Skip to content

chore(deps): update dependency kubernetes-sigs/bom to v0.8.0 (v1.37) - #2058

Open
renovate[bot] wants to merge 1 commit into
v1.37from
renovate/v1.37-all-github-action
Open

renovate[bot] wants to merge 1 commit into
v1.37from
renovate/v1.37-all-github-action

Conversation

@renovate

@renovate renovate Bot commented Sep 28, 2026

Copy link
Copy Markdown
Contributor

This PR contains the following updates:

Package Update Change
kubernetes-sigs/bom minor v0.7.1 → v0.8.0

Release Notes

kubernetes-sigs/bom (kubernetes-sigs/bom)

v0.8.0

Compare Source

Changes by Kind
Deprecation
  • Bom now downloads modules from go proxy instead of using x/tools/go/vcs (#​588, @​puerco)
  • SPDX JSON is now the default output format. Pass --format tag-value for the previous default. Pipelines that consume bom generate output without specifying a format will see JSON where they used to see tag-value.
  • CycloneDX and SPDX JSON can now be read. bom document outline, bom document query and bom validate accept CycloneDX 1.3–1.7 JSON and SPDX 2.2/2.3 in both tag-value and JSON encodings.
  • Dependency data comes from unpack's decomposers. Go modules are resolved from go.mod/go.sum through the module proxy rather than by shelling out to go list, so a Go toolchain is no longer required to scan a Go codebase.
  • A new --offline flag scans without reaching the network. The document then lists every module a Go codebase requires in its go.mod, direct and indirect, but not the modules that appear only in go.sum — the test-only and pruned dependencies of dependencies — and dependency licenses go unresolved. Scanning an image reference is refused outright, as pulling one needs a registry; image archives on disk are unaffected.
  • Container image SBOMs have a new shape. The package inventory is now read from the image's squashed filesystem instead of being attributed to individual layers, which was frequently wrong. Layers are still recorded, as structural nodes carrying their diff id, but they no longer own packages. Image packages are named for the image reference and carry the manifest digest and a pkg:oci purl.
  • Directory packages are identified by their codebase. A directory holding a Go module is now named for the module rather than the directory, and carries a purl. Its dependency graph is included.
  • Parsing is stricter. Documents are validated against the SPDX schema rather than read field by field, so SBOMs that violate the specification are now rejected instead of partially parsed. Documents with an empty spdxVersion, or with package originators that are neither NOASSERTION nor a Person:/Organization: value, will fail to open.
  • Package URLs are canonically encoded. Characters the purl specification reserves are now percent-encoded — + renders as %2B — so purls match those produced by other SBOM tools byte for byte.
  • Debian packages carry a download location, synthesized from the Debian pool using the source package name, which is how the pool is laid out.
  • License detection changed. Licenses are classified with the scanner's embedded corpus rather than the downloaded SPDX license list, and both the new engine and the pkg/spdx compatibility layer now use the same classifier, where previously they could disagree. Edge-case classifications may differ from previous releases.
  • The SPDX license list is no longer embedded in the binary, taking 3.6 MB off it. It was only needed to feed the old classifier, which had to write every license to disk before it could recognize one. bom no longer reads or writes a license cache to classify files; a license list is fetched only when something asks for one explicitly. The CheckEmbeddedData and UpdateEmbeddedData mage targets that maintained the embedded archive are gone.
  • External document references are not preserved when reading. A document's externalDocumentRefs, and relationships pointing into another document, are dropped on parse. Support is planned upstream.
  • The document license list version is not preserved when reading.
  • --license, --no-gomod, --scan-images and --analyze-images are still accepted but no longer do anything, and warn when used. Reading a codebase's dependencies and a container image's packages are part of every scan now, deep image layer analysis has no equivalent in the new pipeline, and --license never had an effect. They are hidden from --help and will be removed in a future major version.
  • [api] New pkg/bom package. bom.Generate(ctx, *GenerateOptions) runs the new engine and returns a protobom *sbom.Document directly.
  • [api] pkg/spdx gained the converters FromProtobom and ToProtobom, and OpenProtobom to read any supported SBOM into a protobom document. DocGenerateOptions gained an Offline field.
  • [api] pkg/query is rewritten over protobom. Engine.Document is now a protobom *sbom.Document, FilterResults.Objects a map[string]*sbom.Node, and Filter.Apply, MatcherFunction and ObjectCycler operate on protobom nodes and take the new query.Graph. The query language and filter semantics are unchanged.
  • [api] The spdx.DocBuilderImplementation interface replaced CreateDocument, CreateSPDXClient and the five Scan* methods with a single GenerateDocument. The interface was never injectable from outside the package.
  • [api] The query printers in cmd/bom/cmd follow the pkg/query rewrite: Printer.PrintObjectList now takes protobom nodes.
  • [api] pkg/license's reader keeps its API, but licenses it returns from classification now carry only their SPDX identifier, not the metadata published in the license list — the classifier reports which license a file holds, not what that license says. Look an identifier up in a Catalog if you need the full record. For the same reason ReaderOptions' ConfidenceThreshold, CacheDir, LicenseDir and LicenseListVersion no longer affect classification, and ReaderDefaultImpl.Classifier and ReaderDefaultImpl.Catalog return nil.
  • [api] DocGenerateOptions fields the new engine does not implement are inert: Format, OutputFile, ProcessGoModules, License and ScanImages are ignored, and AnalyseLayers warns and does nothing. The format arguments to spdx.NewDocBuilder and spdx.WithFormat already had no effect.
  • [api] The generation internals below are superseded by the new engine. They still compile and are still exported, but bom no longer calls them, they receive no further work, and they will be removed in a future major version. Use pkg/bom.Generate or spdx.DocBuilder.Generate instead.
    • spdx.SPDX's generation methods: PackageFromDirectory, PackageFromImageTarball, PackageFromArchive, ImageRefToPackage, AnalyzeImageLayer, ExtractTarballTmp, PullImagesToArchive
    • spdx.PullImageToArchive
    • The Go module scanner: spdx.GoModule, spdx.NewGoModule, spdx.NewGoModuleFromPath, spdx.GoModImplementation, spdx.GoModDefaultImpl and their supporting types
    • The image layer analyzers: spdx.ImageAnalyzer, spdx.NewImageAnalyzer, spdx.ContainerLayerAnalyzer, spdx.ContainerLayerAnalyzerOptions
    • The pkg/osinfo package, superseded by unpack's system decomposers
    • The pkg/spdx/json/v2.2 package
  • --no-gitignore now works. The flag was declared and parsed but its value never reached the generator, so .gitignore files were always read.
  • --no-transient now works, and in the direction its help text describes. It was both dropped before reaching the generator and inverted on the way, so asking for direct dependencies only would have requested the opposite.
  • File names are populated when reading SPDX JSON. They previously were not, which silently broke bom validate and name filtering on JSON input.
  • Package declared licenses are no longer recorded as concluded licenses when reading SPDX JSON.
  • A malformed relationship no longer terminates the process.
  • The document namespace is preserved when reading a document, rather than being replaced by a generated urn:uuid:. (#​680, @​puerco) [SIG Release]
API Change
  • Bom now uses the intoto attestation framework libraries, dropping the old in-toto-go module. The provenance APIs have been generalized a bit, introducing a breaking change in some functions. (#​598, @​puerco)
Feature
  • Added Open, Parse and Write to sigs.k8s.io/bom/pkg/bom and deprecated spdx.DocBuilder and spdx.OpenDoc. Queries match multi-segment purl namespaces and reach relationship cycles, bom validate -d works on Go module directories, and documents accepted by v0.7.1 can be read again. (#​705, @​saschagrunert) [SIG Release]
  • Added bom document dot to export the relationship graph of an SPDX or CycloneDX SBOM in Graphviz DOT format. (#​702, @​saschagrunert) [SIG Release]
  • Added experimental SPDX 3.0.1 output with bom generate --format spdx3-json. (#​706, @​saschagrunert) [SIG Release]
  • bom generate lists Go binaries in images and files passed with --file together with the Go modules recorded in their build information. (#​700, @​saschagrunert) [SIG Release]
Bug or Regression
  • Directory SBOMs of Go modules now list only the module versions selected for the build, instead of every version found in go.sum. (#​703, @​saschagrunert) [SIG Release]
  • Fix: handle docker v29+ images with attestation data already included (#​605, @​jeefy)
  • Fixed invalid SPDX output (tag-value file attribution, license expressions, empty licenseInfoInFiles), same-named sources being merged, and made generated SBOMs reproducible. --no-gomod works again and SOURCE_DATE_EPOCH is honored. (#​704, @​saschagrunert) [SIG Release]
Other (Cleanup or Flake)
  • Add dummy dockerfile to keep track the go version and use that in ci (#​550, @​cpanato)
Dependencies
Added
  • buf.build/gen/go/bufbuild/protovalidate/protocolbuffers/go: 5032544
  • cyphar.com/go-pathrs: v0.2.1
  • github.com/BurntSushi/toml: v1.6.0
  • github.com/CycloneDX/cyclonedx-go: v0.12.0
  • github.com/anchore/go-struct-converter: v0.1.0
  • github.com/asaskevich/govalidator: a9d515a
  • github.com/blang/semver: v3.5.1
  • github.com/bradleyjkemp/cupaloy/v2: v2.8.0
  • github.com/bwesterb/go-ristretto: v1.2.4
  • github.com/carabiner-dev/attestation: v0.2.1
  • github.com/carabiner-dev/collector: v0.3.11
  • github.com/carabiner-dev/command: v0.3.1
  • github.com/carabiner-dev/github: v0.2.3
  • github.com/carabiner-dev/hasher: v0.2.4
  • github.com/carabiner-dev/jsonl: v0.2.1
  • github.com/carabiner-dev/openeox: v1.0.0
  • github.com/carabiner-dev/osv: v0.1.1
  • github.com/carabiner-dev/policy: v0.5.1
  • github.com/carabiner-dev/predicates: v0.5.0
  • github.com/carabiner-dev/protograph: 4dc9de9
  • github.com/carabiner-dev/signer: v0.5.4
  • github.com/carabiner-dev/spdx3: v0.1.0
  • github.com/carabiner-dev/termtable: v1.1.0
  • github.com/carabiner-dev/unpack: v0.3.2
  • github.com/carabiner-dev/vcslocator: v0.4.7
  • github.com/cenkalti/backoff/v5: v5.0.3
  • github.com/cespare/xxhash/v2: v2.3.0
  • github.com/chzyer/readline: v1.5.1
  • github.com/clipperhouse/displaywidth: v0.11.0
  • github.com/clipperhouse/uax29/v2: v2.7.0
  • github.com/coreos/go-oidc/v3: v3.20.0
  • github.com/cyberphone/json-canonicalization: 19d51d7
  • github.com/digitorus/pkcs7: ffadbf3
  • github.com/digitorus/timestamp: c455327
  • github.com/github/go-spdx/v2: v2.7.0
  • github.com/go-jose/go-jose/v4: v4.1.4
  • github.com/go-openapi/analysis: v0.25.5
  • github.com/go-openapi/errors: v0.22.8
  • github.com/go-openapi/jsonpointer: v1.0.0
  • github.com/go-openapi/jsonreference: v1.0.0
  • github.com/go-openapi/loads: v0.25.0
  • github.com/go-openapi/runtime: v0.33.0
  • github.com/go-openapi/runtime/server-middleware: v0.33.0
  • github.com/go-openapi/spec: v0.22.9
  • github.com/go-openapi/strfmt: v0.27.0
  • github.com/go-openapi/swag: v0.28.0
  • github.com/go-openapi/swag/cmdutils: v0.28.0
  • github.com/go-openapi/swag/conv: v0.28.0
  • github.com/go-openapi/swag/fileutils: v0.28.0
  • github.com/go-openapi/swag/jsonutils: v0.28.0
  • github.com/go-openapi/swag/loading: v0.28.0
  • github.com/go-openapi/swag/mangling: v0.28.0
  • github.com/go-openapi/swag/netutils: v0.28.0
  • github.com/go-openapi/swag/pools: v0.28.0
  • github.com/go-openapi/swag/stringutils: v0.28.0
  • github.com/go-openapi/swag/typeutils: v0.28.0
  • github.com/go-openapi/swag/yamlutils: v0.28.0
  • github.com/go-openapi/validate: v0.26.1
  • github.com/go-viper/mapstructure/v2: v2.5.0
  • github.com/goccy/go-json: v0.10.6
  • github.com/google/certificate-transparency-go: v1.3.3
  • github.com/grpc-ecosystem/grpc-gateway/v2: v2.30.0
  • github.com/hashicorp/go-cleanhttp: v0.5.2
  • github.com/hashicorp/go-retryablehttp: v0.7.8
  • github.com/hashicorp/golang-lru/v2: v2.0.7
  • github.com/ianlancetaylor/demangle: f615e6b
  • github.com/in-toto/attestation: v1.2.0
  • github.com/jedisct1/go-minisign: a09352b
  • github.com/moby/moby/api: v1.55.0
  • github.com/moby/moby/client: v0.5.1
  • github.com/ncruces/go-strftime: v1.0.0
  • github.com/oklog/ulid/v2: v2.1.2
  • github.com/olekukonko/cat: 50322a0
  • github.com/openvex/go-vex: v0.2.8
  • github.com/pkg/browser: 5ac0b6a
  • github.com/protobom/protobom: v0.6.2
  • github.com/sassoftware/relic: v7.2.1
  • github.com/sigstore/protobuf-specs: v0.5.1
  • github.com/sigstore/rekor: v1.5.3
  • github.com/sigstore/rekor-tiles/v2: v2.3.0
  • github.com/sigstore/sigstore: v1.10.9
  • github.com/sigstore/sigstore-go: v1.3.0
  • github.com/sigstore/timestamp-authority/v2: v2.1.3
  • github.com/spdx/gordf: 7098f93
  • github.com/spdx/tools-golang: v0.5.7
  • github.com/terminalstatic/go-xsd-validate: v0.1.8
  • github.com/theupdateframework/go-tuf: v0.7.0
  • github.com/theupdateframework/go-tuf/v2: v2.4.2
  • github.com/transparency-dev/formats: v0.1.1
  • github.com/transparency-dev/merkle: v0.0.2
  • github.com/xeipuuv/gojsonpointer: 02993c4
  • github.com/xeipuuv/gojsonreference: bd5ef7b
  • github.com/xeipuuv/gojsonschema: v1.2.0
  • github.com/youmark/pkcs8: a2c0da2
  • google.golang.org/genproto/googleapis/api: 6ac0973
  • google.golang.org/genproto/googleapis/rpc: 6ac0973
  • modernc.org/cc/v4: v4.29.0
  • modernc.org/ccgo/v4: v4.34.6
  • modernc.org/fileutil: v1.4.0
  • modernc.org/gc/v2: v2.6.5
  • modernc.org/gc/v3: v3.1.4
  • modernc.org/goabi0: v0.2.0
  • modernc.org/sortutil: v1.2.1
Changed
Removed
  • github.com/codahale/rfc6979: 6a90f24
  • github.com/containerd/log: v0.1.0
  • github.com/containerd/stargz-snapshotter/estargz: v0.16.3
  • github.com/docker/distribution: v2.8.3
  • github.com/docker/docker: v28.2.2
  • github.com/go-jose/go-jose/v3: v3.0.0
  • github.com/gogo/protobuf: v1.3.2
  • github.com/kballard/go-shellquote: 95032a8
  • github.com/mattn/go-sqlite3: v1.14.16
  • github.com/mitchellh/go-homedir: v1.1.0
  • github.com/moby/sys/atomicwriter: v0.1.0
  • github.com/morikuni/aec: v1.0.0
  • github.com/urfave/cli: v1.22.16
  • github.com/vbatts/tar-split: v0.12.1
  • github.com/zeebo/errs: v1.3.0
  • go.opentelemetry.io/otel/exporters/otlp/otlptrace/otlptracehttp: v1.33.0
  • golang.org/x/time: 1f47c86
  • golang.org/x/tools/go/vcs: v0.1.0-deprecated
  • google.golang.org/genproto: 637eb22
  • lukechampine.com/uint128: v1.3.0
  • modernc.org/cc/v3: v3.41.0
  • modernc.org/ccgo/v3: v3.16.15
  • modernc.org/httpfs: v1.0.6
  • modernc.org/tcl: v1.15.2
  • modernc.org/z: v1.7.3

Configuration

📅 Schedule: (UTC)

  • Branch creation
    • "on monday"
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about this update again.


  • If you want to rebase/retry this PR, check this box

This PR was generated by Mend Renovate. View the repository job log.

Signed-off-by: renovate[bot] <29139614+renovate[bot]@users.noreply.github.com>

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants