sonar-cryptography icon indicating copy to clipboard operation
sonar-cryptography copied to clipboard

Logged statistic about the amount of detected assets is different form the number of assets in the CBOM

Open n1ckl0sk0rtge opened this issue 9 months ago • 0 comments

Given for example keycloak (#9c2825eb0e64aa7ea40b8dc3605d37046f6a24cb), when scanned the logged statistic would indicated that 94 assets were detected. However the cbom (attached) contains 138 finding.

cbom.json

n1ckl0sk0rtge avatar Mar 21 '25 14:03 n1ckl0sk0rtge