Skip to content

Large discrepancies in number of components between "cyclonedx/bom v3.10.6" and "cyclonedx/cyclonedx-npm v1.6.0" #374

Closed Answered by jkowalleck
EvgeniaPatsoni asked this question in Q&A
Discussion options

You must be logged in to vote

the sort answer: @cyclonedx/bom had issues detecting all the dependencies, so some were not in the SBOM result.

The long answer:
@cyclonedx/cyclonedx-npm not only finds ALL the dependencies, but it also does not run artificial component deduplication. The reasons are described here and are discussed here and here ... and there.

Replies: 1 comment

Comment options

You must be logged in to vote
0 replies
Answer selected by jkowalleck
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants
Converted from issue

This discussion was converted from issue #332 on December 15, 2022 10:25.