Hacktoberfest 2026: los issues que los mantenedores marcaron para octubre, abiertos y aptos para principiantes. Explorar issues de Hacktoberfest

Bug: Dependency Trees uses dependencies[0] as root instead of metadata.component.bom-ref

Abierto
#5,745 0 comentarios 0 reacciones 0 asignados Ver en GitHub

Los mantenedores suelen responder en 1 día

@faystmax ya está trabajando en esto.

Desde el 3/10/2026.

  • #5749 de @faystmax — abierto

Evaluación

Dificultad
4/5
Tiempo estimado
3-5 días
Aptitud para principiantes
68/100
Tipo de issue
Error
Claridad
Bastante claro
Estado de actividad
Activo
Stack tecnológico
typescript

Línea de trabajo

Read spring-boot-admin-server-ui/src/main/frontend/views/instances/sbomdependencytrees/sbomUtils.ts and tree.vue to trace how the SBOM root and dependency records reach normalizeData(). Use the provided root-not-first.cdx.json or mock instance.fetchSbom() in tree.spec.ts, then verify that metadata.component["bom-ref"] selects the root regardless of dependency order and that reordered-root regression cases pass.

Escrito por el modelo de indexación a partir del texto del issue.

Descripción

Spring Boot Admin Server information

  • Version: 4.1.3
  • Spring Boot version: 4.1.1

Client information

  • Spring Boot versions: 3.5.10
  • SBOM format: CycloneDX JSON

Description

The Dependency Trees view selects the first entry in dependencies as the root. It does not use the component described by metadata.component["bom-ref"].

As a result, the UI can display only a library's subtree even though the SBOM contains the application's dependency graph. Reordering otherwise identical dependency records changes the displayed root and visible dependencies.

This is present in the 4.1.3 source and in master inspected on 2026-10-03. The normalization behavior was reproduced in isolation using the existing helper's executable logic; this is not a claim that a full SBA browser integration test was run.

Minimal input

Save as root-not-first.cdx.json:

{
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "version": 1,
  "metadata": {
    "component": { "type": "application", "bom-ref": "app", "name": "demo-app", "version": "1.0.0" }
  },
  "components": [
    { "type": "library", "bom-ref": "a", "name": "library-a", "version": "1.0.0" },
    { "type": "library", "bom-ref": "b", "name": "library-b", "version": "1.0.0" },
    { "type": "library", "bom-ref": "c", "name": "library-c", "version": "1.0.0" }
  ],
  "dependencies": [
    { "ref": "a", "dependsOn": ["c"] },
    { "ref": "app", "dependsOn": ["a", "b"] },
    { "ref": "b", "dependsOn": [] },
    { "ref": "c", "dependsOn": [] }
  ]
}

Reproduction

At helper level, pass the fixture's dependencies to normalizeData(). The result is rooted at a with child c. Move only the app record to index zero and repeat: the root becomes app and both a and b appear.

For UI reproduction, return the same document from the monitored application's SBOM endpoint (or mock instance.fetchSbom() in tree.spec.ts), then open Dependency Trees. Repeat with only the array order changed.

Actual normalized tree:

a
└── c

Expected tree:

app
├── a
│   └── c
└── b

The result should be independent of the order of dependencies records.

Cause

In sbomUtils.ts at 4.1.3, normalizeData() reads both the root's reference and its children from sbomDependencies[0].

In tree.vue at 4.1.3, fetchSbomDependencies() retains only res.data.dependencies, so the normalizer never receives the metadata root reference.

CycloneDX identifies dependency targets by bom-ref; metadata.component describes the component that the BOM is about. The consumer should not infer that component from array position. See the CycloneDX 1.6 schema.

Suggested fix and regression coverage

  • Pass metadata.component["bom-ref"] along with the dependency records, or pass the required parts of the SBOM document to the normalizer.
  • Select the root by exact, unmodified bom-ref, then look up its outgoing edges by ref.
  • Keep display-name normalization separate from graph identity.
  • Define a safe policy for absent metadata, absent root records and missing/empty dependency data; do not silently invent an application root from index zero.
  • Test reordered records, root first/middle/last, and metadata propagation through tree.vue.

There is a related independent problem: recursive expansion currently has no cycle detection. Selecting the correct root can expose a previously unreachable cycle, so the two fixes should be considered together. [Add the cycle issue link after creating it.]

Related reports

  • #5153 concerns missing dependency data / an undefined-index error; its discussion does not establish this ordering defect.
  • #5358 reports missing dependencies without a minimal example demonstrating root selection.
  • #3463 originally requested dependency graph visualization.

I would be happy to contribute a PR targeting master with regression tests.

Lenguaje dominante
Java
Estrellas
12.9k
Forks
3.2k
Merge medio
13 h 56 min
PR fusionados (30 d)
84

Preparar el entorno

Primeros pasos

  1. Lee el issue completo y luego la guía de contribución del proyecto.
  2. Comenta en el issue que vas a ocuparte — evita que dos personas hagan lo mismo.
  3. Haz un fork del repositorio y trabaja en una rama.
  4. Abre un pull request que haga referencia al número del issue.

Más de codecentric/spring-boot-admin

Todos los issues de codecentric/spring-boot-admin

Issues similares

Más issues de Java

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.