Skip to content

build(deps): bump github.com/anchore/syft from 1.51.0 to 1.51.1 in the syft group across 1 directory - #336

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/syft-449f413f23
Open

dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/go_modules/syft-449f413f23

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 31, 2026

Copy link
Copy Markdown
Contributor

Bumps the syft group with 1 update in the / directory: github.com/anchore/syft.

Updates github.com/anchore/syft from 1.51.0 to 1.51.1

Release notes

Sourced from github.com/anchore/syft's releases.

v1.51.1

Bug Fixes

Additional Changes

  • gzip binary classifier reports false-positive GNU gzip from BusyBox multicall binary via applet symlink [Issue #5171] [PR #5202 @​spiffcs]
  • pnpm v5 lockfile: underscore peer-dep suffixes are not stripped from package versions [Issue #5174] [PR #5175 @​codeAnqiang-ma]
  • pnpm cataloger reads only the first YAML document: SBOM contains pnpm's own binaries and no project dependencies [Issue #5168] [PR #5188 @​hamodywe]

Dependencies

72 dependency changes (70 updated, 1 added, 1 removed). 3 vulnerabilities remediated.

🟢 Remediated (3)

  • cel.dev/expr v0.25.1v0.25.2
  • cloud.google.com/go/auth v0.18.2v0.22.0
  • cloud.google.com/go/iam v1.5.3v1.11.0
  • cloud.google.com/go/logging v1.13.1v1.18.0
  • cloud.google.com/go/longrunning v0.8.0v1.2.0
  • cloud.google.com/go/monitoring v1.24.3v1.29.0
  • cloud.google.com/go/storage v1.61.3v1.64.0
  • cloud.google.com/go/trace v1.11.7v1.16.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/detectors/gcp v1.32.0v1.33.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/exporter/metric v0.55.0v0.57.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/cloudmock v0.55.0v0.57.0
  • github.com/GoogleCloudPlatform/opentelemetry-operations-go/internal/resourcemapping v0.55.0v0.57.0
  • github.com/anchore/stereoscope v0.3.0v0.3.1

... (truncated)

Commits
  • 91a0032 chore(deps): update anchore dependencies (#5085)
  • f91bf45 fix: correct Apache Derby group ID in purl generation (#5090)
  • c5fc699 chore(deps): update CPE dictionary index (#5221)
  • d3734dd fix(binary): detect grafana security-patch release versions (#5213)
  • bf82010 fix(lua): skip rockspec with no package name (#4825)
  • 7ca1f22 fix(dotnet): correct inverted dependency-of relationship direction in package...
  • 93cf893 fix(rpm): keep the epoch when parsing RPM manifest packages (#5201)
  • 34ef7dc chore(deps): bump golang.org/x/mod from 0.39.0 to 0.40.0 (#5208)
  • 29edf90 chore(deps): bump github.com/hashicorp/go-getter from 1.8.6 to 1.8.8 (#5207)
  • 766907e chore(deps): bump github.com/stretchr/testify from 1.11.1 to 1.12.0 (#5206)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update go code labels Aug 31, 2026
@dependabot dependabot Bot changed the title Bump github.com/anchore/syft from 1.51.0 to 1.51.1 in the syft group Bump github.com/anchore/syft from 1.51.0 to 1.51.1 in the syft group across 1 directory Sep 7, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/syft-449f413f23 branch 3 times, most recently from ef2e65e to cbb445b Compare September 10, 2026 17:53
@dependabot dependabot Bot changed the title Bump github.com/anchore/syft from 1.51.0 to 1.51.1 in the syft group across 1 directory build(deps): bump github.com/anchore/syft from 1.51.0 to 1.51.1 in the syft group across 1 directory Sep 14, 2026
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/syft-449f413f23 branch from cbb445b to 1a2127e Compare September 14, 2026 17:53
Bumps the syft group with 1 update in the / directory: [github.com/anchore/syft](https://github.com/anchore/syft).


Updates `github.com/anchore/syft` from 1.51.0 to 1.51.1
- [Release notes](https://github.com/anchore/syft/releases)
- [Changelog](https://github.com/anchore/syft/blob/main/RELEASE.md)
- [Commits](anchore/syft@v1.51.0...v1.51.1)

---
updated-dependencies:
- dependency-name: github.com/anchore/syft
  dependency-version: 1.51.1
  dependency-type: direct:production
  update-type: version-update:semver-patch
  dependency-group: syft
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/go_modules/syft-449f413f23 branch from 1a2127e to b6b1136 Compare September 15, 2026 17:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants