Skip to content

build(deps): bump github.com/anchore/syft from 1.38.0 to 1.43.0#1957

Closed
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/go_modules/github.com/anchore/syft-1.43.0
Closed

build(deps): bump github.com/anchore/syft from 1.38.0 to 1.43.0#1957
dependabot[bot] wants to merge 1 commit intomainfrom
dependabot/go_modules/github.com/anchore/syft-1.43.0

Conversation

@dependabot
Copy link
Copy Markdown
Contributor

@dependabot dependabot Bot commented on behalf of github Apr 22, 2026

Bumps github.com/anchore/syft from 1.38.0 to 1.43.0.

Release notes

Sourced from github.com/anchore/syft's releases.

v1.43.0

Added Features

Bug Fixes

Additional Changes

(Full Changelog)

v1.42.4

Bug Fixes

Additional Changes

(Full Changelog)

v1.42.3

Bug Fixes

  • Missing secondary evidence for .NET dependency in ghcr.io/open-telemetry/demo:2.0.0-accounting image [#4652]

Additional Changes

... (truncated)

Commits
  • 390cf6c chore(deps): update anchore dependencies (#4797)
  • 4393654 Chore fix sync bump (#4809)
  • d179724 fix: improve redhat-release parsing fallback for RHEL clones (#4808)
  • 2ddaaac restore go minimum version to 1.25.8 (#4805)
  • 073b4c5 chore(deps): restore Go version to 1.25.8 (#4804)
  • ff6c34d fix: improve haskell classifiers (#4793)
  • 66ba575 chore(deps): bump the actions-minor-patch group across 1 directory with 2 upd...
  • ed306c2 chore(deps): bump github.com/go-git/go-git/v5 from 5.17.0 to 5.18.0 (#4792)
  • 33bc4b8 chore(deps): update Go version (#4798)
  • 89e4e60 fix: update jruby download URLs from S3 to GitHub Releases (#4799)
  • Additional commits viewable in compare view

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file go Pull requests that update Go code labels Apr 22, 2026
Bumps [github.com/anchore/syft](https://github.com/anchore/syft) from 1.38.0 to 1.43.0.
- [Release notes](https://github.com/anchore/syft/releases)
- [Changelog](https://github.com/anchore/syft/blob/main/RELEASE.md)
- [Commits](anchore/syft@v1.38.0...v1.43.0)

---
updated-dependencies:
- dependency-name: github.com/anchore/syft
  dependency-version: 1.43.0
  dependency-type: direct:production
  update-type: version-update:semver-minor
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot dependabot Bot force-pushed the dependabot/go_modules/github.com/anchore/syft-1.43.0 branch from 3c72b5b to 62bc79c Compare April 28, 2026 21:58
@dependabot @github
Copy link
Copy Markdown
Contributor Author

dependabot Bot commented on behalf of github May 1, 2026

Superseded by #1966.

@dependabot dependabot Bot closed this May 1, 2026
@dependabot dependabot Bot deleted the dependabot/go_modules/github.com/anchore/syft-1.43.0 branch May 1, 2026 19:38
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file go Pull requests that update Go code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants