anchore / anchore/syft

javascript-cataloger: false positive - cross-spawn

Open
#3,471 8 comments 1 reaction 0 assignees View on GitHub
question
Dominant language
Go
Stars
9.6k
Forks
954
Avg merge
23h 27m
Merged PRs (30d)
48

Description

**What happened**:

We install the dependency `cross-spawn` as one of the dependencies of jest in version `7.0.6`, however it seems the javascript cataloger can't parse our yarn.lock file, as it lists cross-spawn `7.0.3` which has a security issue and results in grype errors.

**What you expected to happen**:

yarn.lock is properly parsed. see our lockfile entry: https://github.com/robertkowalski/syft-minimal-example/blob/58974e0e983ec6a628770d1229a2c328d11c9394/yarn.lock#L859-L866

**Steps to reproduce the issue**:

```
$ git clone https://github.com/robertkowalski/syft-minimal-example.git
$ cd syft-minimal-example
$ docker build --tag cross-spawn .
$ syft cross-spawn -o syft-text
```
```
[...]

[cross-spawn]
Version: 7.0.3
Type: npm
Found by: javascript-package-cataloger
```

**Anything else we need to know?**:

**Environment**:
- Output of `syft version`:
```
Application: syft
Version: 1.16.0
BuildDate: 2024-11-04T20:23:27Z
GitCommit: Homebrew
GitDescription: [not provided]
Platform: darwin/amd64
GoVersion: go1.23.2
Compiler: gc
```

- OS (e.g: `cat /etc/os-release` or similar): OSX Sonoma 14.7

Contributor guide

Open the contributing guide

Research direction

Start by running the supplied syft reproduction against the linked yarn.lock entry and inspect the javascript-package-cataloger path that reports cross-spawn 7.0.3. Trace how this lockfile entry is parsed, then verify that the cataloger reports the resolved dependency correctly without the false positive.

Written by the indexing model from the issue text.

Assessment

Tech stack
go, javascript
Domain
devtools
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.