Thanks to visit codestin.com
Credit goes to github.com

Skip to content

Syft generates different CycloneDX SBOMs from conan.lock depending on operating system #4242

@eugenhoffmann

Description

@eugenhoffmann

What happened:
Different CycloneDX SBOMs are generated from the same conan.lock file depending on the used operating system windows/linux.

  • Windows generated SBOM does not contain "conan.lock" component in the component list
  • Linux generated SBOM contains "conan.lock" component in component list.
Image

What you expected to happen:
Both, Linux and Windows generated SBOMs should not contain "conan.lock" component in component list

Steps to reproduce the issue:

  1. Use conan.lock file (rename it to conan.lock first)
  2. Run the command on windows and on linux: syft conan.lock --output --cyclonedx-xml=sbom.xml
  3. Results:

Anything else we need to know?:

Environment:

  • Output of syft version:

    • Windows:
      • Application: syft
      • Version: 1.33.0
      • BuildDate: 2025-09-15T20:38:16Z
      • GitCommit: b87b919
      • GitDescription: v1.33.0
      • Platform: windows/amd64
      • GoVersion: go1.24.7
      • Compiler: gc
      • SchemaVersion: 16.0.39
    • Linux:
      • Application: syft
      • Version: 1.33.0
      • BuildDate: 2025-09-15T20:38:16Z
      • GitCommit: b87b919
      • GitDescription: v1.33.0
      • Platform: linux/amd64
      • GoVersion: go1.24.7
      • Compiler: gc
      • SchemaVersion: 16.0.39
  • OS (e.g: cat /etc/os-release or similar):

    • windows/amd64
    • linux/amd64

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workinggood-first-issueGood for newcomerswindowsregarding the windows OS

    Type

    No type

    Projects

    Status

    Ready

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions