ci: submit resolved bun tree to GitHub dependency graph (accurate SBOM/Dependabot) - #3413
Merged
Merged
Conversation
GitHub does not natively parse bun.lock, so its dependency graph, exported SBOM, and Dependabot only see declared package.json ranges plus the npm package-lock.json in apps/mcp-server — they are blind to the bun dependency tree and to our overrides. Syft parses bun.lock with fully resolved versions, so this workflow scans the repo with Syft (anchore/sbom-action) and submits the result via GitHub's Dependency Submission API. After it runs on main, GitHub's own Export SBOM and Dependabot reflect the real bun tree; the SBOM is also uploaded as a workflow artifact. Runs on main (when lockfiles/manifests change), weekly, and on demand. Needs contents:write for the submission API. No run: steps / no untrusted input, so no workflow-injection surface. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Contributor
There was a problem hiding this comment.
All reported issues were addressed across 1 file
Confidence score: 5/5
- Safe to merge after the addressed issues were fixed.
Reply with feedback, questions, or to request a fix.
Fix all with cubic | Re-trigger cubic
The action runs with contents:write (Dependency Submission API), so the mutable @v0 tag is a supply-chain risk — a retag or repo compromise would run altered third-party code with our write token. Pin to the full commit SHA of v0.24.0 (Syft v1.42.3, which parses bun.lock). Bump SHA + comment together to upgrade. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
Contributor
|
🎉 This PR is included in version 3.102.0 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Makes GitHub's own dependency graph — and therefore its exported SBOM and Dependabot — accurate for the bun dependency tree.
The problem: GitHub does not natively parse
bun.lock(confirmed against GitHub's docs and this repo). Out of the box its dependency graph sees only declaredpackage.jsonranges plus the one npmpackage-lock.json(apps/mcp-server). So anyone who exports the SBOM or self-generates a scan gets a picture that's blind to the entire bun tree — missing both the real transitive versions and theoverrideswe use to patch them. This is exactly what produced the earlier inflated/misleading scans.The fix: Syft does parse
bun.lockwith fully resolved versions (verified locally: 2508 packages, overrides applied — e.g.axios 1.18.1,form-data 4.0.6,ws 8.21.0). This workflow runs Syft viaanchore/sbom-actionand submits the resolved tree through GitHub's Dependency Submission API (dependency-snapshot: true). Once it runs onmain:Triggers
pushtomain(when a lockfile/manifest or this workflow changes), a weekly schedule, andworkflow_dispatch. Requirescontents: write(the Dependency Submission API needs it). Norun:steps and no event-input interpolation, so there's no workflow-injection surface.Heads-up (expected, not a bug)
Once the resolved bun tree is in the graph, Dependabot will start alerting on the bun side too — including the ~15 dev/build-time / no-upstream-fix findings that
bun auditreports (0 critical). That's accurate; they can be triaged/dismissed-with-rationale as they appear. This is the intended trade-off for making self-service reports correct.🤖 Generated with Claude Code
Summary by cubic
Submits the resolved Bun dependency tree to GitHub’s dependency graph so Export SBOM and Dependabot reflect real versions and overrides. Adds a CI workflow that builds an SPDX SBOM, submits a dependency snapshot, and uploads the file as an artifact.
New Features
anchore/sbom-action(Syft) to parsebun.lockandapps/mcp-server/package-lock.json, then submits a dependency snapshot and uploadssbom.spdx.json.mainwhen lockfiles/manifests or the workflow change, weekly cron, and manual dispatch.Refactors
anchore/sbom-actionto the commit for v0.24.0 (Syft v1.42.3) to avoid mutable tag risk withcontents: write.Written for commit 5b24cf9. Summary will update on new commits.