Skip to content

Releases: CycloneDX/cdxgen

Release v11.0.0

15 Nov 15:18
ce64722
Compare
Choose a tag to compare

Announcement blog on LinkedIn

Top Features

  • New ML profiles (ml-tiny, ml, ml-deep) added. Pass them via the cli args --profile.
  • New filter techniques (--min-confidence and --technique)

BREAKING changes

cyclonedx-maven-plugin is no longer used by default. PREFER_MAVEN_DEPS_TREE now defaults to true. Set this value to false should you prefer the cyclonedx maven plugin.

What's Changed

🚀 Features

Other Changes

Full Changelog: v10.11.0...v11.0.0

Release v10.11.0 - Happy swiftwali

31 Oct 14:21
cb40883
Compare
Choose a tag to compare

Swift developers deserve better tooling to make their lives simple. Accurate information about where and how a given library (both internal and external) is used, can help with prioritization and vulnerability management.

This release adds a new state-of-the-art semantic analysis engine for swift 😎. cdxgen can generate a precise semantic slice representing the application context with accurate types and fully qualified call names for a range of swift applications. The slices are then utlilized by evinse to generate "occurrences evidence" for the SBOM as shown.

2024-10-30_22-12-16

We can't wait to iterate to bring you more enhancements and visibility over the coming weeks.

What's Changed

🚀 Features

Other Changes

  • Use bom-ref consistently in the dependency tree by @prabhu in #1431
  • Run "Upload base images" action only on main repository by @marob in #1436
  • Run some GitHub action jobs only on main repository by @marob in #1438
  • Graciously fail for fastlane managed swift projects by @prabhu in #1443

Full Changelog: v10.10.7...v10.11.0

v10.10.7

22 Oct 11:55
b309cff
Compare
Choose a tag to compare

What's Changed

🚀 Features

  • Adds support for specifying npm install args by @prabhu in #1428

Full Changelog: v10.10.6...v10.10.7

Release v10.10.6

20 Oct 21:19
5b39562
Compare
Choose a tag to compare

What's Changed

Other Changes

Full Changelog: v10.10.5...v10.10.6

Release v10.10.5

17 Oct 10:08
160b735
Compare
Choose a tag to compare

What's Changed

Other Changes

Full Changelog: v10.10.4...v10.10.5

Release v10.10.4

08 Oct 18:06
f546437
Compare
Choose a tag to compare

What's Changed

Other Changes

  • Improve root dependency list for Gemfile.lock by @prabhu in #1409

Full Changelog: v10.10.3...v10.10.4

Release v10.10.3

03 Oct 10:52
49d8e6a
Compare
Choose a tag to compare

We are now publishing new language-specific custom base images (contributed by AppThreat). We have seen significant improvements for Python and .Net framework applications in the field with these images. They are also lightweight compared to the default cdxgen image.

What's Changed

🚀 Features

Other Changes

Full Changelog: v10.10.2...v10.10.3

Release v10.10.2

01 Oct 08:14
6aa3175
Compare
Choose a tag to compare

What's Changed

Other Changes

  • search only for Bazel workspace and module files by @maur1 in #1394
  • feat: Ignore parent component for types with empty components by @prabhu in #1399

Full Changelog: v10.10.1...v10.10.2

Release v10.10.1

24 Sep 14:20
6aac1f3
Compare
Choose a tag to compare

Windows sae builds are back 😎

What's Changed

Other Changes

Full Changelog: v10.10.0...v10.10.1

Release v10.10.0

22 Sep 22:32
23fbc41
Compare
Choose a tag to compare

Gradle multi-threading mode is now the default 😎. Enjoy the turbo-charged performance contributed with ❤️ by @malice00. Also includes the new atom, which is a bit more leaner and performant ⚡️. Last, but not least, the repo is refactored to help with maintenance and testing (Thanks @aryan-rajoria and @setchy!)

What's Changed

Other Changes

  • [Gradle] Don't use full multi-threading, SBOMs can be completely wrong by @malice00 in #1376
  • Do not create empty component.components by @prabhu in #1378
  • [Gradle] Fixed a problem with scoped NPM packages while resolving modules from NPM by @malice00 in #1379
  • Handling sub-components of the root component the same as all other components by @malice00 in #1371
  • [Gradle] Added deep-scanning of gradle modules by @malice00 in #1380
  • refactor: project structure PR by @aryan-rajoria in #1382
  • Typescript 5.6.x with the latest atom by @prabhu in #1384
  • Feat: Include components from pnpm-lock.yaml importers by @aryan-rajoria in #1377
  • Poetry root list from pyproject.toml by @prabhu in #1386
  • [Gradle] Scanning of all modules fixed by @malice00 in #1383
  • Update atom and other packages by @prabhu in #1387

Full Changelog: v10.9.11...v10.10.0