Skip to content

Releases: CycloneDX/cdxgen

Release v11.2.0 - Think, Evaluate, and Improve

28 Feb 15:16
205ad38
Compare
Choose a tag to compare

Thanks to continuous thought logging and GPT-powered evaluation, we have fixed several bugs to enhance precision and improve the user experience.

What's Changed

  • [Documentation] Split the table in ENV.md by language/tool and sorted the keys. by @malice00 in #1649
  • Convert to relative paths using postgen + goodies by @prabhu in #1652
  • Auto-detect gradle composite builds by @prabhu in #1658
  • npm workspace improvements by @prabhu in #1659
  • [swift] Parent hierarchy and properties improvements by @prabhu in #1664

Full Changelog: v11.1.10...v11.2.0

Release v11.1.10

22 Feb 15:38
1807d97
Compare
Choose a tag to compare

What's Changed

Other Changes

  • result.stderr could be null in node.js even with non-zero error code by @prabhu in #1641
  • Fix pnpm and yarn lock file detection by @konstantinas1 in #1643

New Contributors

Full Changelog: v11.1.9...v11.1.10

Release v11.1.9

18 Feb 20:50
450d3bc
Compare
Choose a tag to compare

cdxgen can now log its thought process while generating the xBOM. cdxgenGPT can then interpret this log and advise whether the generated SBOM is accurate and complete. Below is an example for the Kafka repository:

Screenshot 2025-02-15 at 17 37 21
Screenshot 2025-02-15 at 17 38 10

bom.json
cdxgen-thoughts.txt

What's Changed

Other Changes

New Contributors

Full Changelog: v11.1.8...v11.1.9

Release v11.1.8

14 Feb 18:28
87084e1
Compare
Choose a tag to compare

What's Changed

🐛 Bug Fixes

Other Changes

Full Changelog: v11.1.7...v11.1.8

Release v11.1.7

01 Feb 17:11
b704676
Compare
Choose a tag to compare

cdxgen (>= v11.1.7) now includes a "secure mode," powered by the Node.js permission model. This "seat-belt approach" allows you to control which system resources cdxgen can access and what actions it can perform with those resources. For example, in --lifecycle pre-build mode, you can restrict cdxgen to reading only specific files, without granting permission to execute child processes. Even when executing node-based commands such as npm or atom, you can further limit the directories these external commands can read and write, as well as their permissions to execute child processes. This makes cdxgen an ideal SBOM tool when dealing with untrusted codebases (which is all software).

For further information, please refer to the permissions documentation or start using the new ghcr.io/cyclonedx/cdxgen-secure container image.

Thank you to @eran-medan and the other security researchers for helping bring this feature live.

Addresses CVE-2024-50611 and #1328. Please update at your convenience.

Full Changelog: v11.1.6...v11.1.7

Release v11.1.6

31 Jan 10:23
7fb050a
Compare
Choose a tag to compare
  • Reduce validation warnings. Fix for #1610
  • golang is included in a few Python images

What's Changed

Other Changes

Full Changelog: v11.1.5...v11.1.6

Release v11.1.5

29 Jan 23:19
6e066ee
Compare
Choose a tag to compare

What's Changed

🧪 Testing

Other Changes

Full Changelog: v11.1.4...v11.1.5

Release v11.1.4

28 Jan 22:12
ffc6796
Compare
Choose a tag to compare

What's Changed

🧪 Testing

  • Restrict -t java11 to linux only in repotests by @prabhu in #1604

Other Changes

  • Handle pnpm workspace with duplicate names by @prabhu in #1603

Full Changelog: v11.1.3...v11.1.4

Release v11.1.3

28 Jan 11:39
0bc0e6f
Compare
Choose a tag to compare

Fixes a bug where automatic installations were no longer performed.

What's Changed

Other Changes

  • fix: install setuptools and wheel before installing requirements by @AnsahMohammad in #1594
  • Ensuring that the evidence.identity format is maintained after components are trimmed by @emcfins in #1591
  • Fix version parsing in CMakeLists files by @asztalosdani in #1596
  • cdxgen secure image - WIP by @prabhu in #1600

New Contributors

Full Changelog: v11.1.2...v11.1.3

Release v11.1.2

22 Jan 18:36
cd77efa
Compare
Choose a tag to compare

What's Changed

Other Changes

  • Adds is_workspace properties to uv parent components by @prabhu in #1590

Full Changelog: v11.1.1...v11.1.2