Skip to content

Cyclone report doesn't contains vulnerability array #11789

Discussion options

You must be logged in to vote

If the vulnerability array is missing in the SBOM, then you will see 0 vulnerabilities in Defect Dojo.

cdxgen by itself doesn't scan for vulnerabilities, it only generates the bill of material. If you're looking to scan also for vulnerabilities and include those in the SBOM, you'll need something like trivy or grype.

Here's the dosc which has an example with grype: https://docs.defectdojo.com/en/connecting_your_tools/parsers/file/cyclonedx/

Replies: 1 comment 3 replies

Comment options

You must be logged in to vote
3 replies
@jugalb-icpl
Comment options

@valentijnscholten
Comment options

Answer selected by mtesauro
@jugalb-icpl
Comment options

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants