BOM processing #1485
Unanswered
higginsm99
asked this question in
Q&A
BOM processing
#1485
Replies: 1 comment 2 replies
-
Yes, and no. For components of type |
Beta Was this translation helpful? Give feedback.
2 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Hi
A Syft generated CycloneDX SBOM contains the path ("path") to each component found. However, after importing the SBOM into DT, DT does not show this information when you look at the component details. For example, I scanned a container comprising 1700 components and after it was analysed by DT I had 200 vulnerabilities of which 3 were in agent-base 4.1.1 and 3 were in agent-base 4.1.2...but I could not see any information as to where agent-base was found. Does DT keep the path information? Knowing the paths to the files containing vulnerable component(s) is useful because it helps a developer pinpoint the package that contains the vulnerable component and either update it or contact the vendor for an update. I did try looking in the Syft SBOM and the DT "Inventory with Vulnerabilities" SBOM, but there are no useful tags retained in the DT SBOM to do a match with.
Beta Was this translation helpful? Give feedback.
All reactions