Skip to content

fix(ci): scan bun.lock via file: input so the SBOM isn't empty - #3414

Merged
Marfuen merged 1 commit into
mainfrom
mariano/fix-sbom-bunlock-scan
Jul 15, 2026
Merged

Marfuen merged 1 commit into
mainfrom
mariano/fix-sbom-bunlock-scan

Conversation

@Marfuen

@Marfuen Marfuen commented Jul 15, 2026 •

Copy link
Copy Markdown
Contributor

Summary

Follow-up fix to the SBOM workflow (merged in #3413). That workflow ran green but submitted a near-empty snapshot, so it didn't actually fix GitHub's blindness to the bun tree.

Root cause

The workflow scanned with path: . (a directory scan). Syft's default directory catalogers do not include the bun cataloger, so it silently skipped bun.lock and only picked up apps/mcp-server/package-lock.json (npm) + the GitHub Actions in the workflows.

Verified against the first run's artifact: 138 packages, and none of the bun tree — axios, better-auth, next, form-data all absent. (94 npm from mcp-server + 41 github-actions + 3 misc.)

Fix

Scan bun.lock via the action's file: input instead. A file scan forces Syft's bun cataloger and yields the full resolved tree — verified locally: 2487 packages with axios 1.18.1, form-data 4.0.6, ws 8.21.0, better-auth, next, systeminformation all present (overrides applied).

apps/mcp-server/package-lock.json is already covered by GitHub's native npm parsing (it's why Dependabot already alerts on it), so submitting just the bun tree completes the graph — no need to scan it here. Also tightened the push path filter accordingly.

Verification

  • ✅ YAML valid; with: { file: bun.lock, format: spdx-json, dependency-snapshot: true }
  • ✅ syft scan file:bun.lock → 2487 pkgs, full bun tree resolved
  • After merge, the workflow re-runs on main; then GitHub's Export SBOM + Dependabot should reflect ~2500 bun packages (up from the empty 138).

🤖 Generated with Claude Code


Summary by cubic

Fix SBOM workflow to scan bun.lock via the action’s file: input so Syft captures the full Bun dependency tree. This restores accurate dependency graph, Export SBOM, and Dependabot coverage.

  • Bug Fixes
    • Switch anchore/sbom-action from path: . to file: bun.lock to trigger the Bun cataloger.
    • Narrow push paths to bun.lock and the workflow file.
    • Keep format: spdx-json and dependency-snapshot: true to submit the resolved tree.

Written for commit 0d86e41. Summary will update on new commits.

Review in cubic

The merged workflow used path: . (a directory scan). Syft's default
DIRECTORY catalogers don't include the bun cataloger, so it silently skipped
bun.lock and submitted a near-empty snapshot (138 pkgs: just mcp-server's
package-lock.json + GitHub Actions — none of the bun tree). Verified: the
generated artifact had 0 bun deps (axios/better-auth/next all absent).

Scan bun.lock with the file: input instead — a file scan forces the bun
cataloger and yields the full resolved tree (2487 pkgs, axios 1.18.1,
form-data 4.0.6, etc.). apps/mcp-server/package-lock.json is already covered
by GitHub's native npm parsing, so submitting the bun tree completes the graph.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 15, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
app Ready Ready Preview, Comment Jul 15, 2026 3:26pm
comp-framework-editor Ready Ready Preview, Comment Jul 15, 2026 3:26pm
portal Ready Ready Preview, Comment Jul 15, 2026 3:26pm

Request Review

@Marfuen
Marfuen merged commit e47e6fd into main Jul 15, 2026
8 of 9 checks passed
@Marfuen
Marfuen deleted the mariano/fix-sbom-bunlock-scan branch July 15, 2026 15:30
claudfuen pushed a commit that referenced this pull request Jul 15, 2026
# [3.102.0](v3.101.2...v3.102.0) (2026-07-15)

### Bug Fixes

* **ci:** pin Syft 1.46.0 in SBOM action (1.42.3 can't parse bun.lock) ([#3415](#3415)) ([5f47024](5f47024))
* **ci:** scan bun.lock via file: input so the SBOM isn't empty ([#3414](#3414)) ([e47e6fd](e47e6fd))
* **deps:** override uuid to ^11.1.1 (Dependabot [#85](#85)) ([#3418](#3418)) ([598ff8c](598ff8c))
* **deps:** patch tmp and js-yaml in mcp-server (Dependabot [#58](https://github.com/trycompai/comp/issues/58)/[#59](https://github.com/trycompai/comp/issues/59)/[#71](https://github.com/trycompai/comp/issues/71)) ([#3412](#3412)) ([59a6b0f](59a6b0f))
* **deps:** remediate dependency security vulnerabilities ([#3403](#3403)) ([7577a37](7577a37))
* **deps:** remediate dependency security vulnerabilities (165→16, 4 critical→0) ([#3406](#3406)) ([d403e9c](d403e9c))
* **device-agent:** implement the installer-cleanup fix ([#3381](#3381)) ([0f7581b](0f7581b))
* **security:** prevent SSRF in task-automation enterprise API calls ([#3411](#3411)) ([dcec288](dcec288)), closes [#116](#116)
* **security:** resolve open CodeQL alerts (XSS, sanitization, workflow perms) ([#3419](#3419)) ([32329be](32329be)), closes [#108](#108) [js/xss-throu#dom](https://github.com/js/xss-throu/issues/dom) [#95](#95) [84/#85](#85)

### Features

* **framework-editor:** raise requirement description limit to 100,000 chars (FRAME-2) ([67c9f4a](67c9f4a))
@claudfuen

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 3.102.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

This branch was successfully deployed

3 active deployments
Preview – comp-framework-editor — 0d86e419 Deployed Jul 15, 2026 by vercel[bot]
Preview – app — 0d86e419 Deployed Jul 15, 2026 by vercel[bot]
Preview – portal — 0d86e419 Deployed Jul 15, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants