Skip to content

SBOM is different on package.json with same command on different systems #502

Closed Answered by jkowalleck
Serraniel asked this question in Q&A
Discussion options

You must be logged in to vote

regarding the result differences:

I understand that the result differs, if you run it in different systems, which each differ in installed npm packages/versions.

You expect, that the "same command" results in the same output.
Did you check that the version of @cyclonedx/cyclonedx-npm and its dependencies are the same on all systems?
I doubt that they are all the same, because you described a behavior that was added as a feature in one version, but did not exist in an older one.


regarding that problem parsing the PURL in DependencyTrack(DT): it is a known issue of DT which allows PURLS of a certain length at max. They know it is an issue and might have fixed it in the past. And in additio…

Replies: 3 comments 10 replies

Comment options

You must be logged in to vote
2 replies
@jkowalleck
Comment options

@Serraniel
Comment options

Answer selected by Serraniel
Comment options

You must be logged in to vote
3 replies
@jkowalleck
Comment options

@jkowalleck
Comment options

@jkowalleck
Comment options

Comment options

You must be logged in to vote
5 replies
@jkowalleck
Comment options

@igord
Comment options

@jkowalleck
Comment options

@igord
Comment options

@jkowalleck
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
question Further information is requested
3 participants
Converted from issue

This discussion was converted from issue #474 on February 13, 2023 16:37.