Skip to content

fix: resolve SBOM dependency tree root from metadata (#5745) - #5749

Open
faystmax wants to merge 1 commit into
codecentric:masterfrom
faystmax:fix-5745-sbom-root
Open

faystmax wants to merge 1 commit into
codecentric:masterfrom
faystmax:fix-5745-sbom-root

Conversation

@faystmax

@faystmax faystmax commented Oct 3, 2026

Copy link
Copy Markdown

Fixes #5745.

The Dependency Trees view previously used dependencies[0] as its root, so reordering CycloneDX dependency records could display a library's subtree instead of the application's dependencies.

Pass metadata.component["bom-ref"] from the SBOM response to the normalizer and resolve the root by its exact reference before formatting its label. When the root cannot be resolved, show the existing SBOM empty-state message instead of selecting an unrelated record. Handle omitted dependency lists safely and keep filtering functional when the initial filter produces no tree.

Regression tests cover root positions, full-reference matching, input preservation, missing metadata/root records, empty or omitted dependency lists, propagation through the fetched SBOM response, and clearing an initially unmatched filter.

@faystmax
faystmax requested a review from a team as a code owner October 3, 2026 18:35

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: Dependency Trees uses dependencies[0] as root instead of metadata.component.bom-ref

1 participant