sonar-cryptography
sonar-cryptography copied to clipboard
Logged statistic about the amount of detected assets is different form the number of assets in the CBOM
Given for example keycloak (#9c2825eb0e64aa7ea40b8dc3605d37046f6a24cb), when scanned the logged statistic would indicated that 94 assets were detected. However the cbom (attached) contains 138 finding.