devops-kung-fu / devops-kung-fu/bomber
SBOM - Duplicating issues as unspecified
Open
- Dominant language
- Go
- Stars
- 624
- Forks
- 56
- PR merge metrics
- No merged PRs in 30d
Description
My SBOM report is generating multiple duplicates that are already listed as high or moderate vulnerability.
Running SBOM version 0.5.1 and GitLab-runner 17.5.3
Is there a known issue for this?
Contributor guide
Research direction
Start by reproducing the SBOM report issue with SBOM version 0.5.1 and GitLab-runner 17.5.3, using the two attached reports as the expected-versus-actual reference. Trace why vulnerabilities already reported as high or moderate are duplicated as unspecified. Done means the duplicate unspecified entries are no longer generated while the existing severity entries remain.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- gitlab, go
- Domain
- security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Needs clarification
- Newbie friendliness
- 38/100