I would like the CycloneDX components to be sorted by bom-ref
#4685
Closed
trevor-vaughan
started this conversation in
Ideas
Replies: 1 comment 6 replies
-
Interesting. We do sort components. Could you try the latest version? trivy/pkg/sbom/cyclonedx/core/cyclonedx.go Lines 206 to 208 in 7d48c5d |
Beta Was this translation helpful? Give feedback.
6 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
When attempting to do a few simple checks in a CI pipeline, I needed to diff a CycloneDX JSON file between a new and old commit.
I discovered that a simple
diff
(ignoring timestamp and global UUID changes) would not work since thecomponents
are not sorted consistently at each run.While this is straightforward to work around, it would be great to have sorted output for quick checks.
Target
Filesystem
Scanner
None
Beta Was this translation helpful? Give feedback.
All reactions