From 17e3bec0555219fdc5a3054cd8d5d1ff3361253f Mon Sep 17 00:00:00 2001 From: Sonu Kapoor Date: Tue, 1 Sep 2026 08:42:18 -0400 Subject: [PATCH] release: v1.32.0 --- CHANGELOG.md | 23 +++++++++++++++++++++++ package-lock.json | 4 ++-- package.json | 2 +- website/docusaurus.config.ts | 2 +- 4 files changed, 27 insertions(+), 4 deletions(-) diff --git a/CHANGELOG.md b/CHANGELOG.md index 6f23aacb..4183f17a 100644 --- a/CHANGELOG.md +++ b/CHANGELOG.md @@ -2,6 +2,29 @@ All notable changes to CVE Lite CLI will be documented in this file. +## [1.32.0] - 2026-09-01 + +### Added + +- `--incomplete-policy warn|error` (default: `warn`): when detection data is incomplete, `warn` exits 0 with a warning; `error` exits 3. GitHub Action gains `incomplete-policy` input with empty default for backward compatibility (#1019, @luojiyin1987, closes #898) +- EPSS scores: findings are enriched with FIRST.org Exploit Prediction Scoring System data after the OSV pass. All CVE aliases are batch-fetched in a single API call. Highest-EPSS score shown in compact terminal top-3 block, verbose table column, and HTML report detail panel; full array in JSON output. Skipped in offline mode and for GHSA-only findings (#1053) +- npm advisory secondary source: after the OSV batch pass, packages with zero OSV matches are checked against the npm registry advisory API (`POST https://registry.npmjs.org/-/npm/v1/security/advisories/bulk`). Closes the coverage gap for CVEs that exist in OSV but have no npm ecosystem mapping. Skips in offline mode, non-fatal on error (#1056, closes #1054) +- `--check-licenses` flag: detect copyleft (LC001: GPL-2.0/3.0, AGPL-3.0, LGPL, EUPL, OSL, CDDL, CPL, EPL) and unknown (LC002: no declared license) licenses across the dependency tree in the same pass as the CVE scan. Informational only - never affects exit code or `--fail-on`. Surfaces in terminal, JSON, SARIF, and HTML reports. GitHub Action gains `check-licenses` input (#1059, closes #1058) + +### Fixed + +- Direct parent version collision: `resolveDirectParentContext` used a name-keyed Map (last-write-wins) to find the direct parent version, producing wrong `currentVersion` baselines and downgrade suggestions when the same package name is installed at multiple different versions. Fixed by using `findPackageAlongPath` with the path prefix to the direct parent position (#1051, closes #1050) + +### Tests + +- Add unit coverage for `src/utils/advisory.ts` (git+ssh:// protocol parsing, short-SHA alias resolution, scope handling, `parseAdvisoryOrCommand` edge cases) (#1046, @suhanemathur, closes #1024) + +### Docs + +- README comparison table: link each capability row to its corresponding docs page (#1064, closes #1063) +- Comparison tables and homepage updated for `--check-licenses`: new row in README and comparison.md, socket.md updated, snyk.md prose updated, homepage FeatureCard and capability pill added, workflow-integration.md gains "License compliance in CI" section (#1061, closes #1060) +- Vulnerability data source descriptions updated to reflect OSV + npm registry advisory API dual-source approach across README, how-it-works, caching, cli-reference, getting-started (#1062, closes #1057) + ## [1.31.0] - 2026-08-27 ### Added diff --git a/package-lock.json b/package-lock.json index 6b381f0e..cfcec4d5 100644 --- a/package-lock.json +++ b/package-lock.json @@ -1,12 +1,12 @@ { "name": "cve-lite-cli", - "version": "1.31.0", + "version": "1.32.0", "lockfileVersion": 3, "requires": true, "packages": { "": { "name": "cve-lite-cli", - "version": "1.31.0", + "version": "1.32.0", "license": "MIT", "dependencies": { "better-sqlite3": "^12.8.0", diff --git a/package.json b/package.json index 5f1820d3..803f98cf 100644 --- a/package.json +++ b/package.json @@ -1,6 +1,6 @@ { "name": "cve-lite-cli", - "version": "1.31.0", + "version": "1.32.0", "description": "Developer-friendly CLI for scanning JS/TS projects for dependency vulnerabilities using local lockfiles and OSV", "type": "module", "bin": { diff --git a/website/docusaurus.config.ts b/website/docusaurus.config.ts index 7518a704..d7ba7ffe 100644 --- a/website/docusaurus.config.ts +++ b/website/docusaurus.config.ts @@ -2,7 +2,7 @@ import {themes as prismThemes} from 'prism-react-renderer'; import type {Config} from '@docusaurus/types'; import type * as Preset from '@docusaurus/preset-classic'; -const latestVersion = 'v1.31.0'; +const latestVersion = 'v1.32.0'; const config: Config = { title: 'CVE Lite CLI',