You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
What happened:
Generating an SBOM for the same application results in different CPEs for some artifacts depending on wether you scan the JAR or the Gradle lockfiles. This is problematic because only one version is correct (from scanning the JAR) and can be associated with a CVE by Grype.
Output from scanning JAR for an affected package (org.apache.commons/commons-text):
henryde
changed the title
Different CPEs between java-cataloger and java-gradle-lockfile-cataloger and
Different CPEs between java-cataloger and java-gradle-lockfile-cataloger
Jul 26, 2023
What happened:
Generating an SBOM for the same application results in different CPEs for some artifacts depending on wether you scan the JAR or the Gradle lockfiles. This is problematic because only one version is correct (from scanning the JAR) and can be associated with a CVE by Grype.
Output from scanning JAR for an affected package (org.apache.commons/commons-text):
Output for the same application from scanning the Gradle lockfile:
Line from
gradle.lockfile
:What you expected to happen:
CPEs should be the same regardless of cataloger.
Environment:
syft version
:The text was updated successfully, but these errors were encountered: