Unmatched Vulnerabilities.affects.ref when scanning CycloneDX sbom with duplicate Purls #7360
Closed
2 tasks done
Labels
kind/bug
Categorizes issue or PR as related to a bug.
scan/sbom
Issues relating to SBOM
scan/vulnerability
Issues relating to vulnerability scanning
Discussed in #7334
Originally posted by scott-boost August 13, 2024
Description
When scanning a cyclone dx sbom with 2 components that have the exact same purls (but different bom-refs), the resulting vulnerability.affects.ref has a seemingly random ref
NOTE: that this bug does not occur if the format is
json
insteadDesired Behavior
vulnerability.affects.ref points to a Component.bom-ref in the same sbom
Actual Behavior
vulnerability.affects.ref DOES NOT point to a Component.bom-ref in the same sbom
Reproduction Steps
Target
SBOM
Scanner
Vulnerability
Output Format
CycloneDX
Mode
Standalone
Debug Output
Operating System
macOS Sonoma 14.6.1
Version
Checklist
trivy clean --all
The text was updated successfully, but these errors were encountered: