Skip to content

Conversation

@bakito-renovate
Copy link
Contributor

This PR contains the following updates:

Package Update Change
github.com/anchore/syft/cmd/syft minor v1.37.0 -> v1.38.0

Release Notes

anchore/syft (github.com/anchore/syft/cmd/syft)

v1.38.0

Compare Source

Added Features
Bug Fixes
  • Support extras statements in Python PDM cataloger [#​4352 @​wagoodman]
  • Preserve --from argument order [#​4350 @​wagoodman]
  • SBOM generated by Syft 1.28 contains license elements missing id or name (causing CycloneDX parser error) [#​4363]
  • empty PURL output in dependency snapshot format breaks sbom-action [#​4311]
  • Interface includes constraint elements, can only be used in type parameters [#​4346]
  • Upgrade github.com/nwaples/rardecode@​v1.1.3 to 2.2.1 [#​4338]
  • Upgrade to Golang 1.25.4 [#​4341]
Additional Changes

(Full Changelog)


Configuration

📅 Schedule: Branch creation - At any time (no schedule defined), Automerge - At any time (no schedule defined).

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Renovate Bot.

@bakito-renovate bakito-renovate bot added the dependencies Pull requests that update a dependency file label Nov 24, 2025
@coveralls
Copy link

Pull Request Test Coverage Report for Build 19623042965

Details

  • 0 of 0 changed or added relevant lines in 0 files are covered.
  • No unchanged relevant lines lost coverage.
  • Overall coverage remained the same at 41.618%

Totals Coverage Status
Change from base Build 19527036283: 0.0%
Covered Lines: 571
Relevant Lines: 1372

💛 - Coveralls

@bakito bakito merged commit 2d88513 into main Nov 24, 2025
8 checks passed
@bakito-renovate bakito-renovate bot deleted the renovate/github.com-anchore-syft-cmd-syft-1.x branch November 24, 2025 06:19
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants