aquasecurity/trivy

enhancement(cyclonedx): use `component.evidence.occurrences.location` for filapaths and linenumber

Open

#9,832 建立於 2025年11月20日

在 GitHub 查看
 (0 留言) (1 反應) (0 負責人)Go (35,000 star) (371 fork)batch import
help wanted

描述

Description

In CycloneDX 1.5, the location and line fields were added under component.evidence.occurrences. These are fields we can use in Trivy:

  1. location can be used instead of property.filePath
  2. line can be used if Trivy supports detecting line numbers for that file

Example:

https://github.com/CycloneDX/cyclonedx-go/blob/72e4629d580624c7d6bd815e2d209a0a62d08047/testdata/valid-evidence.json#L74-L77

Discussed in https://github.com/aquasecurity/trivy/discussions/9823

貢獻者指南