feat(cyclonedx): output source PURL as external reference - #5246
Open
swadaptive wants to merge 5 commits into
Open
feat(cyclonedx): output source PURL as external reference#5246swadaptive wants to merge 5 commits into
swadaptive wants to merge 5 commits into
Conversation
Signed-off-by: swadaptive <268603322+swadaptive@users.noreply.github.com>
Signed-off-by: swadaptive <268603322+swadaptive@users.noreply.github.com>
Signed-off-by: swadaptive <268603322+swadaptive@users.noreply.github.com>
Signed-off-by: swadaptive <268603322+swadaptive@users.noreply.github.com>
Signed-off-by: swadaptive <268603322+swadaptive@users.noreply.github.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Description
Adds an additional external reference to package components that are associated with a source package. Main use case is to aid vulnerability matching in ecosystems that report vulnerabilities against source packages instead of the binary package that
syftdetected was actually installed. Similar use case to the non-standardupstreamPURL qualifier thatsyftandgrypealready implement (which this PR leaves untouched).Uses the external reference type
source-distributionthat was introduced in CycloneDX v1.6 in combination with thepkgPackageURL URI scheme that was added to the IANA registry in July to indicate a source PURL which can be matched against vulnerability databases. I expect this change to make it easier for other vulnerability scanners to make use of the upstream source information without committing to support the syft-specificupstreamqualifier.Note: This change exposes a bug in
cyclonedx-gowhen encoding SBOMs. The library doesn't properly flag / filterexternalReferencetypes that were introduced later as invalid in earlier versions of the spec. With this changesyftwill output invalid documents for CycloneDX 1.5 or below until the bug is fixed upstream.Type of change
Checklist
Issue references