Skip to main content

Changes in Update Released on 29-November-2022

This Update includes the changes described in the following sections.

Issues/Bugs Addressed

The following issues were addressed in the Update:

Issue IDIssue Summary
SCA-44021Addition of Go vulnerability mapper to the list of our automated vulnerability mappers
SCA-44283Added the license Microsoft .Net Compiler Platform Redistributable Packages Preview to the data library
SCA-44290Updated the invalid urls of few Go forge components like Alamofire/AlamofireImage, BoltsFramework/Bolts-Swift and bitstadium/hockeykit.
SCA-44376Updating license information for the components jquery (id: 3526090)
SCA-44397, SCA-43635Fixed false positive vulnerability for the components like system.threading.tasks nuget package and MySQL NPM module.

Enhanced License Detection Capability for Components

License detection capability and license evidence mechanism for the following components was updated/added:

  • Qt-GPL-exception-1.0.txt

  • SchemeReport.txt

  • SWL.txt

  • Universal-FOSS-exception-1.0.txt

  • X11-distribute-modifications-variant.txt

  • XSkat.txt

  • CECILL-1.0

  • CECILL-1.1

  • CECILL-2.0

  • CECILL-2.1

  • CECILL-B

  • CECILL-C

  • MPL-1.0

  • MPL-1.1

  • MPL-2.0

  • MPL-2.0-no-copyleft-exception

  • NPL-1.0

  • NPL-1.1

  • MIT License

  • MIT-open-group

  • X11

  • X11-distribute-modifications-variant

  • XSkat

  • SWL

  • SchemeReport

New/Update Component Requests

  • XIPH Flac

  • XORG XServer

Collector Status

The following table lists Collector Status information.

NameDate of Last Successful Run
crates8/25/2022
npm10/11/2022
pypi10/18/2022
alpine11/8/2022
gitlab11/19/2022
cpan11/24/2022
rubygems11/24/2022
clojars11/24/2022
github11/24/2022
maven-google11/25/2022
fedora-koji11/26/2022
cran11/26/2022
nuget gallery11/26/2022
hackage11/27/2022
packagist11/28/2022
go11/28/2022
maven2-ibiblio11/28/2022