All notable changes to this project will be documented in this file.
The format is based on Keep a Changelog, and this project adheres to Semantic Versioning.
- Enhanced the VEX report to retrieve annotated vulnerability analysis data for inventory, including all suppressed vulnerabilities.
- Enhanced VEX report to retrieve annotated vulnerability analysis data.
- Update common submodule to prep for tomcat upgrade in 2023R4
- Using common 3.6.8 env/requirements
- Use common module for API and branding etc
- Resove issue with SPDX license mapping
- Improved logging
- unicode cleanup for description
- Validated with cyclonedx-cli v 0.24.2
- Handle failure in purl creation gracefully (custom components will probably be skipped)
- Standardized registration logic
- Added support for VRD and VEX options vs just auto creating
- Updates for validation passing
- common requirements venv for all reports
- Support for project level custom fields
- Add purls
- Add license url
- Initial internal release of CycloneDX Report