Skip to content

Releases: sonatype/actions

Release 1.10.0

10 Apr 19:35

Choose a tag to compare

  • Added support for API-based CI configuration
  • Added support for Sonatype Container Scanner
  • Added support for zstd-compressed Docker image layers
  • Fixed an issue with memory handling during container scanning

Release 1.9.3

09 Mar 17:32

Choose a tag to compare

  • Fixed an issue where the SARIF file was deleted too early, preventing successful upload

Release 1.9.2

06 Mar 15:36

Choose a tag to compare

  • Temporary workspace files are now cleaned up earlier during the pipeline run

Release 1.9.1

10 Feb 20:00

Choose a tag to compare

  • Added basic authentication support for the iq-cli-download-url parameter

Release 1.9.0

23 Dec 18:12

Choose a tag to compare

  • Added support for JavaScript reachability analysis

Release 1.8.2

05 Dec 17:42

Choose a tag to compare

  • Fixed an edge case where scans failed for npm projects

Release 1.8.1

04 Dec 18:24

Choose a tag to compare

  • Maintenance release

Release 1.8.0

25 Nov 18:27

Choose a tag to compare

  • Implemented security controls for the iq-cli-download-url parameter in the setup-iq-cli action

Release 1.7.0

07 Nov 19:50

Choose a tag to compare

  • Added support for npm workspaces
  • Improved scan performance for pnpm-lock.yaml files

Release 1.6.2

09 Oct 19:06

Choose a tag to compare

  • Added Priorities Report URL to Build Summary
  • Added support for Docker Client v28 in Docker Image Analysis
  • Added support for scanning pnpm-lock.yaml v9 manifest files