New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Packages not being found in 1.0.1 #2706
Comments
Hi @devinrsmith , I gave this a try, and it seems to be working properly for me:
Do you have a syft configuration file that's overriding some default settings? Are you able to send the output of |
I don't think I have any custom configuration; I've managed my installs by installing the am64 rpm releases on Fedora.
|
@devinrsmith something is wrong trying to download the attachment (404), but I gave this a shot with a
Are you able to run this on a clean fedora container? If you re-run this a few times, does it happen to eventually succeed? |
I guess the upload didn't work for some reason. I'll paste it here:
I'll try in a container soon. |
Developer notes: if someone is able to pick this up to try to reproduce it, a possibility why this isn't working for Devin could be due to handling of |
Hey @devinrsmith, have you had a chance to try to reproduce this in your container yet? We have so far been unable to reproduce the problem here but we would be happy to keep looking. Thanks! |
I'm unable to reproduce the issue using a fedora container; it seems to work. There must be something about my main workstation that is different. Using 1.1.1 now from my workstation I get the same issue though. With
from the container:
I'm not sure how to continue debugging the issues; is there some sort of tar-level logging I could enable? |
Thanks @devinrsmith, this is helpful. On a hunch, can you try moving the tar file to /tmp and scanning it from there, and/or creating a new system user (without "dev" in the username) and scanning from there? (Please also double check your tar file to make sure it is a real tar file -- during testing we thought we had reproduced the problem but we were scanning something that wasn't a real tar file because we had not followed redirects with curl.) Thank you! |
We've got a workflow that involves creating an SBOM from a tarball. It was working as of 0.105.1; on 1.0.1, there are no packages found. I'm not sure if the specifics of this tarball matter; but it can be found at https://github.com/deephaven/deephaven-core/releases/download/v0.33.2/server-jetty-0.33.2.tar
Notice 326 packages on the former, 0 packages on the latter. Happy to provide more details if it would help.
The text was updated successfully, but these errors were encountered: