Syft - v1.31.0 released

:sparkles: Help shape the future of Syft! Share your thoughts in our quick 5-question survey. Your feedback will guide our development priorities and help us better serve your needs. Thank you! :raising_hands:

Release Notes:

Version v1.31.0

Added Features

  • Option to set PackageSupplier in root of SPDX document generated by CLI #3098 #4131 @spiffcs

Bug Fixes

  • closed reader during java binary detection #4129 @kzantow
  • support multiple letters in openssl patch version #4106 @honigbot
  • Can not have license ID #1964 #4132 @spiffcs
  • Syft sometimes reports URL for license value when scanning JARs with a URL in Bundle-License field of manifest #3186

(Full Changelog)