anchore / anchore/syft

Software packages installed in C:\ProgramData hidden directory on Windows are missing in SBOM.

Open
#973 1 comment 0 reactions 0 assignees View on GitHub
bug ecosystem:windows good-first-issue windows
Dominant language
Go
Stars
9.6k
Forks
954
Avg merge
23h 27m
Merged PRs (30d)
48

Description

**What happened**: Software packages installed in C:\ProgramData hidden directory on Windows are not included in SBOM.

**What you expected to happen**: All software packages installed on Windows should be included in SBOM.

**How to reproduce it (as minimally and precisely as possible)**:
Run `syft packages C:/ProgramData/ -o spdx-json --file C:/temp/sbom.json` on a Windows machine. The result file lists no packages at all. The json output file looks like this:
`{
"SPDXID": "SPDXRef-DOCUMENT",
"name": "C-/ProgramData",
"spdxVersion": "SPDX-2.2",
"creationInfo": {
"created": "2022-04-25T15:54:01.6848241Z",
"creators": [
"Organization: Anchore, Inc",
"Tool: syft-0.43.0"
],
"licenseListVersion": "3.16"
},
"dataLicense": "CC0-1.0",
"documentNamespace": "https://anchore.com/syft/dir/C-/ProgramData-885e79dd-6f7a-4fa6-bf3e-199da720e095",
"packages": []
}`

**Anything else we need to know?**: no

**Environment**:
- Output of `syft version`: 0.43.0
- OS (e.g: `cat /etc/os-release` or similar): Windows Server 2019 or newer

Contributor guide

Open the contributing guide

Research direction

Reproduce `syft packages C:/ProgramData/ -o spdx-json --file C:/temp/sbom.json` on Windows Server 2019 or newer and inspect the filesystem package-discovery path for hidden directories. Done means the generated SBOM includes software packages installed under `C:\ProgramData` instead of an empty package list.

Written by the indexing model from the issue text.

Assessment

Tech stack
go
Domain
cli, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.