Skip to content

Releases: fossas/fossa-cli

v3.17.1

14 Apr 06:41
8234492

Choose a tag to compare

What's Changed

  • [ANE-2900] Omit unset fields from project edit request body by @nficca in #1688
  • [ANE-2655] Expose yarn and npm workspace packages as individual build targets by @jagonalez in #1643
  • [ANE-2901] UV: Add directory source type to uv.lock parser by @zlav in #1691

Full Changelog: v3.17.0...v3.17.1

v3.17.0

09 Apr 18:38
423737e

Choose a tag to compare

What's Changed

  • [ANE-2886] Handle missing version field in uv.lock editable packages by @zlav in #1682
  • add a comment about who has access to macos signing stuff by @spatten in #1681
  • Gradle: Add additional development and test configurations for common plugins by @zlav and @jeffalder in #1685
  • Vendetta: single-file and multi-location deps by @nficca in #1680

Full Changelog: v3.16.7...v3.17.0

v3.16.7

02 Apr 21:51
v3.16.7
3341930

Choose a tag to compare

  • Cargo: Deal with git-backed cargo locators properly (#1670)

v3.16.6

31 Mar 09:24
d15da81

Choose a tag to compare

What's Changed

Full Changelog: v3.16.5...v3.16.6

v3.16.5

23 Mar 18:55
v3.16.5
b54765a

Choose a tag to compare

  • PNPM: Fix pnpm v9 lockfile transitive devDependency classification. Dependencies of devDependencies were incorrectly reported as production dependencies in pnpm v9 projects. (#1668)

v3.16.4

20 Mar 18:51
025451c

Choose a tag to compare

Mac OS: Resolve an issue with dynamic linking on some Mac OS systems.

v3.16.3

19 Mar 17:36
v3.16.3
d4f6b4d

Choose a tag to compare

  • Elixir: Use MIX_ENV=prod for accurate production dependency resolution, with fallback to --only prod for projects lacking config/prod.exs (#1662)
  • Infrastructure: Add cmdEnvVars field to Command type for setting environment variables on subprocesses via typed-process (#1662)

v3.16.2

10 Mar 18:44
v3.16.2
925643a

Choose a tag to compare

  • Conda: Make conda analysis work on versions of conda where the --force flag is deprecated for conda env create (#1661)
  • Bug fix: fail early if the --output flag is combined with --snippet-scan or --x-vendetta flags (#1659)
  • Hide deprecated --experimental-use-v3-go-resolver, --experimental-skip-vsi-graph and --experimental-link-project-binary flags, and deprecate the experimental-link-user-defined-dependency-binary subcommand. The flags and subcommand still work, but are no longer documented or shown in the help text (#1633)

v3.16.1

09 Mar 18:29
984c004

Choose a tag to compare

  • Licensing: Add standalone detection for Solace proprietary licenses (solace-software-2021, solace-non-production-1.0, solace-api-1.1) (#1660)
  • Licensing: Add support for SPDX tag-value format license declarations

v3.16.0

23 Feb 14:34
8b1c5ff

Choose a tag to compare

What's Changed

Full Changelog: v3.15.9...v3.16.0