fix(ci): scan bun.lock via file: input so the SBOM isn't empty - #3414
Merged
Merged
Conversation
The merged workflow used path: . (a directory scan). Syft's default DIRECTORY catalogers don't include the bun cataloger, so it silently skipped bun.lock and submitted a near-empty snapshot (138 pkgs: just mcp-server's package-lock.json + GitHub Actions — none of the bun tree). Verified: the generated artifact had 0 bun deps (axios/better-auth/next all absent). Scan bun.lock with the file: input instead — a file scan forces the bun cataloger and yields the full resolved tree (2487 pkgs, axios 1.18.1, form-data 4.0.6, etc.). apps/mcp-server/package-lock.json is already covered by GitHub's native npm parsing, so submitting the bun tree completes the graph. Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
claudfuen
pushed a commit
that referenced
this pull request
Jul 15, 2026
# [3.102.0](v3.101.2...v3.102.0) (2026-07-15) ### Bug Fixes * **ci:** pin Syft 1.46.0 in SBOM action (1.42.3 can't parse bun.lock) ([#3415](#3415)) ([5f47024](5f47024)) * **ci:** scan bun.lock via file: input so the SBOM isn't empty ([#3414](#3414)) ([e47e6fd](e47e6fd)) * **deps:** override uuid to ^11.1.1 (Dependabot [#85](#85)) ([#3418](#3418)) ([598ff8c](598ff8c)) * **deps:** patch tmp and js-yaml in mcp-server (Dependabot [#58](https://github.com/trycompai/comp/issues/58)/[#59](https://github.com/trycompai/comp/issues/59)/[#71](https://github.com/trycompai/comp/issues/71)) ([#3412](#3412)) ([59a6b0f](59a6b0f)) * **deps:** remediate dependency security vulnerabilities ([#3403](#3403)) ([7577a37](7577a37)) * **deps:** remediate dependency security vulnerabilities (165→16, 4 critical→0) ([#3406](#3406)) ([d403e9c](d403e9c)) * **device-agent:** implement the installer-cleanup fix ([#3381](#3381)) ([0f7581b](0f7581b)) * **security:** prevent SSRF in task-automation enterprise API calls ([#3411](#3411)) ([dcec288](dcec288)), closes [#116](#116) * **security:** resolve open CodeQL alerts (XSS, sanitization, workflow perms) ([#3419](#3419)) ([32329be](32329be)), closes [#108](#108) [js/xss-throu#dom](https://github.com/js/xss-throu/issues/dom) [#95](#95) [84/#85](#85) ### Features * **framework-editor:** raise requirement description limit to 100,000 chars (FRAME-2) ([67c9f4a](67c9f4a))
Contributor
|
🎉 This PR is included in version 3.102.0 🎉 The release is available on GitHub release Your semantic-release bot 📦🚀 |
This branch was successfully deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary
Follow-up fix to the SBOM workflow (merged in #3413). That workflow ran green but submitted a near-empty snapshot, so it didn't actually fix GitHub's blindness to the bun tree.
Root cause
The workflow scanned with
path: .(a directory scan). Syft's default directory catalogers do not include the bun cataloger, so it silently skippedbun.lockand only picked upapps/mcp-server/package-lock.json(npm) + the GitHub Actions in the workflows.Verified against the first run's artifact: 138 packages, and none of the bun tree —
axios,better-auth,next,form-dataall absent. (94 npm from mcp-server + 41 github-actions + 3 misc.)Fix
Scan
bun.lockvia the action'sfile:input instead. A file scan forces Syft's bun cataloger and yields the full resolved tree — verified locally: 2487 packages withaxios 1.18.1,form-data 4.0.6,ws 8.21.0,better-auth,next,systeminformationall present (overrides applied).apps/mcp-server/package-lock.jsonis already covered by GitHub's native npm parsing (it's why Dependabot already alerts on it), so submitting just the bun tree completes the graph — no need to scan it here. Also tightened thepushpath filter accordingly.Verification
with: { file: bun.lock, format: spdx-json, dependency-snapshot: true }syft scan file:bun.lock→ 2487 pkgs, full bun tree resolvedmain; then GitHub's Export SBOM + Dependabot should reflect ~2500 bun packages (up from the empty 138).🤖 Generated with Claude Code
Summary by cubic
Fix SBOM workflow to scan
bun.lockvia the action’sfile:input so Syft captures the full Bun dependency tree. This restores accurate dependency graph, Export SBOM, and Dependabot coverage.anchore/sbom-actionfrompath: .tofile: bun.lockto trigger the Bun cataloger.bun.lockand the workflow file.format: spdx-jsonanddependency-snapshot: trueto submit the resolved tree.Written for commit 0d86e41. Summary will update on new commits.