Replies: 5 comments 17 replies
-
Hello @glennvdv
I couldn't build the image. It looks like the system needs some configuration. We are focusing on other priorities. Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
-
What error are you getting? Only java & docker are needed to be able to build it |
Beta Was this translation helpful? Give feedback.
-
pushed to https://hub.docker.com/repository/docker/stuikerd/vulnerable-spring-boot/general |
Beta Was this translation helpful? Give feedback.
-
User found 1 more case with same problem - #8287. This problem is aggravated by the fact that for such sbom files we create a spdx file with an empty name field (and this is not a valid file(#8287) therefore we need to make some decision regarding such situations (fixes are needed in the sbom analyzer). I see 2 ways:
@knqyf263 wdyt? |
Beta Was this translation helpful? Give feedback.
-
Related issue - #8189 |
Beta Was this translation helpful? Give feedback.
-
Description
When creating an sbom of a docker image created with the command bootBuildImage. Trivy generates a component with an empty name.
Desired Behavior
Or component should not be present, or name should be filled in
Actual Behavior
name is missing
Reproduction Steps
Target
Container Image
Scanner
None
Output Format
CycloneDX
Mode
Standalone
Debug Output
Operating System
linux
Version
Checklist
trivy clean --all
Beta Was this translation helpful? Give feedback.
All reactions