Skip to content

🌱 Bump github.com/google/osv-scanner/v2 from 2.3.2 to 2.6.0 - #5264

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/google/osv-scanner/v2-2.6.0
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/github.com/google/osv-scanner/v2-2.6.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Oct 1, 2026 •

Copy link
Copy Markdown
Contributor

Bumps github.com/google/osv-scanner/v2 from 2.3.2 to 2.6.0.

Release notes

Sourced from github.com/google/osv-scanner/v2's releases.

v2.6.0

Features:

  • [Feature #2888](google/osv-scanner#2888) Publish multi-arch (linux/arm64) image for osv-scanner-action.
  • [Feature #3066](google/osv-scanner#3066) Configure retry policy with exponential backoff for transient gRPC errors in scalibr plugins.
  • Dependency scanning & lockfile improvements via osv-scalibr:
    • Extract Git repository URLs and support local OSV tag matching for Git-based dependencies in JavaScript lockfiles (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock).
    • Assign pkg:git PURL type to Git commit-pinned dependencies across JS and Cargo lockfiles to avoid false positives against registry packages (#2863).
    • Retain packages without a version or PURL in SPDX output (google/osv-scalibr#2375) and merge related packages based on lineage relationships.
  • New extractors and plugin support via osv-scalibr:
    • Many additional filetypes are supported. These are not enabled by default yet, so if you need a particular new filetype, use --experimental-plugins flag. See "Supported Inventory Types" for the extractor name.

Fixes:

  • [Bug #3075](google/osv-scanner#3075) Ensure results property in JSON output is an empty array [] instead of null when scanning with --allow-no-lockfiles and no lockfiles are found.
  • [Bug #3071](google/osv-scanner#3071) Preserve valid UTF-8 sequences when truncating multibyte text in vertical output.
  • [Bug #2919](google/osv-scanner#2919) Add filter to show packages with license violations but no vulnerabilities in the HTML report.
  • [Bug #3049](google/osv-scanner#3049) Keep filter dropdown checklist open when clicking options in the HTML report.
  • [Bug #3023](google/osv-scanner#3023) Guard against panic on empty or whitespace-only license expressions in SPDX license evaluation.
  • [Bug #3032](google/osv-scanner#3032) Bound recursion depth when parsing SPDX license expressions to prevent stack overflow on deeply nested expressions.
  • [Bug #3061](google/osv-scanner#3061) Remove purl caching in scan filtering to avoid dropping SBOM packages without purls.
  • [Bug #3063](google/osv-scanner#3063) Log plugin and enricher errors during container scans instead of failing silently.
  • [Bug #2977](google/osv-scanner#2977) Return an error instead of aborting the process (log.Fatalf) when an rlib archive has no object file during Rust source analysis.
  • [Bug #3083](google/osv-scanner#3083) Return a descriptive error from DoContainerScan when ScannerActions.Image is empty instead of panicking.
  • Fixes via osv-scalibr:
    • Fix false-positive Go standard library matches for packages with module paths ending in /go (e.g. pkg:golang/github.com/json-iterator/go) (#3017).
    • Secure guided remediation file operations with os.Root to prevent path traversal attacks (google/osv-scalibr#2363).
    • Prevent OOM and disk exhaustion issues with tar bombs during archive extraction.
    • Strip platform suffix from RubyGems versions in CycloneDX (google/osv-scalibr#2313).
    • Ignore .deps.json files that don't have an object as their root in dotnet/depsjson extractor (google/osv-scalibr#2423).

Misc:

  • Update osv-scalibr to v0.5.3-0.20260911142458-3090dbb7aaa2 (#3079).
  • Update Go to v1.27 and golangci-lint to v2.13 (#3046).
    • This now supports call analysis on go v1.27 projects.
  • Update google.golang.org/grpc to v1.83.2 (#3062).

New Contributors

... (truncated)

Changelog

Sourced from github.com/google/osv-scanner/v2's changelog.

v2.6.0

Features:

  • [Feature #2888](google/osv-scanner#2888) Publish multi-arch (linux/arm64) image for osv-scanner-action.
  • [Feature #3066](google/osv-scanner#3066) Configure retry policy with exponential backoff for transient gRPC errors in scalibr plugins.
  • Dependency scanning & lockfile improvements via osv-scalibr:
    • Extract Git repository URLs and support local OSV tag matching for Git-based dependencies in JavaScript lockfiles (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lock).
    • Assign pkg:git PURL type to Git commit-pinned dependencies across JS and Cargo lockfiles to avoid false positives against registry packages (#2863).
    • Retain packages without a version or PURL in SPDX output (google/osv-scalibr#2375) and merge related packages based on lineage relationships.
  • New extractors and plugin support via osv-scalibr:
    • Many additional filetypes are supported. These are not enabled by default yet, so if you need a particular new filetype, use --experimental-plugins flag. See "Supported Inventory Types" for the extractor name.

Fixes:

  • [Bug #3075](google/osv-scanner#3075) Ensure results property in JSON output is an empty array [] instead of null when scanning with --allow-no-lockfiles and no lockfiles are found.
  • [Bug #3071](google/osv-scanner#3071) Preserve valid UTF-8 sequences when truncating multibyte text in vertical output.
  • [Bug #2919](google/osv-scanner#2919) Add filter to show packages with license violations but no vulnerabilities in the HTML report.
  • [Bug #3049](google/osv-scanner#3049) Keep filter dropdown checklist open when clicking options in the HTML report.
  • [Bug #3023](google/osv-scanner#3023) Guard against panic on empty or whitespace-only license expressions in SPDX license evaluation.
  • [Bug #3032](google/osv-scanner#3032) Bound recursion depth when parsing SPDX license expressions to prevent stack overflow on deeply nested expressions.
  • [Bug #3061](google/osv-scanner#3061) Remove purl caching in scan filtering to avoid dropping SBOM packages without purls.
  • [Bug #3063](google/osv-scanner#3063) Log plugin and enricher errors during container scans instead of failing silently.
  • [Bug #2977](google/osv-scanner#2977) Return an error instead of aborting the process (log.Fatalf) when an rlib archive has no object file during Rust source analysis.
  • [Bug #3083](google/osv-scanner#3083) Return a descriptive error from DoContainerScan when ScannerActions.Image is empty instead of panicking.
  • Fixes via osv-scalibr:
    • Fix false-positive Go standard library matches for packages with module paths ending in /go (e.g. pkg:golang/github.com/json-iterator/go) (#3017).
    • Secure guided remediation file operations with os.Root to prevent path traversal attacks (google/osv-scalibr#2363).
    • Prevent OOM and disk exhaustion issues with tar bombs during archive extraction.
    • Strip platform suffix from RubyGems versions in CycloneDX (google/osv-scalibr#2313).
    • Ignore .deps.json files that don't have an object as their root in dotnet/depsjson extractor (google/osv-scalibr#2423).

Misc:

  • Update osv-scalibr to v0.5.3-0.20260911142458-3090dbb7aaa2 (#3079).
  • Update Go to v1.27 and golangci-lint to v2.13 (#3046).
    • This now supports call analysis on go v1.27 projects.
  • Update google.golang.org/grpc to v1.83.2 (#3062).

v2.5.1

Fixes:

  • Preserve package namespaces when querying osv.dev API (fixes #2978).
  • Re-add support for the OSV_SCANNER_LOCAL_DB_CACHE_DIRECTORY environment variable (fixes #2983).
  • Fix local vulnerability matching (--offline-vulnerabilities) not working when network capability is NetworkOnline.

v2.5.0

Features & Refactors:

... (truncated)

Commits
  • e840a6e chore: Release osv-scanner v2.6.0 (#3076)
  • 566148c fix: return error when container image is missing (#3083)
  • a0c76dd feat: update osv-scalibr (#3079)
  • 1f87b5c feat: update osv-scalibr (#3078)
  • 93d3cad fix(output): preserve UTF-8 when truncating text (#3071)
  • ca08313 feat: update osv-scalibr (#3074)
  • 7efabb9 build(goreleaser): publish multi-arch (arm64) osv-scanner-action image (#2888)
  • ca51965 fix: ensure results property is an array in json output when there are no l...
  • 260ff08 refactor: remove unused internal/depsdev package (#3069)
  • b397661 fix(sourceanalysis): return an error instead of exiting when an rlib has no o...
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Oct 1, 2026
@dependabot
dependabot Bot requested a review from a team as a code owner October 1, 2026 03:48
@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Oct 1, 2026
@dependabot
dependabot Bot had a problem deploying to integration-test October 1, 2026 03:48 Failure
Bumps [github.com/google/osv-scanner/v2](https://github.com/google/osv-scanner) from 2.3.2 to 2.6.0.
- [Release notes](https://github.com/google/osv-scanner/releases)
- [Changelog](https://github.com/google/osv-scanner/blob/main/CHANGELOG.md)
- [Commits](google/osv-scanner@v2.3.2...v2.6.0)

---
updated-dependencies:
- dependency-name: github.com/google/osv-scanner/v2
  dependency-version: 2.6.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/github.com/google/osv-scanner/v2-2.6.0 branch from 4b37a85 to 4bf01d2 Compare October 2, 2026 08:25
@dependabot
dependabot Bot had a problem deploying to integration-test October 2, 2026 08:25 Failure

This branch had an error being deployed

2 failed deployments
gitlab — 4bf01d22 Deployed Oct 2, 2026 by dependabot[bot] via gitlab-integration-trusted #5335
integration-test — 4bf01d22 Deployed Oct 2, 2026 by dependabot[bot] via integration-trusted #12686
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

Status: No status

Development

Successfully merging this pull request may close these issues.

0 participants