Incomplete SBOM generated from Docker image #1496
Unanswered
robross0606
asked this question in
Q&A
Replies: 2 comments 39 replies
-
As a secondary question, is there a way to tell |
Beta Was this translation helpful? Give feedback.
0 replies
-
|
Beta Was this translation helpful? Give feedback.
39 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I have a Docker image pulled down in a build environment as a TAR file. If I run
cdxgen
like this:The output shows this:
The resulting SBOM file includes all the typical
node
base language dependencies but none of the actual dependencies from the project in/usr/src/app
. So I'm left wondering what these two warnings mean:Beta Was this translation helpful? Give feedback.
All reactions