Skip to content

Releases: fabric8-analytics/fabric8-analytics-vscode-extension

v0.9.5

30 Jul 13:09
Compare
Choose a tag to compare

Changelog

  • enhancement - Added support for vulnerability analysis for Gradle build manifests.
  • enhancement - Added support for vulnerability analysis on images in Dockerfiles.
  • enhancement - Added new settings for the Python and Go ecosystems.
  • enhancement - Added support for private GitHub Registries.
  • fixes - Fixed an issue by removing a redundant / at the beginning of Windows URI paths that was causing some mvn commands to fail. See PR#692 for details.
  • fixes - Fixed an issue with the Stack Analysis running on an open file, instead of running on an opened manifest file. See PR#692 for details.
  • known issue - You can get an error by using the Use Pip Dep Tree and Use Python Virtual Environment options simultaneously. See the Known Issues section of the README for more information.
  • known issue - Red Hat Dependency Analytics has limitations for Maven and Gradle. See the Known Issues section of the README for more information.
  • informational - Added a telemetry event to track Red Hat's recommended version acceptance.

What's Changed

Full Changelog: v0.9.4...v0.9.5

v0.9.4

25 Mar 09:56
ca4be57
Compare
Choose a tag to compare

Changelog

  • informational - Removing access to Snyk's Vulnerability Database.

What's Changed

Full Changelog: v0.9.3...v0.9.4

v0.9.3

06 Mar 13:45
Compare
Choose a tag to compare

Changelog

  • enhancement - Red Hat Dependency Analytics reporting has integrated the ONGuard service by using Open Source Vulnerability (OSV) and the National Vulnerability Database (NVD) data sources for additional vulnerability information.
  • enhancement - Integrated VS Code's Secret Storage feature for securing the Snyk token. See PR689 for details.
  • fixes - Fixed an issue with displaying wrong data when the event handler for Component Analysis was triggered on a unsaved manifest file. Component Analysis is no longer triggered on unsaved manifest files. See PR#239 for details.
  • fixes - Fixed an issue where the diagnostic source name is being obscured in the View Problem panel from an inline analysis. See PR#239 for details.
  • informational - The naming convention for VS Code commands has changed from fabric8 to rhda. For example, fabric8.stackAnalysis is now rhda.stackAnalysis.

What's Changed

Full Changelog: v0.9.2...v0.9.3

v0.9.2

05 Feb 15:22
Compare
Choose a tag to compare

What's Changed

  • informational - The redHatDependencyAnalyticsReportFilePath setting name has changed to reportFilePath. If you had a custom file path set for redHatDependencyAnalyticsReportFilePath, then you need to add your custom file path to the reportFilePath setting.
  • enhancement - Added a vulnerability severity alert level setting for the user to receive inline notifications for just errors or warnings. See PR#674 for details.
  • fixes - Fixed an issue with the codeActionsMap call. When multiple manifest documents are open that have the same dependency, one of the document entries gets deleted. This gave a wrong result in the analysis. See PR#236 for details.
  • fixes - Fixed an issue in the Exhort Javascript API. This fix enables and supports analysis of pom.xml manifests that include local modules, and a parent Project Object Model (POM). See the PR#237 for details.
  • fixes - Fixed an issue with the analysis report not displaying because of spaces in the manifest file path. See PR#100 for details.

Full Changelog: v0.9.1...v0.9.2

v0.9.1

24 Dec 09:16
Compare
Choose a tag to compare

What's Changed

Full Changelog: v0.9.0...v0.9.1

v0.9.0

21 Dec 08:56
Compare
Choose a tag to compare

What's Changed

  • refactor: code structure supporting single source exhort payload to multi source by @IlonaShishov in PR#661
  • informational - Service Preview release of Red Hat Dependency Analytics (RHDA) extension.
  • informational - Configuration names for all supported executable paths in the extension settings have changed. These executable paths are only used for the analysis.
  • enhancement - Added support for error observation by using Sentry.
  • enhancement - Support for more complex SPDX SBOM relationships.
  • enhancement - Added recommendations and remediations in the Quick Fix... tab.
  • fixes - Fixed an issue where unique Snyk vulnerability information was not being displayed in the Dependency Analytics report. See PR#217 for details.
  • fixes - Better valid and invalid token alert messages for the Snyk vulnerability information provider. See PR#218 for details.
  • fixes - Fixed analysis report discrepancies between Red Hat Dependency Analytics and Snyk’s analytics. See PR#219 for details.
  • fixes - Fixed the Go and Python package links so they point to their specific package manager website.

v0.7.5

20 Dec 13:36
Compare
Choose a tag to compare
v0.7.5 Pre-release
Pre-release

What's Changed

Full Changelog: v0.7.4...v0.7.5

v0.7.4

15 Nov 17:16
Compare
Choose a tag to compare
v0.7.4 Pre-release
Pre-release

What's Changed

New Contributors

Full Changelog: v0.7.3...v0.7.4

v0.7.3

08 Nov 09:05
Compare
Choose a tag to compare

What's Changed

Full Changelog: v0.7.2...v0.7.3

v0.7.2

05 Oct 12:21
Compare
Choose a tag to compare
v0.7.2 Pre-release
Pre-release

What's Changed

Full Changelog: v0.7.1...v0.7.2