Skip to content

ci: submit resolved bun tree to GitHub dependency graph (accurate SBOM/Dependabot) - #3413

Merged
Marfuen merged 2 commits into
mainfrom
mariano/sbom-dependency-submission
Jul 15, 2026
Merged

Marfuen merged 2 commits into
mainfrom
mariano/sbom-dependency-submission

Conversation

@Marfuen

@Marfuen Marfuen commented Jul 15, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Makes GitHub's own dependency graph — and therefore its exported SBOM and Dependabot — accurate for the bun dependency tree.

The problem: GitHub does not natively parse bun.lock (confirmed against GitHub's docs and this repo). Out of the box its dependency graph sees only declared package.json ranges plus the one npm package-lock.json (apps/mcp-server). So anyone who exports the SBOM or self-generates a scan gets a picture that's blind to the entire bun tree — missing both the real transitive versions and the overrides we use to patch them. This is exactly what produced the earlier inflated/misleading scans.

The fix: Syft does parse bun.lock with fully resolved versions (verified locally: 2508 packages, overrides applied — e.g. axios 1.18.1, form-data 4.0.6, ws 8.21.0). This workflow runs Syft via anchore/sbom-action and submits the resolved tree through GitHub's Dependency Submission API (dependency-snapshot: true). Once it runs on main:

  • GitHub's Export SBOM includes the resolved bun tree.
  • Dependabot covers the bun side (not just mcp-server).
  • The SBOM is also uploaded as a workflow artifact for anyone who wants the file directly.

Triggers

push to main (when a lockfile/manifest or this workflow changes), a weekly schedule, and workflow_dispatch. Requires contents: write (the Dependency Submission API needs it). No run: steps and no event-input interpolation, so there's no workflow-injection surface.

Heads-up (expected, not a bug)

Once the resolved bun tree is in the graph, Dependabot will start alerting on the bun side too — including the ~15 dev/build-time / no-upstream-fix findings that bun audit reports (0 critical). That's accurate; they can be triaged/dismissed-with-rationale as they appear. This is the intended trade-off for making self-service reports correct.

🤖 Generated with Claude Code


Summary by cubic

Submits the resolved Bun dependency tree to GitHub’s dependency graph so Export SBOM and Dependabot reflect real versions and overrides. Adds a CI workflow that builds an SPDX SBOM, submits a dependency snapshot, and uploads the file as an artifact.

  • New Features

    • Scans the repo with anchore/sbom-action (Syft) to parse bun.lock and apps/mcp-server/package-lock.json, then submits a dependency snapshot and uploads sbom.spdx.json.
    • Triggers on push to main when lockfiles/manifests or the workflow change, weekly cron, and manual dispatch.
    • Dependabot will now alert on the Bun tree; triage as needed.
  • Refactors

    • Pins anchore/sbom-action to the commit for v0.24.0 (Syft v1.42.3) to avoid mutable tag risk with contents: write.

Written for commit 5b24cf9. Summary will update on new commits.

Review in cubic

GitHub does not natively parse bun.lock, so its dependency graph, exported
SBOM, and Dependabot only see declared package.json ranges plus the npm
package-lock.json in apps/mcp-server — they are blind to the bun dependency
tree and to our overrides. Syft parses bun.lock with fully resolved versions,
so this workflow scans the repo with Syft (anchore/sbom-action) and submits
the result via GitHub's Dependency Submission API. After it runs on main,
GitHub's own Export SBOM and Dependabot reflect the real bun tree; the SBOM
is also uploaded as a workflow artifact.

Runs on main (when lockfiles/manifests change), weekly, and on demand.
Needs contents:write for the submission API. No run: steps / no untrusted
input, so no workflow-injection surface.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 15, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
app Ready Ready Preview, Comment Jul 15, 2026 3:12pm
comp-framework-editor Ready Ready Preview, Comment Jul 15, 2026 3:12pm
portal Ready Ready Preview, Comment Jul 15, 2026 3:12pm

Request Review

@cubic-dev-ai cubic-dev-ai Bot left a comment •

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

All reported issues were addressed across 1 file

Confidence score: 5/5

  • Safe to merge after the addressed issues were fixed.

Reply with feedback, questions, or to request a fix.

Fix all with cubic | Re-trigger cubic

Comment thread .github/workflows/sbom.yml Outdated
The action runs with contents:write (Dependency Submission API), so the
mutable @v0 tag is a supply-chain risk — a retag or repo compromise would
run altered third-party code with our write token. Pin to the full commit
SHA of v0.24.0 (Syft v1.42.3, which parses bun.lock). Bump SHA + comment
together to upgrade.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@claudfuen

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 3.102.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

This branch was successfully deployed

3 active deployments
Preview – app — 5b24cf99 Deployed Jul 15, 2026 by vercel[bot]
Preview – comp-framework-editor — 5b24cf99 Deployed Jul 15, 2026 by vercel[bot]
Preview – portal — 5b24cf99 Deployed Jul 15, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants