Skip to content

fix(ci): pin Syft 1.46.0 in SBOM action (1.42.3 can't parse bun.lock) - #3415

Merged
Marfuen merged 1 commit into
mainfrom
mariano/fix-sbom-syft-version
Jul 15, 2026
Merged

Marfuen merged 1 commit into
mainfrom
mariano/fix-sbom-syft-version

Conversation

@Marfuen

@Marfuen Marfuen commented Jul 15, 2026 •

Copy link
Copy Markdown
Contributor

Root cause (proven)

After #3414 switched to file: bun.lock, the SBOM run still submitted an empty snapshot (artifact had 1 package). The CI log shows the action ran syft scan file:bun.lock with Syft 1.42.3 (bundled in anchore/sbom-action@v0.24.0).

Reproduced both versions locally against this repo's bun.lock:

Syft file:bun.lock result
1.42.3 (action default) 1 package — no working bun.lock support
1.46.0 2484 packages (spdx) / 2496 resolved deps (github snapshot format)

So it was never the scan target — it's the Syft version.

Fix

Pin syft-version: v1.46.0 in the action so it uses a Syft that can parse bun.lock.

After merge

The workflow re-runs on main; the sbom.spdx.json artifact should jump from 1 → ~2484 packages, and the submitted snapshot (~2496 deps) populates the dependency graph. Then GitHub's Export SBOM + Dependabot finally reflect the bun tree. (Expect Dependabot to then surface the ~15 dev/build bun audit findings — accurate, 0 critical.)

🤖 Generated with Claude Code


Summary by cubic

Pin Syft to v1.46.0 in the SBOM workflow so bun.lock is parsed correctly and the dependency snapshot is fully populated.

  • Bug Fixes
    • anchore/sbom-action@v0.24.0 bundles Syft 1.42.3, which can’t read bun.lock (yields 1 package).
    • Pinning syft-version: v1.46.0 fixes parsing. Expect sbom.spdx.json to include ~2484 packages and the snapshot ~2496 deps.

Written for commit ffc9423. Summary will update on new commits.

Review in cubic

The SBOM run still produced an empty snapshot after switching to file:bun.lock.
Root cause proven: anchore/sbom-action@v0.24.0 bundles Syft 1.42.3, and
'syft scan file:bun.lock' on 1.42.3 yields exactly 1 package (no bun.lock
support). Syft 1.46.0 yields the full tree — verified locally: 2484 packages
(spdx) / 2496 resolved deps in the GitHub snapshot format that gets submitted.

Pin syft-version: v1.46.0 so the action uses a Syft that can read bun.lock.

Co-Authored-By: Claude Fable 5 <noreply@anthropic.com>
@vercel

vercel Bot commented Jul 15, 2026 •

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated (UTC)
app Ready Ready Preview, Comment Jul 15, 2026 3:38pm
comp-framework-editor Ready Ready Preview, Comment Jul 15, 2026 3:38pm
portal Ready Ready Preview, Comment Jul 15, 2026 3:38pm

Request Review

@Marfuen
Marfuen merged commit 5f47024 into main Jul 15, 2026
6 of 9 checks passed
@Marfuen
Marfuen deleted the mariano/fix-sbom-syft-version branch July 15, 2026 15:34
claudfuen pushed a commit that referenced this pull request Jul 15, 2026
# [3.102.0](v3.101.2...v3.102.0) (2026-07-15)

### Bug Fixes

* **ci:** pin Syft 1.46.0 in SBOM action (1.42.3 can't parse bun.lock) ([#3415](#3415)) ([5f47024](5f47024))
* **ci:** scan bun.lock via file: input so the SBOM isn't empty ([#3414](#3414)) ([e47e6fd](e47e6fd))
* **deps:** override uuid to ^11.1.1 (Dependabot [#85](#85)) ([#3418](#3418)) ([598ff8c](598ff8c))
* **deps:** patch tmp and js-yaml in mcp-server (Dependabot [#58](https://github.com/trycompai/comp/issues/58)/[#59](https://github.com/trycompai/comp/issues/59)/[#71](https://github.com/trycompai/comp/issues/71)) ([#3412](#3412)) ([59a6b0f](59a6b0f))
* **deps:** remediate dependency security vulnerabilities ([#3403](#3403)) ([7577a37](7577a37))
* **deps:** remediate dependency security vulnerabilities (165→16, 4 critical→0) ([#3406](#3406)) ([d403e9c](d403e9c))
* **device-agent:** implement the installer-cleanup fix ([#3381](#3381)) ([0f7581b](0f7581b))
* **security:** prevent SSRF in task-automation enterprise API calls ([#3411](#3411)) ([dcec288](dcec288)), closes [#116](#116)
* **security:** resolve open CodeQL alerts (XSS, sanitization, workflow perms) ([#3419](#3419)) ([32329be](32329be)), closes [#108](#108) [js/xss-throu#dom](https://github.com/js/xss-throu/issues/dom) [#95](#95) [84/#85](#85)

### Features

* **framework-editor:** raise requirement description limit to 100,000 chars (FRAME-2) ([67c9f4a](67c9f4a))
@claudfuen

Copy link
Copy Markdown
Contributor

🎉 This PR is included in version 3.102.0 🎉

The release is available on GitHub release

Your semantic-release bot 📦🚀

This branch was successfully deployed

3 active deployments
Preview – app — ffc94237 Deployed Jul 15, 2026 by vercel[bot]
Preview – portal — ffc94237 Deployed Jul 15, 2026 by vercel[bot]
Preview – comp-framework-editor — ffc94237 Deployed Jul 15, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants