cdxgen: BOMs from Docker image missing packages
Using cdxgen on a Docker image will generate BOM, but not correct one. Many of the packages installed in our python project is missing, compared to running cdxgen on the project directly.
Our Docker image has a workdir of \app, could this be an issue? Does cdxgen want a specific workdir to work correctly?
About this issue
- Original URL
- State: closed
- Created 2 years ago
- Comments: 21 (12 by maintainers)
Not a problem. Glad it worked!
@prabhu Now it works! I did not see that my previous log-snippet was badly formatted. Sorry!
@diblaze This helps. Yes, the site-packages inside .venv would be matching a range of patterns. Thank you. I will let you know once a new update is ready for testing.
Sadly I can not share the complete tree structure. However,
poetry.lockis directly underdapp. So it should find it. Also I checked our docker image,cdxgenis run byrootuser.For now the workaround is to run
cdxgenon the project before creating the image.@diblaze could you share the debug logs with version 4.0.13?