8000 Syft SBOMs support dependency hierarchies. · Issue #1674 · anchore/syft · GitHub
[go: up one dir, main page]
More Web Proxy on the site http://driver.im/
Skip to content

Syft SBOMs support dependency hierarchies. #1674

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
bardenstein opened this issue Mar 16, 2023 · 2 comments
Closed

Syft SBOMs support dependency hierarchies. #1674

bardenstein opened this issue Mar 16, 2023 · 2 comments
Labels
enhancement New feature or request

Comments

@bardenstein
Copy link

What would you like to be added:
When I generate SBOMs from Syft (in either CycloneDX or SPDX), the resulting SBOM files don't show the dependency hierarchies (i.e. the tree relationships between libraries) that other generators do (like the open-sbom-generator).

I want/need to be able to see, for a given vulnerable library, how it was introduced into an asset.

Ex:

  • Dependency 1 (has a CVE)
    • introduced by dep 2
      • introduced by dep 3
        • introduced by dep 4, which is a top-level library / root node.

Why is this needed:
This allows me to tell developers what libraries they specifically need to upgrade/replace in order to remediate vulns or other issues introduced.

Additional context:

@bardenstein bardenstein added the enhancement New feature or request label Mar 16, 2023
@tgerla tgerla added this to OSS Mar 16, 2023
@eliaslevy
Copy link

This is a duplicate of #572.

@wagoodman
Copy link
Contributor
wagoodman commented Jul 27, 2023 75B0

Indeed it's a dup -- I'll close this one. Shout out if there is extra context that is not capture in the original issue.

@wagoodman wagoodman closed this as not planned Won't fix, can't repro, duplicate, stale Jul 27, 2023
@github-project-automation github-project-automation bot moved this to Done in OSS Jul 27, 2023
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
Archived in project
Development

No branches or pull requests

3 participants
0