Skip to content

SBOM export: per-component supplier and description from real enrichment sources #380

Description

@bomly-guy

Context

PR #364 raised SBOM export quality substantially (self-scan: CycloneDX 80.9/B, SPDX 78.2, NTIA-compliant, schema-clean in both formats). Two completeness fields remain empty by design: per-component supplier and description. Bomly does not fabricate them — heuristics like "supplier = PURL namespace" would put made-up assertions into a compliance artifact. This is also the one remaining EU-CRA profile error sbom-tools v0.1.22 reports against our output ("Direct dependency supplier (mandatory)", CRA Annex I, Part III / prEN 40000-1-3 [PRE-7-RQ-03]).

Proposal

Populate both fields during --enrich from sources that actually assert them:

  • deps.dev already serves package metadata for the ecosystems it covers; extend internal/matchers/depsdev to capture description and origin/publisher data plus VCS/homepage links, store them on sdk.Package (new fields — SDK contract change, released and pinned per the usual flow), and project them into both formats in internal/sbom/transform.go:
    • CycloneDX: component.supplier, component.description, externalReferences (vcs, website).
    • SPDX: PackageSupplier, PackageDescription (or PackageSummary), external references.
  • Registry-native matchers (npm metadata, etc.) can contribute where deps.dev has no coverage.
  • Emit only when a source asserts the data; absent stays absent.

Related (same completeness bucket, different source): CPE identifiers could be generated via the vendored syft CPE package and emitted as component.cpe / SPDX cpe23Type refs — worth considering in the same effort or a sibling issue.

Acceptance

  • bomly scan --enrich -o cyclonedx -o spdx fills supplier/description for packages the sources cover, in both formats.
  • No fabricated values for uncovered packages.
  • sbom-tools CRA validation of an enriched self-scan reports zero supplier errors for covered ecosystems; NTIA stays compliant; both formats stay schema-clean.
  • Docs: docs/SBOM.md "What Bomly puts in the SBOM" updated.

🤖 Generated with Claude Code

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions