trivy icon indicating copy to clipboard operation
trivy copied to clipboard

feat(sbom): add manufacturer field to CycloneDX tools metadata

Open krikera opened this issue 6 months ago • 8 comments

Description

The manufacturer field improves human readability while keeping the existing group field for technical namespace purposes.

  • Add ToolManufacturer constant with value 'Aqua Security Software Ltd.'
  • Include manufacturer field in CycloneDX metadata tools component
  • Update test to expect the new manufacturer field

Related issues

  • Close #9014

Checklist

  • [✅ ] I've read the guidelines for contributing to this repository.
  • [✅ ] I've followed the conventions in the PR title.
  • [✅ ] I've added tests that prove my fix is effective or that my feature works.
  • [ ] I've updated the documentation with the relevant information (if needed).
  • [ ] I've added usage information (if the PR introduces new options)
  • [ ] I've included a "before" and "after" example to the description (if the PR is a user interface change).

krikera avatar Jun 09 '25 18:06 krikera

CLA assistant check
All committers have signed the CLA.

CLAassistant avatar Jun 09 '25 18:06 CLAassistant

CLA assistant check
Thank you for your submission! We really appreciate it. Like many open source projects, we ask that you sign our Contributor License Agreement before we can accept your contribution.
You have signed the CLA already but the status is still pending? Let us recheck it.

CLAassistant avatar Jun 09 '25 18:06 CLAassistant

Hello @krikera Can you update integration (mage test:updateGolden command may help) and unit tests?

DmitriyLewen avatar Jun 10 '25 04:06 DmitriyLewen

Hey @DmitriyLewen. Yeah sure!

krikera avatar Jun 10 '25 04:06 krikera

Actually, I found that mage test:updateGolden currently updates a lot of irrelevant files. We need to improve it. In this case, it might be faster to make the changes manually.

knqyf263 avatar Jun 10 '25 06:06 knqyf263

Hey @knqyf263 Should I update the integration test?

krikera avatar Jun 10 '25 14:06 krikera

You just need to update golden files. Please let us know if you need help.

knqyf263 avatar Jun 10 '25 14:06 knqyf263

Thanks. Yeah sure.

krikera avatar Jun 10 '25 14:06 krikera

@krikera Do you have time to fix the tests? If not, @DmitriyLewen can you please take it over? We need to complete it for v0.64.0.

knqyf263 avatar Jun 26 '25 07:06 knqyf263

okay, i will do that at this week

DmitriyLewen avatar Jun 26 '25 07:06 DmitriyLewen