-
Notifications
You must be signed in to change notification settings - Fork 3k
Open
Labels
kind/featureCategorizes issue or PR as related to a new feature.Categorizes issue or PR as related to a new feature.scan/sbomIssues relating to SBOMIssues relating to SBOM
Description
Description:
Trivy currently fails to decode CycloneDX 1.7 SBOMs with the error invalid specification version.
$ trivy sbom merged.cdx.json
FATAL Fatal error run error: sbom scan error: scan error: scan failed: failed analysis: SBOM decode error: failed to decode: CycloneDX decode error: CycloneDX decode error: invalid specification version
Root Cause
The upstream library https://github.com/CycloneDX/cyclonedx-go does not yet support version 1.7.
Upstream tracking issue: CycloneDX/cyclonedx-go#247
References
Reactions are currently unavailable
Metadata
Metadata
Assignees
Labels
kind/featureCategorizes issue or PR as related to a new feature.Categorizes issue or PR as related to a new feature.scan/sbomIssues relating to SBOMIssues relating to SBOM