Skip to content

fix: omit goarch/goos PURL qualifiers from mod SBOMs - #746

Open
arpitjain099 wants to merge 1 commit into
CycloneDX:mainfrom
arpitjain099:chore/mod-purl-no-platform
Open

fix: omit goarch/goos PURL qualifiers from mod SBOMs#746
arpitjain099 wants to merge 1 commit into
CycloneDX:mainfrom
arpitjain099:chore/mod-purl-no-platform

Conversation

@arpitjain099

Copy link
Copy Markdown

Fixes #662. A mod SBOM is platform independent, but its component PURLs currently carry goarch/goos from the build host, so the same module produces different PURLs on different machines and PURL-based matching or dedup across SBOMs breaks. This adds a platform-neutral module PURL (Module.ModulePackageURL and a WithModulePURL converter option) and uses it in the mod generator for both the main component and dependencies, matching what the app and bin generators already do for their dependency graphs and what nscuro noted back in #148. app and bin themselves are untouched, so they still emit goos/goarch on the build-environment main component, and -short-purls still wins when it's set.

I regenerated the mod snapshots with UPDATE_SNAPSHOTS=true; the only diff is goarch/goos dropping off the mod PURLs, and go test ./pkg/generate/... plus the internal sbom/gomod tests stay green (app and bin included). Thanks for taking a look.

Module SBOMs are platform independent, so embedding the build host's
GOOS/GOARCH in component PURLs is incorrect: the same module produces
different PURLs on different machines, which breaks PURL-based matching
and deduplication across SBOMs.

Add a platform-neutral Module.ModulePackageURL and a WithModulePURL
converter option, and use it in the mod generator for the main
component and dependencies. The app and bin generators are left
untouched, so they still emit goos/goarch on the build-environment
main component. -short-purls still takes precedence when enabled.

Fixes CycloneDX#662

Signed-off-by: Arpit Jain <arpitjain099@gmail.com>
@arpitjain099
arpitjain099 requested a review from a team as a code owner July 3, 2026 23:00
@codacy-production

Copy link
Copy Markdown

Up to standards ✅

🟢 Issues 0 issues

Results:
0 new issues

View in Codacy

🟢 Metrics 0 complexity · 0 duplication

Metric Results
Complexity 0
Duplication 0

View in Codacy

NEW Get contextual insights on your PRs based on Codacy's metrics, along with PR and Jira context, without leaving GitHub. Enable AI reviewer
TIP This summary will be updated as you push new changes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

The GOOS and GOARCH PURL qualifiers should not be included in mod SBOM

1 participant