Skip to content

fix: include vulnerabilities in CycloneDX SBOM - #198

Open
SwaatiR wants to merge 1 commit into
OWASP:mainfrom
SwaatiR:fix/197-sbom-vulnerabilities
Open

SwaatiR wants to merge 1 commit into
OWASP:mainfrom
SwaatiR:fix/197-sbom-vulnerabilities

Conversation

@SwaatiR

@SwaatiR SwaatiR commented Oct 1, 2026

Copy link
Copy Markdown

Summary

Fixes #197.

CycloneDX SBOM generation was producing the component inventory but not including vulnerability findings.

generate_sbom() now explicitly enables Trivy's vulnerability scanner using --scanners vuln, so vulnerability findings are included in the generated CycloneDX SBOM.

Verification

Reproduced using:

ubuntu:stonking-20260705

Before the fix:

  • Normal JSON report: 14 vulnerabilities
  • CycloneDX SBOM: 0 vulnerabilities
  • CycloneDX components: 103

After the fix:

  • Normal JSON report: 14 vulnerabilities
  • CycloneDX SBOM: 20 vulnerabilities
  • CycloneDX components: 103

The SBOM vulnerability count is higher because the normal DockSec report is severity-filtered, while the SBOM vulnerability scan is not.

Tests

Added regression coverage for:

  • CycloneDX SBOM vulnerability scanning
  • Offline SBOM generation

Full test suite:

546 passed, 3 skipped, 153 subtests passed

@github-actions github-actions Bot added core Changes to core scanning logic tests Changes to the test suite labels Oct 1, 2026

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

core Changes to core scanning logic tests Changes to the test suite

Projects

None yet

Development

Successfully merging this pull request may close these issues.

[BUG] Vulnerabilities found by Trivy image scans are not added to SBOM

1 participant