-
Notifications
You must be signed in to change notification settings - Fork 76
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Command to output SBOM #194
base: main
Are you sure you want to change the base?
Conversation
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Looks good and validated locally.... could use some tests though :)
zender [projects/oss/nancy] pr/194? → go list -json -m all | ./nancy sbom [335b210]
<?xml version="1.0" encoding="UTF-8"?>
<bom xmlns="http://cyclonedx.org/schema/bom/1.1" xmlns:v="http://cyclonedx.org/schema/ext/vulnerability/1.0" version="1">
<components>
<component type="library" bom-ref="pkg:golang/cloud.google.com/[email protected]">
<name>go</name>
<version>0.46.3</version>
<purl>pkg:golang/cloud.google.com/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/cloud.google.com/go/[email protected]">
<name>bigquery</name>
<version>1.0.1</version>
<purl>pkg:golang/cloud.google.com/go/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/cloud.google.com/go/[email protected]">
<name>datastore</name>
<version>1.0.0</version>
<purl>pkg:golang/cloud.google.com/go/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/cloud.google.com/go/[email protected]">
<name>firestore</name>
<version>1.1.0</version>
<purl>pkg:golang/cloud.google.com/go/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/cloud.google.com/go/[email protected]">
<name>pubsub</name>
<version>1.0.1</version>
<purl>pkg:golang/cloud.google.com/go/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/cloud.google.com/go/[email protected]">
<name>storage</name>
<version>1.0.0</version>
<purl>pkg:golang/cloud.google.com/go/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/dmitri.shuralyov.com/gpu/[email protected]">
<name>mtl</name>
<version>0.0.0-20190408044501-666a987793e9</version>
<purl>pkg:golang/dmitri.shuralyov.com/gpu/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/burntsushi/[email protected]">
<name>toml</name>
<version>0.3.1</version>
<purl>pkg:golang/github.com/burntsushi/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/burntsushi/[email protected]">
<name>xgb</name>
<version>0.0.0-20160522181843-27f122750802</version>
<purl>pkg:golang/github.com/burntsushi/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/flaque/[email protected]">
<name>filet</name>
<version>0.0.0-20190209224823-fc4d33cfcf93</version>
<purl>pkg:golang/github.com/flaque/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/masterminds/[email protected]">
<name>semver</name>
<version>0.0.0-20190925130524-317e8cce5480</version>
<purl>pkg:golang/github.com/masterminds/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/masterminds/[email protected]">
<name>vcs</name>
<version>1.13.1</version>
<purl>pkg:golang/github.com/masterminds/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/oneofone/[email protected]">
<name>xxhash</name>
<version>1.2.2</version>
<purl>pkg:golang/github.com/oneofone/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/alecthomas/[email protected]">
<name>template</name>
<version>0.0.0-20160405071501-a0175ee3bccc</version>
<purl>pkg:golang/github.com/alecthomas/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/alecthomas/[email protected]">
<name>units</name>
<version>0.0.0-20151022065526-2efee857e7cf</version>
<purl>pkg:golang/github.com/alecthomas/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/armon/[email protected]">
<name>circbuf</name>
<version>0.0.0-20150827004946-bbbad097214e</version>
<purl>pkg:golang/github.com/armon/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/armon/[email protected]">
<name>consul-api</name>
<version>0.0.0-20180202201655-eb2c6b5be1b6</version>
<purl>pkg:golang/github.com/armon/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/armon/[email protected]">
<name>go-metrics</name>
<version>0.0.0-20180917152333-f0300d1749da</version>
<purl>pkg:golang/github.com/armon/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/armon/[email protected]">
<name>go-radix</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/armon/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/beevik/[email protected]">
<name>etree</name>
<version>1.1.0</version>
<purl>pkg:golang/github.com/beevik/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/beorn7/[email protected]">
<name>perks</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/beorn7/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/bgentry/[email protected]">
<name>speakeasy</name>
<version>0.1.0</version>
<purl>pkg:golang/github.com/bgentry/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/bketelsen/[email protected]">
<name>crypt</name>
<version>0.0.3-0.20200106085610-5cbc8cc4026c</version>
<purl>pkg:golang/github.com/bketelsen/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/boltdb/[email protected]">
<name>bolt</name>
<version>1.3.1</version>
<purl>pkg:golang/github.com/boltdb/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/census-instrumentation/[email protected]">
<name>opencensus-proto</name>
<version>0.2.1</version>
<purl>pkg:golang/github.com/census-instrumentation/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/cespare/[email protected]">
<name>xxhash</name>
<version>1.1.0</version>
<purl>pkg:golang/github.com/cespare/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/client9/[email protected]">
<name>misspell</name>
<version>0.3.4</version>
<purl>pkg:golang/github.com/client9/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/common-nighthawk/[email protected]">
<name>go-figure</name>
<version>0.0.0-20200609044655-c4b36f998cf2</version>
<purl>pkg:golang/github.com/common-nighthawk/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/coreos/[email protected]">
<name>bbolt</name>
<version>1.3.2</version>
<purl>pkg:golang/github.com/coreos/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/coreos/[email protected]">
<name>etcd</name>
<version>3.3.24</version>
<purl>pkg:golang/github.com/coreos/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/coreos/[email protected]">
<name>go-semver</name>
<version>0.3.0</version>
<purl>pkg:golang/github.com/coreos/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/coreos/[email protected]">
<name>go-systemd</name>
<version>0.0.0-20190321100706-95778dfbb74e</version>
<purl>pkg:golang/github.com/coreos/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/coreos/[email protected]">
<name>pkg</name>
<version>0.0.0-20180928190104-399ea9e2e55f</version>
<purl>pkg:golang/github.com/coreos/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/cpuguy83/go-md2man/[email protected]">
<name>v2</name>
<version>2.0.0</version>
<purl>pkg:golang/github.com/cpuguy83/go-md2man/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/creack/[email protected]">
<name>pty</name>
<version>1.1.9</version>
<purl>pkg:golang/github.com/creack/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/davecgh/[email protected]">
<name>go-spew</name>
<version>1.1.1</version>
<purl>pkg:golang/github.com/davecgh/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/dgrijalva/[email protected]">
<name>jwt-go</name>
<version>3.2.0</version>
<purl>pkg:golang/github.com/dgrijalva/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/dgryski/[email protected]">
<name>go-sip13</name>
<version>0.0.0-20181026042036-e10d5fee7954</version>
<purl>pkg:golang/github.com/dgryski/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/envoyproxy/[email protected]">
<name>go-control-plane</name>
<version>0.9.1-0.20191026205805-5f8ba28d4473</version>
<purl>pkg:golang/github.com/envoyproxy/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/envoyproxy/[email protected]">
<name>protoc-gen-validate</name>
<version>0.1.0</version>
<purl>pkg:golang/github.com/envoyproxy/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/fatih/[email protected]">
<name>color</name>
<version>1.7.0</version>
<purl>pkg:golang/github.com/fatih/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/fsnotify/[email protected]">
<name>fsnotify</name>
<version>1.4.9</version>
<purl>pkg:golang/github.com/fsnotify/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/ghodss/[email protected]">
<name>yaml</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/ghodss/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/go-gl/[email protected]">
<name>glfw</name>
<version>0.0.0-20190409004039-e6da0acd62b1</version>
<purl>pkg:golang/github.com/go-gl/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/go-kit/[email protected]">
<name>kit</name>
<version>0.8.0</version>
<purl>pkg:golang/github.com/go-kit/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/go-logfmt/[email protected]">
<name>logfmt</name>
<version>0.4.0</version>
<purl>pkg:golang/github.com/go-logfmt/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/go-stack/[email protected]">
<name>stack</name>
<version>1.8.0</version>
<purl>pkg:golang/github.com/go-stack/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/gogo/[email protected]">
<name>protobuf</name>
<version>1.2.1</version>
<purl>pkg:golang/github.com/gogo/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/golang/[email protected]">
<name>dep</name>
<version>0.5.4</version>
<purl>pkg:golang/github.com/golang/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/golang/[email protected]">
<name>glog</name>
<version>0.0.0-20160126235308-23def4e6c14b</version>
<purl>pkg:golang/github.com/golang/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/golang/[email protected]">
<name>groupcache</name>
<version>0.0.0-20190129154638-5b532d6fd5ef</version>
<purl>pkg:golang/github.com/golang/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/golang/[email protected]">
<name>mock</name>
<version>1.3.1</version>
<purl>pkg:golang/github.com/golang/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/golang/[email protected]">
<name>protobuf</name>
<version>1.4.2</version>
<purl>pkg:golang/github.com/golang/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/google/[email protected]">
<name>btree</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/google/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/google/[email protected]">
<name>go-cmp</name>
<version>0.5.0</version>
<purl>pkg:golang/github.com/google/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/google/[email protected]">
<name>martian</name>
<version>2.1.0</version>
<purl>pkg:golang/github.com/google/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/google/[email protected]">
<name>pprof</name>
<version>0.0.0-20190515194954-54271f7e092f</version>
<purl>pkg:golang/github.com/google/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/google/[email protected]">
<name>renameio</name>
<version>0.1.0</version>
<purl>pkg:golang/github.com/google/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/googleapis/gax-go/[email protected]">
<name>v2</name>
<version>2.0.5</version>
<purl>pkg:golang/github.com/googleapis/gax-go/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/gopherjs/[email protected]">
<name>gopherjs</name>
<version>0.0.0-20181017120253-0766667cb4d1</version>
<purl>pkg:golang/github.com/gopherjs/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/gorilla/[email protected]">
<name>websocket</name>
<version>1.4.2</version>
<purl>pkg:golang/github.com/gorilla/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/grpc-ecosystem/[email protected]">
<name>go-grpc-middleware</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/grpc-ecosystem/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/grpc-ecosystem/[email protected]">
<name>go-grpc-prometheus</name>
<version>1.2.0</version>
<purl>pkg:golang/github.com/grpc-ecosystem/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/grpc-ecosystem/[email protected]">
<name>grpc-gateway</name>
<version>1.9.0</version>
<purl>pkg:golang/github.com/grpc-ecosystem/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/consul/[email protected]">
<name>api</name>
<version>1.1.0</version>
<purl>pkg:golang/github.com/hashicorp/consul/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/consul/[email protected]">
<name>sdk</name>
<version>0.1.1</version>
<purl>pkg:golang/github.com/hashicorp/consul/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/[email protected]">
<name>errwrap</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/hashicorp/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/[email protected]">
<name>go-cleanhttp</name>
<version>0.5.1</version>
<purl>pkg:golang/github.com/hashicorp/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/[email protected]">
<name>go-immutable-radix</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/hashicorp/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/[email protected]">
<name>go-msgpack</name>
<version>0.5.3</version>
<purl>pkg:golang/github.com/hashicorp/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/[email protected]">
<name>go-multierror</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/hashicorp/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/[email protected]">
<name>go-rootcerts</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/hashicorp/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/[email protected]">
<name>go-sockaddr</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/hashicorp/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/[email protected]">
<name>go-syslog</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/hashicorp/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/[email protected]">
<name>go-uuid</name>
<version>1.0.1</version>
<purl>pkg:golang/github.com/hashicorp/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/[email protected]">
<name>go.net</name>
<version>0.0.1</version>
<purl>pkg:golang/github.com/hashicorp/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/[email protected]">
<name>golang-lru</name>
<version>0.5.1</version>
<purl>pkg:golang/github.com/hashicorp/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/[email protected]">
<name>hcl</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/hashicorp/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/[email protected]">
<name>logutils</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/hashicorp/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/[email protected]">
<name>mdns</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/hashicorp/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/[email protected]">
<name>memberlist</name>
<version>0.1.3</version>
<purl>pkg:golang/github.com/hashicorp/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/hashicorp/[email protected]">
<name>serf</name>
<version>0.8.2</version>
<purl>pkg:golang/github.com/hashicorp/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/inconshreveable/[email protected]">
<name>mousetrap</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/inconshreveable/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/jarcoal/[email protected]">
<name>httpmock</name>
<version>1.0.5</version>
<purl>pkg:golang/github.com/jarcoal/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/jedib0t/go-pretty/[email protected]">
<name>v6</name>
<version>6.0.4</version>
<purl>pkg:golang/github.com/jedib0t/go-pretty/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/jmank88/[email protected]">
<name>nuts</name>
<version>0.4.0</version>
<purl>pkg:golang/github.com/jmank88/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/jonboulle/[email protected]">
<name>clockwork</name>
<version>0.1.0</version>
<purl>pkg:golang/github.com/jonboulle/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/json-iterator/[email protected]">
<name>go</name>
<version>1.1.6</version>
<purl>pkg:golang/github.com/json-iterator/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/jstemmer/[email protected]">
<name>go-junit-report</name>
<version>0.0.0-20190106144839-af01ea7f8024</version>
<purl>pkg:golang/github.com/jstemmer/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/jtolds/[email protected]">
<name>gls</name>
<version>4.20.0</version>
<purl>pkg:golang/github.com/jtolds/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/julienschmidt/[email protected]">
<name>httprouter</name>
<version>1.2.0</version>
<purl>pkg:golang/github.com/julienschmidt/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/kisielk/[email protected]">
<name>errcheck</name>
<version>1.1.0</version>
<purl>pkg:golang/github.com/kisielk/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/kisielk/[email protected]">
<name>gotool</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/kisielk/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/konsorten/[email protected]">
<name>go-windows-terminal-sequences</name>
<version>1.0.3</version>
<purl>pkg:golang/github.com/konsorten/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/kr/[email protected]">
<name>fs</name>
<version>0.1.0</version>
<purl>pkg:golang/github.com/kr/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/kr/[email protected]">
<name>logfmt</name>
<version>0.0.0-20140226030751-b84e30acd515</version>
<purl>pkg:golang/github.com/kr/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/kr/[email protected]">
<name>pretty</name>
<version>0.1.0</version>
<purl>pkg:golang/github.com/kr/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/kr/[email protected]">
<name>pty</name>
<version>1.1.1</version>
<purl>pkg:golang/github.com/kr/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/kr/[email protected]">
<name>text</name>
<version>0.2.0</version>
<purl>pkg:golang/github.com/kr/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/logrusorgru/[email protected]">
<name>aurora</name>
<version>2.0.3</version>
<purl>pkg:golang/github.com/logrusorgru/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/magiconair/[email protected]">
<name>properties</name>
<version>1.8.1</version>
<purl>pkg:golang/github.com/magiconair/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/mattn/[email protected]">
<name>go-colorable</name>
<version>0.0.9</version>
<purl>pkg:golang/github.com/mattn/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/mattn/[email protected]">
<name>go-isatty</name>
<version>0.0.3</version>
<purl>pkg:golang/github.com/mattn/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/mattn/[email protected]">
<name>go-runewidth</name>
<version>0.0.9</version>
<purl>pkg:golang/github.com/mattn/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/matttproud/[email protected]">
<name>golang_protobuf_extensions</name>
<version>1.0.1</version>
<purl>pkg:golang/github.com/matttproud/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/miekg/[email protected]">
<name>dns</name>
<version>1.0.14</version>
<purl>pkg:golang/github.com/miekg/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/mitchellh/[email protected]">
<name>cli</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/mitchellh/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/mitchellh/[email protected]">
<name>go-homedir</name>
<version>1.1.0</version>
<purl>pkg:golang/github.com/mitchellh/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/mitchellh/[email protected]">
<name>go-testing-interface</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/mitchellh/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/mitchellh/[email protected]">
<name>gox</name>
<version>0.4.0</version>
<purl>pkg:golang/github.com/mitchellh/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/mitchellh/[email protected]">
<name>iochan</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/mitchellh/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/mitchellh/[email protected]">
<name>mapstructure</name>
<version>1.3.3</version>
<purl>pkg:golang/github.com/mitchellh/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/modern-go/[email protected]">
<name>concurrent</name>
<version>0.0.0-20180306012644-bacd9c7ef1dd</version>
<purl>pkg:golang/github.com/modern-go/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/modern-go/[email protected]">
<name>reflect2</name>
<version>1.0.1</version>
<purl>pkg:golang/github.com/modern-go/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/mwitkow/[email protected]">
<name>go-conntrack</name>
<version>0.0.0-20161129095857-cc309e4a2223</version>
<purl>pkg:golang/github.com/mwitkow/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/niemeyer/[email protected]">
<name>pretty</name>
<version>0.0.0-20200227124842-a10e7caefd8e</version>
<purl>pkg:golang/github.com/niemeyer/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/nightlyone/[email protected]">
<name>lockfile</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/nightlyone/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/oklog/[email protected]">
<name>ulid</name>
<version>1.3.1</version>
<purl>pkg:golang/github.com/oklog/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/package-url/[email protected]">
<name>packageurl-go</name>
<version>0.1.0</version>
<purl>pkg:golang/github.com/package-url/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/pascaldekloe/[email protected]">
<name>goe</name>
<version>0.0.0-20180627143212-57f6aae5913c</version>
<purl>pkg:golang/github.com/pascaldekloe/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/pelletier/[email protected]">
<name>go-toml</name>
<version>1.8.0</version>
<purl>pkg:golang/github.com/pelletier/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/pkg/[email protected]">
<name>errors</name>
<version>0.9.1</version>
<purl>pkg:golang/github.com/pkg/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/pkg/[email protected]">
<name>profile</name>
<version>1.2.1</version>
<purl>pkg:golang/github.com/pkg/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/pkg/[email protected]">
<name>sftp</name>
<version>1.10.1</version>
<purl>pkg:golang/github.com/pkg/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/pmezard/[email protected]">
<name>go-difflib</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/pmezard/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/posener/[email protected]">
<name>complete</name>
<version>1.1.1</version>
<purl>pkg:golang/github.com/posener/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/prometheus/[email protected]">
<name>client_golang</name>
<version>0.9.3</version>
<purl>pkg:golang/github.com/prometheus/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/prometheus/[email protected]">
<name>client_model</name>
<version>0.0.0-20190812154241-14fe0d1b01d4</version>
<purl>pkg:golang/github.com/prometheus/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/prometheus/[email protected]">
<name>common</name>
<version>0.4.0</version>
<purl>pkg:golang/github.com/prometheus/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/prometheus/[email protected]">
<name>procfs</name>
<version>0.0.0-20190507164030-5867b95ac084</version>
<purl>pkg:golang/github.com/prometheus/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/prometheus/[email protected]">
<name>tsdb</name>
<version>0.7.1</version>
<purl>pkg:golang/github.com/prometheus/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/recoilme/[email protected]">
<name>pudge</name>
<version>1.0.3</version>
<purl>pkg:golang/github.com/recoilme/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/rogpeppe/[email protected]">
<name>fastuuid</name>
<version>0.0.0-20150106093220-6724a57986af</version>
<purl>pkg:golang/github.com/rogpeppe/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/rogpeppe/[email protected]">
<name>go-internal</name>
<version>1.3.0</version>
<purl>pkg:golang/github.com/rogpeppe/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/russross/blackfriday/[email protected]">
<name>v2</name>
<version>2.0.1</version>
<purl>pkg:golang/github.com/russross/blackfriday/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/ryanuber/[email protected]">
<name>columnize</name>
<version>0.0.0-20160712163229-9b3edd62028f</version>
<purl>pkg:golang/github.com/ryanuber/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/sdboyer/[email protected]">
<name>constext</name>
<version>0.0.0-20170321163424-836a14457353</version>
<purl>pkg:golang/github.com/sdboyer/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/sean-/[email protected]">
<name>seed</name>
<version>0.0.0-20170313163322-e2103e2c3529</version>
<purl>pkg:golang/github.com/sean-/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/shopspring/[email protected]">
<name>decimal</name>
<version>1.2.0</version>
<purl>pkg:golang/github.com/shopspring/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/shurcool/[email protected]">
<name>sanitized_anchor_name</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/shurcool/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/sirupsen/[email protected]">
<name>logrus</name>
<version>1.6.0</version>
<purl>pkg:golang/github.com/sirupsen/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/smartystreets/[email protected]">
<name>assertions</name>
<version>0.0.0-20180927180507-b2de0cb4f26d</version>
<purl>pkg:golang/github.com/smartystreets/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/smartystreets/[email protected]">
<name>goconvey</name>
<version>1.6.4</version>
<purl>pkg:golang/github.com/smartystreets/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/soheilhy/[email protected]">
<name>cmux</name>
<version>0.1.4</version>
<purl>pkg:golang/github.com/soheilhy/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/sonatype-nexus-community/[email protected]">
<name>go-sona-types</name>
<version>0.0.7</version>
<purl>pkg:golang/github.com/sonatype-nexus-community/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/spaolacci/[email protected]">
<name>murmur3</name>
<version>0.0.0-20180118202830-f09979ecbc72</version>
<purl>pkg:golang/github.com/spaolacci/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/spf13/[email protected]">
<name>afero</name>
<version>1.3.4</version>
<purl>pkg:golang/github.com/spf13/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/spf13/[email protected]">
<name>cast</name>
<version>1.3.1</version>
<purl>pkg:golang/github.com/spf13/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/spf13/[email protected]">
<name>cobra</name>
<version>1.0.0</version>
<purl>pkg:golang/github.com/spf13/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/spf13/[email protected]">
<name>jwalterweatherman</name>
<version>1.1.0</version>
<purl>pkg:golang/github.com/spf13/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/spf13/[email protected]">
<name>pflag</name>
<version>1.0.5</version>
<purl>pkg:golang/github.com/spf13/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/spf13/[email protected]">
<name>viper</name>
<version>1.7.1</version>
<purl>pkg:golang/github.com/spf13/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/stretchr/[email protected]">
<name>objx</name>
<version>0.1.1</version>
<purl>pkg:golang/github.com/stretchr/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/stretchr/[email protected]">
<name>testify</name>
<version>1.6.1</version>
<purl>pkg:golang/github.com/stretchr/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/subosito/[email protected]">
<name>gotenv</name>
<version>1.2.0</version>
<purl>pkg:golang/github.com/subosito/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/tmc/[email protected]">
<name>grpc-websocket-proxy</name>
<version>0.0.0-20190109142713-0ad062ec5ee5</version>
<purl>pkg:golang/github.com/tmc/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/ugorji/[email protected]">
<name>go</name>
<version>1.1.4</version>
<purl>pkg:golang/github.com/ugorji/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/xiang90/[email protected]">
<name>probing</name>
<version>0.0.0-20190116061207-43a291ad63a2</version>
<purl>pkg:golang/github.com/xiang90/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/xordataexchange/[email protected]">
<name>crypt</name>
<version>0.0.3-0.20170626215501-b2862e3d0a77</version>
<purl>pkg:golang/github.com/xordataexchange/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/go.etcd.io/[email protected]">
<name>bbolt</name>
<version>1.3.2</version>
<purl>pkg:golang/go.etcd.io/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/[email protected]">
<name>go.opencensus.io</name>
<version>0.22.0</version>
<purl>pkg:golang/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/go.uber.org/[email protected]">
<name>atomic</name>
<version>1.4.0</version>
<purl>pkg:golang/go.uber.org/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/go.uber.org/[email protected]">
<name>multierr</name>
<version>1.1.0</version>
<purl>pkg:golang/go.uber.org/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/go.uber.org/[email protected]">
<name>zap</name>
<version>1.10.0</version>
<purl>pkg:golang/go.uber.org/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/golang.org/x/[email protected]">
<name>crypto</name>
<version>0.0.0-20190820162420-60c769a6c586</version>
<purl>pkg:golang/golang.org/x/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/golang.org/x/[email protected]">
<name>exp</name>
<version>0.0.0-20191030013958-a1ab85dbe136</version>
<purl>pkg:golang/golang.org/x/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/golang.org/x/[email protected]">
<name>image</name>
<version>0.0.0-20190802002840-cff245a6509b</version>
<purl>pkg:golang/golang.org/x/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/golang.org/x/[email protected]">
<name>lint</name>
<version>0.0.0-20190930215403-16217165b5de</version>
<purl>pkg:golang/golang.org/x/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/golang.org/x/[email protected]">
<name>mobile</name>
<version>0.0.0-20190719004257-d2bd2a29d028</version>
<purl>pkg:golang/golang.org/x/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/golang.org/x/[email protected]">
<name>mod</name>
<version>0.1.0</version>
<purl>pkg:golang/golang.org/x/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/golang.org/x/[email protected]">
<name>net</name>
<version>0.0.0-20190620200207-3b0461eec859</version>
<purl>pkg:golang/golang.org/x/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/golang.org/x/[email protected]">
<name>oauth2</name>
<version>0.0.0-20190604053449-0f29369cfe45</version>
<purl>pkg:golang/golang.org/x/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/golang.org/x/[email protected]">
<name>sync</name>
<version>0.0.0-20200625203802-6e8e738ad208</version>
<purl>pkg:golang/golang.org/x/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/golang.org/x/[email protected]">
<name>sys</name>
<version>0.0.0-20200824131525-c12d262b63d8</version>
<purl>pkg:golang/golang.org/x/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/golang.org/x/[email protected]">
<name>text</name>
<version>0.3.3</version>
<purl>pkg:golang/golang.org/x/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/golang.org/x/[email protected]">
<name>time</name>
<version>0.0.0-20190308202827-9d24e82272b4</version>
<purl>pkg:golang/golang.org/x/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/golang.org/x/[email protected]">
<name>tools</name>
<version>0.0.0-20191112195655-aa38f8e97acc</version>
<purl>pkg:golang/golang.org/x/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/golang.org/x/[email protected]">
<name>xerrors</name>
<version>0.0.0-20191204190536-9bdfabe68543</version>
<purl>pkg:golang/golang.org/x/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/google.golang.org/[email protected]">
<name>api</name>
<version>0.13.0</version>
<purl>pkg:golang/google.golang.org/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/google.golang.org/[email protected]">
<name>appengine</name>
<version>1.6.1</version>
<purl>pkg:golang/google.golang.org/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/google.golang.org/[email protected]">
<name>genproto</name>
<version>0.0.0-20200526211855-cb27e3aa2013</version>
<purl>pkg:golang/google.golang.org/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/google.golang.org/[email protected]">
<name>grpc</name>
<version>1.27.0</version>
<purl>pkg:golang/google.golang.org/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/google.golang.org/[email protected]">
<name>protobuf</name>
<version>1.25.0</version>
<purl>pkg:golang/google.golang.org/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/alecthomas/[email protected]">
<name>kingpin</name>
<version>2.2.6</version>
<purl>pkg:golang/github.com/alecthomas/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/go-check/[email protected]">
<name>check</name>
<version>1.0.0-20200227125254-8fa46927fb4f</version>
<purl>pkg:golang/github.com/go-check/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/go-errgo/[email protected]">
<name>errgo</name>
<version>2.1.0</version>
<purl>pkg:golang/github.com/go-errgo/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/go-playground/[email protected]">
<name>assert</name>
<version>1.2.1</version>
<purl>pkg:golang/github.com/go-playground/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/go-ini/[email protected]">
<name>ini</name>
<version>1.60.1</version>
<purl>pkg:golang/github.com/go-ini/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/go-resty/[email protected]">
<name>resty</name>
<version>1.12.0</version>
<purl>pkg:golang/github.com/go-resty/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/go-yaml/[email protected]">
<name>yaml</name>
<version>2.3.0</version>
<purl>pkg:golang/github.com/go-yaml/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/github.com/go-yaml/[email protected]">
<name>yaml</name>
<version>3.0.0-20200313102051-9f266ea9e77c</version>
<purl>pkg:golang/github.com/go-yaml/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/honnef.co/go/[email protected]">
<name>tools</name>
<version>0.0.1-2019.2.3</version>
<purl>pkg:golang/honnef.co/go/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
<component type="library" bom-ref="pkg:golang/rsc.io/[email protected]">
<name>binaryregexp</name>
<version>0.2.0</version>
<purl>pkg:golang/rsc.io/[email protected]</purl>
<v:vulnerabilities></v:vulnerabilities>
</component>
</components>
</bom>
Testing on this repo: https://github.com/sonatype-nexus-community/cyclonedx-sbom-examples $ go list -m all | nancy sbom > nancy-bom.xml
That's the resulting cyclonedx. When scanned w/ the CLI there are no vulns reported in IQ:
Compared to the same report submitted to IQ with Nancy directly: Looks like report from the cyclonedx ingestion doesn't have the 'v' in front of any of the versions while the direct Nancy submission does |
Kudos, SonarCloud Quality Gate passed! 0 Bugs No Coverage information |
Did this real quick, but this outputs an sbom to the command line
This pull request makes the following changes:
sbom
commandIt relates to the following issue #s:
cc @bhamail / @DarthHater / @ButterB0wl