1.7.0 (2026-08-03)

Added

  • Vulnerabilities can be filtered by severity.
  • During CSAF Generation a CPE or pURL can now be provided for a product. Furthermore it can be prevented that a “vendor” entry is created inside the product tree.

Changed

  • Improved matching algorithm between SBOMs and CSAFs.

Fixed

  • Duplicated component in a BOM are now treated as a warning instead of an error, since they may appear in the syft output.