Skip to content

Releases: CycloneDX/cdxgen

Release v11.0.7

12 Dec 20:01
a47c1d8
Compare
Choose a tag to compare

What's Changed

  • Force package lock creation for stubborn projects with .npmrc by @prabhu in #1488

Full Changelog: v11.0.6...v11.0.7

Release v11.0.6

09 Dec 17:10
2c9113b
Compare
Choose a tag to compare

What's Changed

Full Changelog: v11.0.5...v11.0.6

Release v11.0.5 - hey quarkus

05 Dec 13:47
250d9ce
Compare
Choose a tag to compare

cdxgen now supports the Quarkus framework with automatic detection for Maven projects—no configuration changes needed. It uses the official dependency-sbom goal but adds extra value by including phantom JARs that aren’t managed through Maven. With the research profile enabled (--profile research), cdxgen produces a highly detailed SBOM with occurrences and call stack evidence, offering better insights than the official implementation, which only tracks jar files.

cdxgenGPT is also updated to better understand the evidence information for decent reasoning performance.

2024-12-05_15-25-57

What's Changed

Other Changes

  • feat: quarkus maven support by @prabhu in #1480
  • Improve printOccurrences function with streaming output for large SBO… by @deeshantk in #1482

New Contributors

Full Changelog: v11.0.4...v11.0.5

Release v11.0.4

03 Dec 14:09
36791cf
Compare
Choose a tag to compare

What's Changed

Other Changes

New Contributors

Full Changelog: v11.0.3...v11.0.4

Release v11.0.3

21 Nov 11:12
5cfb69f
Compare
Choose a tag to compare

What's Changed

Other Changes

Full Changelog: v11.0.2...v11.0.3

Release v11.0.2

18 Nov 14:28
aebea7b
Compare
Choose a tag to compare

What's Changed

🚀 Features

Other Changes

  • update atom to get cpg 1.0.1 and the latest protobuf by @prabhu in #1462
  • Safely handle components without names by @prabhu in #1464
  • Update atom to get tagging and android apk improvements by @prabhu in #1465

Full Changelog: v11.0.1...v11.0.2

Release v11.0.1

17 Nov 06:55
a07301b
Compare
Choose a tag to compare

Notable Features

  • Official cdxgen base image updated to almalinux:10-kitten-minimal. dotnet 9 sdk is now used as default.
  • All base images updated to use :v11 as the suffix. Due to a release mistake the last few cdxgen :v10 images inadvertently use cdxgen v11.0.0. Let us know if you are affected by this mistake.
  • Latest dosai with support for dotnet 9 via [email protected].

What's Changed

Other Changes

Full Changelog: v11.0.0...v11.0.1

Release v11.0.0

15 Nov 15:18
ce64722
Compare
Choose a tag to compare

Announcement blog on LinkedIn

Top Features

  • New ML profiles (ml-tiny, ml, ml-deep) added. Pass them via the cli args --profile.
  • New filter techniques (--min-confidence and --technique)

BREAKING changes

cyclonedx-maven-plugin is no longer used by default. PREFER_MAVEN_DEPS_TREE now defaults to true. Set this value to false should you prefer the cyclonedx maven plugin.

What's Changed

🚀 Features

Other Changes

Full Changelog: v10.11.0...v11.0.0

Release v10.11.0 - Happy swiftwali

31 Oct 14:21
cb40883
Compare
Choose a tag to compare

Swift developers deserve better tooling to make their lives simple. Accurate information about where and how a given library (both internal and external) is used, can help with prioritization and vulnerability management.

This release adds a new state-of-the-art semantic analysis engine for swift 😎. cdxgen can generate a precise semantic slice representing the application context with accurate types and fully qualified call names for a range of swift applications. The slices are then utlilized by evinse to generate "occurrences evidence" for the SBOM as shown.

2024-10-30_22-12-16

We can't wait to iterate to bring you more enhancements and visibility over the coming weeks.

What's Changed

🚀 Features

Other Changes

  • Use bom-ref consistently in the dependency tree by @prabhu in #1431
  • Run "Upload base images" action only on main repository by @marob in #1436
  • Run some GitHub action jobs only on main repository by @marob in #1438
  • Graciously fail for fastlane managed swift projects by @prabhu in #1443

Full Changelog: v10.10.7...v10.11.0

v10.10.7

22 Oct 11:55
b309cff
Compare
Choose a tag to compare

What's Changed

🚀 Features

  • Adds support for specifying npm install args by @prabhu in #1428

Full Changelog: v10.10.6...v10.10.7