v1.11.0

Release notes for syft v1.11.0

Release Notes

Version v1.11.0

Added Features

Bug Fixes

Additional Changes

  • rather than have a hard max recursive depth - syft should detect parent pom cycles [#2284 #2769 @GijsCalis]
  • increase java purl generation test coverage [#3110 @westonsteimel]
  • Updated PackageSupplier to type Organization for JAR files [#3093 @harippriyas]
  • Ensure accurate java main artifact name retrieval for multi-JARs and refine fallback approach [#3054 @dor-hayun]

(Full Changelog)

Last modified October 10, 2025: fix reference links (1594d93)