forked from google/osv-scanner
-
Notifications
You must be signed in to change notification settings - Fork 0
Commit
This commit does not belong to any branch on this repository, and may belong to a fork outside of the repository.
More specific cyclone dx parsing (google#258)
Make sure the file name follows the recognized file names here: https://cyclonedx.org/specification/overview/#recognized-file-patterns Resolves google#257 Also - adds tests for sboms, - makes SBOM scan logging output consistent with lockfile scan logging output - Minor refactor of SBOMs I believe we will also want something similar to parse-as in lockfiles for SBOMs as well in the future to allow file names that doesn't conform to the standard to be scanned.
- Loading branch information
1 parent
a9a5a24
commit 3dc655a
Showing
7 changed files
with
5,785 additions
and
15 deletions.
There are no files selected for viewing
Large diffs are not rendered by default.
Oops, something went wrong.
5,110 changes: 5,110 additions & 0 deletions
5,110
cmd/osv-scanner/fixtures/sbom-insecure/postgres-stretch.cdx.xml
Large diffs are not rendered by default.
Oops, something went wrong.
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters