Replies: 1 comment
-
|
Hello @candrews cyclonedx-go doesn't currently support 1.7. Related issue - #10185 Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Uh oh!
There was an error while loading. Please reload this page.
-
Description
Trivy doesn't currently support CycloneDX 1.7 SBOMs, failing with an error when an attempt is made to process one.
The CycloneDX 1.7 specification was published October 21, 2025: https://github.com/CycloneDX/specification/releases/tag/1.7
Example CycloneDX 1.7 SBOM:
merged.cdx.json
Desired Behavior
Trivy should support CycloneDX 1.7 SBOMs.
Actual Behavior
Reproduction Steps
Target
SBOM
Scanner
Vulnerability
Output Format
None
Mode
Standalone
Debug Output
Operating System
Linux
Version
Checklist
trivy clean --allBeta Was this translation helpful? Give feedback.
All reactions