devops-kung-fu / devops-kung-fu/bomber

SBOM - Duplicating issues as unspecified

Open
#301 0 comments 0 reactions 0 assignees View on GitHub
Dominant language
Go
Stars
624
Forks
56
PR merge metrics
No merged PRs in 30d

Description

My SBOM report is generating multiple duplicates that are already listed as high or moderate vulnerability.
Running SBOM version 0.5.1 and GitLab-runner 17.5.3

Image

Image

Is there a known issue for this?

Contributor guide

Open the contributing guide

Research direction

Start by reproducing the SBOM report issue with SBOM version 0.5.1 and GitLab-runner 17.5.3, using the two attached reports as the expected-versus-actual reference. Trace why vulnerabilities already reported as high or moderate are duplicated as unspecified. Done means the duplicate unspecified entries are no longer generated while the existing severity entries remain.

Written by the indexing model from the issue text.

Assessment

Tech stack
gitlab, go
Domain
security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Needs clarification
Newbie friendliness
38/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.