Repository navigation
Conversation
andrew
left a comment
There was a problem hiding this comment.
-
cmd/sbom.go:210-240: Resolution matching requires the manifest and lockfile to share a directory. A rootpackage-lock.jsoncannot resolvepackages/web/package.json. A real npm workspace produces two lodash components, with the nested declaration absent from the resolved component. Match shared root or ancestor lockfiles and add a regression through the publicsbomcommand. -
cmd/sbom.go:292-304: When a valid constraint matches no candidate, the code retains every original candidate. A^5.0.0declaration is attached to lockfile version4.17.21. Preserve this as an unresolved occurrence, and reserve fallback matching for unsupported constraint syntax. -
cmd/sbom.go:151-157:sbom --type spdxdrops every occurrence property becausegit-pkgs/sbomhas no SPDX property encoding. Fix and release that module before bumping it here, or explicitly limit occurrence metadata to CycloneDX. -
go.mod:17:v0.1.6now contains the pinned commit, so the temporary pseudo-version should be removed. That tag requires Go 1.26.7 while this project pins 1.26.6, so either bump the project toolchain or publish a compatiblesbomrelease.
7a27913 to
ed63645
Compare
|
Addressed all four points. Workspace declarations now match the nearest ancestor lockfile, valid constraints with no matching resolved version remain unresolved, and occurrence properties are explicitly limited to CycloneDX and documented. I also switched to |
andrew
left a comment
There was a problem hiding this comment.
cmd/sbom.go:335-362: Prefer direct candidates before constraint matching. Givenfoo@^5.0.0, a direct lockfile entry at4.0.0, and a transitive entry at5.1.0,sbomattaches the manifest occurrence to transitivefoo@5.1.0. The nested entry cannot resolve the root declaration. Filter to direct entries first, leave the declaration unresolved when none satisfy its constraint, and add a command-level regression.
|
Thanks, Fixed. SBOM resolution now prefers direct lockfile candidates before evaluating constraints, so a compatible transitive entry cannot claim a direct manifest declaration. Added a command-level regression covering the mismatched direct and compatible transitive versions. |
andrew
left a comment
There was a problem hiding this comment.
cmd/sbom.go:335-343: Scope direct-candidate preference to manifests beside the lockfile. npm marks only root declarations as direct. When root and workspace manifests require different versions of the same package, the root candidate displaces the compatible workspace resolution before constraint matching. Add command-level coverage for that case.
0c3c3e8 to
087de4a
Compare
|
Thanks, Fixed. Direct-candidate preference is now limited to manifests beside the lockfile. Workspace manifests using an ancestor lockfile select the compatible resolved version using their own constraint. I added command-level regression coverage for root and workspace manifests requiring different versions, rebased onto current |
Closes #307
Summary
manifest_pathrequirementdependency_typegithub.com/git-pkgs/sbomto the merged commit from Preserve package properties in CycloneDX output sbom#14 so properties are encoded in CycloneDX JSON and XML.Dependency version
github.com/git-pkgs/sbomis currently pinned to the immutable pseudo-version for the merged git-pkgs/sbom#14 commit becausev0.1.6has not yet been tagged.The dependency can be changed to
v0.1.6if that tag is published before this PR merges.Testing
Added regression coverage for:
Verification
gofmtgo test ./... -count=1go tool golangci-lint run ./...go mod tidy -diffgit diff --check