When scanning an SPDX SBOM using osv-scanner 2.5.0 or 2.5.1, we essentially get all vulnerabilities ever registered for Golang's stdlib.
stdlib@v1.1.12 has the following known vulnerabilities:
GO-2021-0142: Unbounded read from invalid inputs in encoding/binary
Severity: 'N/A'; Minimal Fix Version: '1.13.15';
GO-2021-0154: Man-in-the-middle attack with SessionTicketsDisabled in crypto/tls
Severity: 'N/A'; Minimal Fix Version: '1.3.2';
GO-2021-0159: Request smuggling due to improper header parsing in net/http
Severity: 'N/A'; Minimal Fix Version: '1.4.3';
GO-2021-0163: Privilege escalation on Windows via malicious DLL in syscall
Severity: 'N/A'; Minimal Fix Version: '1.5.4';
...
GO-2026-6218: Avoid quadratic complexity in resolvePath in net/url
Severity: 'N/A'; Minimal Fix Version: '1.25.13';
The package, stdlib@v1.1.12 is nowhere to be found in the SBOM. Instead, stdlib@1.27.0 exists. When scanning the same SBOM using osv-scanner 2.4.0, no issues are reported.
The SBOM is generated using Docker (which in turn uses Syft).
Here's the stdlib entry in the SBOM:
To run osv-scanner I place the SBOMs in a directory and run:
go run "github.com/google/osv-scanner/v2/cmd/osv-scanner@v2.5.1" scan --no-ignore --format vertical ./sboms
go run "github.com/google/osv-scanner/v2/cmd/osv-scanner@v2.5.0" scan --no-ignore --format vertical ./sboms
go run "github.com/google/osv-scanner/v2/cmd/osv-scanner@v2.4.0" scan --no-ignore --format vertical ./sboms
The first two fail, the last works as expected.
Logs:
Scanning dir ./test
Starting filesystem walk for root: /
Neither CPE, PURL, nor external reference found for package: &{IsUnpackaged:false PackageName:sbom PackageSPDXIdentifier:DocumentRoot-Directory-sbom PackageVersion: PackageFileName: PackageSupplier:0x3395795426e0 PackageOriginator:<nil> PackageDownloadLocation:NOASSERTION FilesAnalyzed:false IsFilesAnalyzedTagPresent:true PackageVerificationCode:<nil> PackageChecksums:[] PackageHomePage: PackageSourceInfo: PackageLicenseConcluded:NOASSERTION PackageLicenseInfoFromFiles:[] PackageLicenseDeclared:NOASSERTION PackageLicenseComments: PackageCopyrightText:NOASSERTION PackageSummary: PackageDescription: PackageComment: PackageExternalReferences:[] PackageAttributionTexts:[] PrimaryPackagePurpose:FILE ReleaseDate: BuiltDate: ValidUntilDate: Files:[] Annotations:[] hasFiles:[]}
Scanned sboms/sbom.spdx.json file and found 110 packages
End status: 1 dirs visited, 2 inodes visited, 1 Extract calls, 8.737792ms elapsed, 8.738ms wall time
Filtered 1 local/unscannable package/s from the scan.
Total 2 packages affected by 152 known vulnerabilities (0 Critical, 0 High, 0 Medium, 0 Low, 152 Unknown) from 1 ecosystem.
151 vulnerabilities can be fixed.
Go
sbom:sboms/sbom.spdx.json: found 2 packages with issues
When scanning an SPDX SBOM using osv-scanner 2.5.0 or 2.5.1, we essentially get all vulnerabilities ever registered for Golang's stdlib.
The package,
stdlib@v1.1.12is nowhere to be found in the SBOM. Instead,stdlib@1.27.0exists. When scanning the same SBOM using osv-scanner 2.4.0, no issues are reported.The SBOM is generated using Docker (which in turn uses Syft).
Here's the stdlib entry in the SBOM:
To run osv-scanner I place the SBOMs in a directory and run:
The first two fail, the last works as expected.
Logs: