2026-07-16 Confidence: high |
— |
| Bugfix | Low |
Emit warnings for consistently unreadable files (non‑SBOMs) during Zarf scans. Emit warnings for consistently unreadable files (non‑SBOMs) during Zarf scans. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Bugfix | Low |
Fail parsing GitHub Actions workflows correctly. Fail parsing GitHub Actions workflows correctly. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
| Bugfix | Low |
Prevent Go vulnerability reporting when installed version exceeds fixed version. Prevent Go vulnerability reporting when installed version exceeds fixed version. Source: granite4.1:30b@2026-07-16-audit Confidence: low |
— |
Full changelog
Added Features
- duplicate RHSAs to all applicable RHEL minor versions [PR #3542 @willmurphyscode]
- add chainguard osv transformer [PR #3474 @crosleyzack]
- populate package architecture for matching [PR #3504 @willmurphyscode]
- lightweight reachability analysis to reduce Golang false positives [Issue #2960] [PR #3509 @spiffcs]
- Deduplicate Go matches that are aliases of each other (same CVE reported under both a
govulndbGO-* ID and its GHSA) [Issue #3511] [PR #3509 @spiffcs] - Support Ubuntu ESM [Issue #3544] [PR #3546 @wagoodman]
Bug Fixes
- regenerate v6.1.8 blob and sql schemas [PR #3574 @spiffcs]
- rhel version streams [PR #3572 @kzantow]
- Grype doesn't match u-boot in SBOM if type is set to firmware [Issue #2537]
- Ignore Go compiler affecting CVE when Docker image only contains a binary compiled with Go [Issue #1782]
- Zarf scans emit warnings for consistently unreadable files (i.e., included non-SBOMs) [Issue #3516] [PR #3545 @brandtkeller]
- Fail parsing github actions [Issue #3220]
- Go vulnerability returned when installed version is greater than fixed version [Issue #3520]
Dependencies
14 dependency changes (11 updated, 3 added).
Updated (11 packages)- github.com/anchore/go-rpmdb
v0.1.0→v0.2.0 - github.com/anchore/syft
v1.46.0→v1.48.0 - github.com/klauspost/compress
v1.18.6→v1.19.0 - golang.org/x/text
v0.38.0→v0.39.0 - golang.org/x/tools
v0.46.0→v0.47.0 - gorm.io/gorm
v1.31.1→v1.31.2 - modernc.org/cc/v4
v4.28.2→v4.28.4 - modernc.org/ccgo/v4
v4.34.0→v4.34.4 - modernc.org/gc/v3
v3.1.2→v3.1.3 - modernc.org/libc
v1.72.3→v1.73.4 - modernc.org/sqlite
v1.51.0→v1.53.0
- github.com/mattn/go-sqlite3
v1.14.23 - gorm.io/driver/sqlite
v1.6.0 - howett.net/plist
v1.0.1
Weekly OSS security release digest.
The CVE patches and breaking changes that affected production tools this week. One email, every Sunday.
No spam, unsubscribe anytime.
Share this release
Related context
Beta — feedback welcome: [email protected]