osv-scanner icon indicating copy to clipboard operation
osv-scanner copied to clipboard

Remove dedicated SBOM flag in favor of `-L` and friends

Open G-Rath opened this issue 6 months ago • 2 comments

The --sbom flag was introduced while we were still figuring out how to handle scanning in different contexts and stuff like resolving patterns to files (like with requirements.txt) rather than just 1:1 mappings.

Nowadays we shouldn't need a dedicated flag (in fact right now you can use -L instead of -sbom and get the same results), and it makes it hard to move forward with #1846 due to its slightly special-but-unneeded behaviour.

We should start by deprecating the --sbom flag in favor of -L, and go from there

G-Rath avatar Jun 16 '25 02:06 G-Rath

This issue has not had any activity for 60 days and will be automatically closed in two weeks

See https://github.com/google/osv-scanner/blob/main/CONTRIBUTING.md for how to contribute a PR if you're interested in helping out.

github-actions[bot] avatar Aug 21 '25 23:08 github-actions[bot]

Image

G-Rath avatar Aug 21 '25 23:08 G-Rath