Skip to content

chore(deps): update dependency google/osv-scanner to v2.6.0 - #30

Open
renovate[bot] wants to merge 1 commit into
masterfrom
renovate/google-osv-scanner-2.x
Open

renovate[bot] wants to merge 1 commit into
masterfrom
renovate/google-osv-scanner-2.x

Conversation

@renovate

@renovate renovate Bot commented Sep 29, 2026

Copy link
Copy Markdown

This PR contains the following updates:

Package Update Change
google/osv-scanner minor v2.5.1 → v2.6.0

Release Notes

google/osv-scanner (google/osv-scanner)

v2.6.0

Compare Source

Features:
  • Feature #​2888 Publish multi-arch (linux/arm64) image for osv-scanner-action.
  • Feature #​3066 Configure retry policy with exponential backoff for transient gRPC errors in scalibr plugins.
  • Dependency scanning & lockfile improvements via osv-scalibr:
    • Extract Git repository URLs and support local OSV tag matching for Git-based dependencies in JavaScript lockfiles (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock).
    • Assign pkg:git PURL type to Git commit-pinned dependencies across JS and Cargo lockfiles to avoid false positives against registry packages (#​2863).
    • Retain packages without a version or PURL in SPDX output (google/osv-scalibr#2375) and merge related packages based on lineage relationships.
  • New extractors and plugin support via osv-scalibr:
    • Many additional filetypes are supported. These are not enabled by default yet, so if you need a particular new filetype, use --experimental-plugins flag. See "Supported Inventory Types" for the extractor name.
Fixes:
  • Bug #​3075 Ensure results property in JSON output is an empty array [] instead of null when scanning with --allow-no-lockfiles and no lockfiles are found.
  • Bug #​3071 Preserve valid UTF-8 sequences when truncating multibyte text in vertical output.
  • Bug #​2919 Add filter to show packages with license violations but no vulnerabilities in the HTML report.
  • Bug #​3049 Keep filter dropdown checklist open when clicking options in the HTML report.
  • Bug #​3023 Guard against panic on empty or whitespace-only license expressions in SPDX license evaluation.
  • Bug #​3032 Bound recursion depth when parsing SPDX license expressions to prevent stack overflow on deeply nested expressions.
  • Bug #​3061 Remove purl caching in scan filtering to avoid dropping SBOM packages without purls.
  • Bug #​3063 Log plugin and enricher errors during container scans instead of failing silently.
  • Bug #​2977 Return an error instead of aborting the process (log.Fatalf) when an rlib archive has no object file during Rust source analysis.
  • Bug #​3083 Return a descriptive error from DoContainerScan when ScannerActions.Image is empty instead of panicking.
  • Fixes via osv-scalibr:
    • Fix false-positive Go standard library matches for packages with module paths ending in /go (e.g. pkg:golang/github.com/json-iterator/go) (#​3017).
    • Secure guided remediation file operations with os.Root to prevent path traversal attacks (google/osv-scalibr#2363).
    • Prevent OOM and disk exhaustion issues with tar bombs during archive extraction.
    • Strip platform suffix from RubyGems versions in CycloneDX (google/osv-scalibr#2313).
    • Ignore .deps.json files that don't have an object as their root in dotnet/depsjson extractor (google/osv-scalibr#2423).
Misc:
  • Update osv-scalibr to v0.5.3-0.20260911142458-3090dbb7aaa2 (#​3079).
  • Update Go to v1.27 and golangci-lint to v2.13 (#​3046).
    • This now supports call analysis on go v1.27 projects.
  • Update google.golang.org/grpc to v1.83.2 (#​3062).

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

@renovate renovate Bot added the dependencies Pull requests that update a dependency file label Sep 29, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants