Ecosyste.ms: OpenCollective

An open API service for software projects hosted on Open Collective.

github.com/devops-kung-fu/bomber

Scans Software Bill of Materials (SBOMs) for security vulnerabilities
https://github.com/devops-kung-fu/bomber

Fixes 0xProto Font in devcontainer (#206)

79b5dc75344e146541776b3ab80c2913b75115ec authored 11 months ago
Extended devcontainer functionality (#205)

* configuration of nerdfont in devcontainer

bd9d2b848c0d389a42e9211186ef0fed83ec411e authored 11 months ago
Adds devcontainer (#203)

Co-authored-by: DJ Schleen <[email protected]>

6a46058d4756f51590214986dffedcc47b52d058 authored 11 months ago
Delete .github/workflows/codeql.yml (#202)

Signed-off-by: DJ Schleen <[email protected]>

3e05144b9dcd1b2069f231f4c7f39c5e271b8b58 authored 11 months ago
Delete .github/workflows/code-analysis.yaml (#201)

Signed-off-by: DJ Schleen <[email protected]>

817ffb646beca04701faa15c39b9bf4ec3711b28 authored 11 months ago
Create codeql.yml (#200)

Signed-off-by: DJ Schleen <[email protected]>

0c606ffa2d8afb27f52d49f2bb3e62fb5e2065b3 authored 11 months ago
Update go-quality.yml (#199)

Signed-off-by: DJ Schleen <[email protected]>

249f16f8668f2c51ab55714e5ac2e8cee7dd85bf authored 11 months ago
Update go-quality.yml (#198)

Signed-off-by: DJ Schleen <[email protected]>

dfaf0f15f9a5a60c80ca3d50ec0208886fa768ba authored 11 months ago
Toolchain patch (#197)

7438ff58f73e5fada999ae0e37401c6b89727fdf authored 11 months ago
OpenAI integration and Bug Fixes (#196)

* Initial commit of AI rendering scaffold
* Fixes test cases and ignore loading functionality
...

870ab0d09b55907a23517dd109a8b8654214a8c9 authored 11 months ago
build(deps): bump actions/checkout from 3 to 4 in /.github/workflows (#190)

Bumps [actions/checkout](https://github.com/actions/checkout) from 3 to 4.
- [Release notes](ht...

56a61bf9aff08bbc269bb6575a26580b5aff5b59 authored 11 months ago
build(deps): bump actions/setup-go from 4 to 5 in /.github/workflows (#191)

Bumps [actions/setup-go](https://github.com/actions/setup-go) from 4 to 5.
- [Release notes](ht...

9d72ecdcb4537b46c9f1ee04f0908b9877869fa3 authored 11 months ago
build(deps): bump github/codeql-action from 2 to 3 in /.github/workflows (#195)

Bumps [github/codeql-action](https://github.com/github/codeql-action) from 2 to 3.
- [Release n...

430a8cf0ac64db0d7bd7857ff489a9cbb9f546f0 authored 11 months ago
build(deps): bump github.com/jedib0t/go-pretty/v6 from 6.4.9 to 6.5.4 (#192)

Bumps [github.com/jedib0t/go-pretty/v6](https://github.com/jedib0t/go-pretty) from 6.4.9 to 6.5....

8c44fb063c7c70fd4143536e7c1851b202305e2b authored 11 months ago
Create code-analysis.yaml (#194)

Signed-off-by: DJ Schleen <[email protected]>

cb9f644e4e256374b674705a18fddbcd5a5e98e0 authored 11 months ago
Fix broken link to test folder (#184)

Signed-off-by: Pablo Hinojosa <[email protected]>

259c8b3c71da55a04bbe31e8eb39420d646d663b authored about 1 year ago
Refactoring, optimizations, and bug fixes (#183)

* Refactored logic out of scan.go into a scanner
* Reduced cyclomatic complexity
* More test c...

831aa1c2fa5269bf25c0523edb338b20fe01558e authored about 1 year ago
Exitcode fix, Filtering fixes (#181)

* Fixes an issue where return code was 10 if no severity flag was set
* Adds exit code function...

6493ced4a333c7756b8476aee24a836528a25c69 authored about 1 year ago
Documentation and Version Bump (#177)

Version bump

0d0b5615c3f1c3ece88702772a7b827c95822b74 authored about 1 year ago
Exit code handling (#165)

* Updates dependencies
* Flags added, return codes on os.Exit
* Filtering done implemented
* ...

ae65a3d1dec745834b86970e5ca0cadadd841e20 authored over 1 year ago
feat: Error handling (#158)

* Fitering of bad purls
* Adds issue output for invalid Purls detected in SBOMS
* Simplifies j...

ce7c346bb2582b764ba37eeafdb8c70fd1c7a6d4 authored almost 2 years ago
Update Snyk docs (#157)

This adds newly supported purl types apk, deb, docker and rpm to the documentation for the Snyk ...

e8477955bdb6015bacdb8a6ea831374f2b91972c authored almost 2 years ago
Misc. Fixes (#153)

* Sets CGO_ENABLED=0
* Corrects xml output label to json
* More demo sboms

---------

Co-...

c67aa58455551b0ad693066572779074bba87309 authored almost 2 years ago
build(deps): bump actions/setup-go from 3 to 4 in /.github/workflows (#149)

Bumps [actions/setup-go](https://github.com/actions/setup-go) from 3 to 4.
- [Release notes](ht...

3fb690628dfc631d4085ee0c838334a67e9acb67 authored almost 2 years ago
Emergency fix to release.yml

3a1e17344ed67324438210d8d2ef895fae6645fb authored almost 2 years ago
Release v0.4.2

315e647bec9f463f3a4854732f3dce8cf5ffc642 authored almost 2 years ago
Update release.yml (#143)

Goreleaser not working, removed deprecated --rm-dist in favor of --clean

312dc361c857bb00089caac54615d69c90af3a79 authored almost 2 years ago
Release v0.4.2

75cc9d1102d70bfcae3780e6222ca73b3fe741c6 authored almost 2 years ago
Update release.yml (#142)

Updates goreleaser to 4.2.0

808b70b2040f259ddd36df21e31984b1f18a68ce authored almost 2 years ago
Version bump and update release to go 1.20 (#141)

df459ace6caeea0f00b8e86915c9f36907f89d93 authored almost 2 years ago
Bug Fixes (#138)

* Doesn't process components without purls (or empty purl nodes)
* Syft action in release.yml f...

579b39b61438d698cc10ec959877b0a743930d34 authored almost 2 years ago
Version bump (#131)

5c7e7dd1653f2290fe23133ac8d63494e8cd8ae3 authored almost 2 years ago
Adds --ignore-file functionality (#126)

64ab76a1613a3d14f44443b8a5b4da8376976d55 authored almost 2 years ago
chore: update snyk readme to include more ecosystems support (#124)

chore: update snyk readme to include mor ecosystems support

fcea0a1b2ab81478735e2d3b83818cbacf44ef33 authored almost 2 years ago
Create FUNDING.yml (#118)

Adds sponsor link

7e83fd21f25cdb4e5d45940a3299e1edeb6cac00 authored about 2 years ago
Added missing logo asset (#117)

44323cccd75527397103201bdc3ef238527fae4a authored about 2 years ago
Updated with new branding (#116)

82dc67e2f0069d9deb06b0bde3aa896ec6a8116e authored about 2 years ago
Updated README.md (#115)

df79c72d2317944fa9eedcce843927a596e70be7 authored about 2 years ago
New Bomber logo (#113)

2a2695b481122eaf6c9e90773c9886c171428100 authored about 2 years ago
fix: Fixes issue where a license expression wasn't being utilized (#108)

* Fixes issue where a license expression wasn't being utilized

* Improves test coverage

1a421ad919879a1fb902bfb00089d9d89285f91c authored about 2 years ago
fix: EPSS Score Issues (#104)

* EPSS enrichment feeds off Vulnerability.Cve
* Adds Cve field to osv vulnerability output
* F...

9ee85bb8344641ea6cd1282ec632393a6d1687be authored about 2 years ago
build(deps): bump goreleaser/goreleaser-action from 3 to 4 in /.github/workflows (#103)

build(deps): bump goreleaser/goreleaser-action in /.github/workflows

Bumps [goreleaser/gorele...

c8a0f6be4280fab120bee2586858361460586c0e authored about 2 years ago
build(deps): bump github.com/jedib0t/go-pretty/v6 from 6.4.2 to 6.4.3 (#96)

Bumps [github.com/jedib0t/go-pretty/v6](https://github.com/jedib0t/go-pretty) from 6.4.2 to 6.4....

ef3d15f973057753d738e912c7b0aa37fa9db59a authored about 2 years ago
build(deps): bump github.com/stretchr/testify from 1.8.0 to 1.8.1 (#74)

Bumps [github.com/stretchr/testify](https://github.com/stretchr/testify) from 1.8.0 to 1.8.1.
-...

a10d9db5aa94791c5d7e08ac6f7e95919153814b authored about 2 years ago
build(deps): bump actions/setup-go from 2 to 3 in /.github/workflows (#93)

Bumps [actions/setup-go](https://github.com/actions/setup-go) from 2 to 3.
- [Release notes](ht...

fc401c856ac93fba348b8edfee19ee07ea95d38e authored about 2 years ago
feat: add Snyk provider docs (#99)

* Adds Snyk provider documentation

d1c36c6bbdd07a6842ba61cc06a83440ca5b7df9 authored about 2 years ago
feat: EPSS support (#89)

* Updated documentation for EPSS
* STDOUT now renders EPSS percentage
* Centralization of enri...

474731186b958028fb7877f0e31b522013ac2a84 authored about 2 years ago
updated release links to Bomber (#87)

The links to the download locations are leading to hookz project releases and not Bomber.

ed7b8f0670e4b7d34d93deafa6b256292f28a7dd authored about 2 years ago
hotfix: release.yml

86ed119b63f1b69608243d22a8792eb84229d603 authored about 2 years ago
feat: Adds files section and hashes to bomber output (#85)

* Adds section in JSON for scanned files with sha256 hash
* Adds file section with names and ha...

da582a034edb639c0be937ca8d9c93bc81b1c818 authored about 2 years ago
feat: Pass package URL and ecosystem when querying OSV (#77)

Pass package URL when querying OSV

Co-authored-by: DJ Schleen <[email protected]>

ec11bf6c49bba28830f3867f91594cf7cc39bdd9 authored about 2 years ago
fix: Delete extra characters from HTML template (#78)

Deletes extra characters from HTML template

f1306a54a9fa0e3ea47f93b0f76a95d046fdd3a5 authored about 2 years ago
fix: Complexity fix for STDIN changes (#75)

Complexity fix for STDIN changes

459a9c3723eb3af6970599be41f79f315e591af1 authored over 2 years ago
feat: read SBOMs from stdin (#73)

Explicit rather than implicit. Use "-" as an argument to scan to trigger
reading from stdin.

1f7f249d0de7ad036fea7ddf75aaf2827473e3f1 authored over 2 years ago
feat: Renders and sanitizes Markdown vuln descriptions to HTML (#72)

* Renders and sanitizes Markdown vuln descriptions to HTML

* Adds error check for res close i...

7e1a7239c18dcc7795c436541ef8d9c4db471832 authored over 2 years ago
feat: add Snyk provider (#69)

Co-authored-by: Maximilian Combüchen <[email protected]>
Co-authored-by: Gareth Rushgrove <...

f280640538c29be7842268bcc9cc824c45680ae5 authored over 2 years ago
fix: licenseDeclared is not slice (#63)

bd5178f299956e6eaf7ad8581469581def05f404 authored over 2 years ago
Delete test.json (#65)

Test file clutter

697f08b9b381d12017b6d99bb74916db53f17af0 authored over 2 years ago
feat: License support (#58)

* License support for STDOUT

* Adds Licenses to html renderer, fixes rendering when no vulns ...

d58403ddf6851bec5742daca5c8fbfcecc951a0d authored over 2 years ago
feat: Adds xml format support for CycloneDX (#53)

* Adds xml format support for CycloneDX
* Version bump

19aa8ec38f352167b66a04d9834f8a553d9b1733 authored over 2 years ago
feat: Version check (#51)

8be71528b9b892de334c66369f13213b8cc33cce authored over 2 years ago
feat: HTML output support (#48)

* Initial html output

* Fixes strange severity issues, colors severity output in html, update...

d9898cd3d00b7ab67c3b1658b79671b9945e39a4 authored over 2 years ago
feat: Renderers (#47)

* Refactored rendering logic out of cmd

* Fixes issue where SPDX wasn't being recognized

*...

93dd74fdc6de980667b07f11050f027e1b1f8636 authored over 2 years ago
feat: Removed removeDuplicates in favor of DKFM common (#44)

* Removed removeDuplicates in favor of DKFM common

b32963ea1f18d65f095370143a5e64d633ac825b authored over 2 years ago
feat: Provider factory and http request cleanup (#43)

* Provider factory
* http request cleanup
* Removes README.md reference to bomber being a modu...

1e127f8d58b72e8289df0473b90d1bcb479d69c7 authored over 2 years ago
fix: Fixes strange merge problems (#39)

Fixes strange merge problems

3cfed2bddd10e3b102b276ceb1508c0a82616e6f authored over 2 years ago
fix: README.md (#38)

* Initial output of JSON
* Fixes OSV output not showing
* Omits empty fields in json output
*...

1a4cf970e0da97ec42bb97acaed9b836eb8c1e1d authored over 2 years ago
feat: Adds json formatted ouput (#33)

* JSON output using --output
* Fixes OSV output not showing
* Omits empty fields in json outpu...

31f5e4fb28c73723fd3f123a170ec7236f2a6fdf authored over 2 years ago
fix: Fixes severity to use Moderate instead of Medium (#31)

Fixes severity to use Moderate instead of Medium

275a85efda8c2a9f1494be8d7a87228bffd5c45c authored over 2 years ago
feat: Adds ecosystem pre-scan info, severity summary (#30)

Adds ecosystem pre-scan info

92636f920a69e8482d8be1192968e886560f71ce authored over 2 years ago
fix: Fixes updated README.md (#28)

Fixes updated README.md

697ad6dae951825b777564c174f3dc020cae6f24 authored over 2 years ago
fix: Fixes release typo from hookz to bomber (#27)

Fixes release typo from hookz to bomber

537b4e988d98abed10dc510f2eb079a440e30a7b authored over 2 years ago
feat: Enhanced Output and Multiple vulnerability providers (#26)

* Extracting common interface, stub out OSV provider
* Initial Snyk providers
* Implemented OS...

3c9f44d2e702db7fde550c3a5f605dc4af0f01e2 authored over 2 years ago
feat: Stabilization and vulnerability display (#17)

* Adds vulnerability struct for OSSIndex vuln details
* Adds debug and enhanced summary output
...

bd674552f2cd659ef79924bc7dd8df20c4de6fab authored over 2 years ago
fix: Warns on missing credentials, fixes output when no valid SBOMs are found (#13)

Warns on missing credentials, fixes output when no valid SBOMs are found

a4c228ea261be1680c505673729140076cb7b629 authored over 2 years ago
fix: Fixes bomber's sbom badge links (#4)

Fixes bomber's sbom badge links

c6b6cddefb3cafbb90b80dba350d97e77d913933 authored over 2 years ago
fix: Update README.md (#3)

Update README.md

Fixes codecov badge

d512cb911d1e4ca594f38c4bdb95715737c50d6e authored over 2 years ago
feat: Initial version of bomber (#2)

* Adding cli
* Tabular output
* Working functionality for scanning against OSSIndex
* Impleme...

524ad5e85ce73dda09488bdd0fd9e7ff2a3d2831 authored over 2 years ago
feat: Initial repository structure and code scaffold (#1)

* Initial repository structure and structs
* Adds github release workflow
* Stubs out tests
*...

38efadc61411d23349706ac291abc6910b8a0c52 authored over 2 years ago
Initial commit

a60511eb042017fb13cd96ada7cd647751200f35 authored over 2 years ago