Replies: 2 comments
-
Do you mean ZIP for Java archives? |
Beta Was this translation helpful? Give feedback.
0 replies
-
No, just ZIPs (see attached example for reproduction). I have to create SBOMs for deep nested directory structures containing ZIPs, EARs, WARs and JARs. These archives are often nested within each other (e.g. ZIP in ZIP, JAR in ZIP,...). At the beginning, I didn't even notice that ZIP files were being skipped, since there is no appropriate log message. It would be nice if Trivy includes the contents of ZIP files when creating an SBOM. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
Hello,
I'm creating SBOMs via rootfs. JARs, WARs and EARs are automatically and recursively searched/unpacked. ZIPs, on the other hand, are skipped/ignored. Is this behavior intentional or this a bug?
Regards, Aline
Target
SBOM
Scanner
None
Beta Was this translation helpful? Give feedback.
All reactions