jfrog / jfrog/frogbot

frogbot&missing SBOM information

Open
#936 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

bug
Dominant language
Go
Stars
372
Forks
107
Avg merge
2d 20h
Merged PRs (30d)
5

Description

Describe the bug

Frogbot cannot pass the dependency information of my self-built JAR files to the SCM feature in JFrog, causing missing SBOM information in my project.

Current behavior

missing SBOM information in my project.My self-built packages cannot be found in the SCM.

Reproduction steps

No response

Expected behavior

No response

JFrog Frogbot version

2.27.2

Package manager info

pom.xml

Git provider

GitLab

JFrog Frogbot configuration yaml file

No response

Operating system type and version

Ubuntu

JFrog Xray version

No response

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start with the reported pom.xml and the GitLab SCM scanning path, then reproduce the missing SBOM information using self-built JAR files. The issue provides no reproduction steps or Frogbot configuration, so confirm the dependency setup and compare the resulting SCM data with the expected project SBOM.

Written by the indexing model from the issue text.

Assessment

Tech stack
gitlab
Domain
devops, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.