René's URL Explorer Experiment


Title: Dependency-Track hook ignores CycloneDX SBOM after secureCodeBox v5.0.0 upgrade · Issue #3272 · secureCodeBox/secureCodeBox · GitHub

Open Graph Title: Dependency-Track hook ignores CycloneDX SBOM after secureCodeBox v5.0.0 upgrade · Issue #3272 · secureCodeBox/secureCodeBox

X Title: Dependency-Track hook ignores CycloneDX SBOM after secureCodeBox v5.0.0 upgrade · Issue #3272 · secureCodeBox/secureCodeBox

Description: 🐞 Bug report Describe the bug After upgrading to secureCodeBox 5.0.0, the persistence-dependencytrack hook is skipping uploads with the message: Only CycloneDX SBOMs can be sent to DependencyTrack, ignoring. This occurs even though the T...

Open Graph Description: 🐞 Bug report Describe the bug After upgrading to secureCodeBox 5.0.0, the persistence-dependencytrack hook is skipping uploads with the message: Only CycloneDX SBOMs can be sent to DependencyTrack,...

X Description: 🐞 Bug report Describe the bug After upgrading to secureCodeBox 5.0.0, the persistence-dependencytrack hook is skipping uploads with the message: Only CycloneDX SBOMs can be sent to DependencyTrack,...

Opengraph URL: https://github.com/secureCodeBox/secureCodeBox/issues/3272

X: @github

direct link

Domain: github.com


Hey, it has json ld scripts:
{"@context":"https://schema.org","@type":"DiscussionForumPosting","headline":"Dependency-Track hook ignores CycloneDX SBOM after secureCodeBox v5.0.0 upgrade","articleBody":"## 🐞 Bug report\n\u003c!--\nThank you for reporting an issue in our project 🙌\n\nBefore opening a new issue, please make sure that we do not have any duplicates already open. You can ensure this by searching the issue list for this repository. If there is a duplicate, please close your issue and add a comment to the existing issue instead.\n--\u003e\n\n### Describe the bug\n\nAfter upgrading to secureCodeBox 5.0.0, the persistence-dependencytrack hook is skipping uploads with the message:\n\n```\nOnly CycloneDX SBOMs can be sent to DependencyTrack, ignoring.\n```\n\nThis occurs even though the Trivy SBOM scan produced a valid CycloneDX 1.6 SBOM, was uploaded to file storage, and the parser completed successfully. As a result, the Dependency-Track project’s Last BOM Import timestamp is not updated.\n\n### Expected behavior\n\nThe DT hook should detect the CycloneDX SBOM and POST it to Dependency-Track.\n\nThe project’s Last BOM Import should update to the current run.\n\n### System (please complete the following information):\n\n - secureCodeBox 5.0.0\n - Kubernetes Version 1.32\n - dependency-track/dependency-track      Chart 0.36.0        Version  4.13.4\n\n### Screenshots / Logs\n\nTrivy SBOM scan \u0026 parser:\n```txt\n\n2025-09-09 10:04:35.081 | 2025-09-09T08:04:35Z\tINFO\t\"--format cyclonedx\" disables security scanning. Specify \"--scanners vuln\" explicitly if you want to include vulnerabilities in the \"cyclonedx\" report. |  \n-- | -- | --\n  |   | 2025-09-09 10:04:35.274 | 2025/09/09 08:04:35 Starting lurker |  \n  |   | 2025-09-09 10:04:35.274 | 2025/09/09 08:04:35 Waiting for main container 'trivy-sbom' to complete |  \n  |   | 2025-09-09 10:04:35.274 | 2025/09/09 08:04:35 After scan is completed file '/home/securecodebox/sbom-cyclonedx.json' will be uploaded to '...s3.amazonaws.com' |  \n  |   | 2025-09-09 10:04:35.275 | 2025/09/09 08:04:35 Waiting for maincontainer to exit. |  \n  |   | 2025-09-09 10:04:39.869 | 2025-09-09T08:04:39Z\tINFO\t[javadb] Downloading Java DB... |  \n  |   | 2025-09-09 10:04:39.870 | 2025-09-09T08:04:39Z\tINFO\t[javadb] Downloading artifact...\trepo=\"mirror.gcr.io/aquasec/trivy-java-db:1\" |  \n  |   | 2025-09-09 10:05:32.887 | 2025-09-09T08:05:32Z\tINFO\t[javadb] Artifact successfully downloaded\trepo=\"mirror.gcr.io/aquasec/trivy-java-db:1\" |  \n  |   | 2025-09-09 10:05:32.906 | 2025-09-09T08:05:32Z\tINFO\t[javadb] Java DB is cached for 3 days. If you want to update the database more frequently, \"trivy clean --java-db\" command clears the DB cache. |  \n  |   | 2025-09-09 10:05:33.099 | 2025-09-09T08:05:33Z\tINFO\tDetected OS\tfamily=\"alpine\" version=\"3.22.1\" |  \n  |   | 2025-09-09 10:05:33.099 | 2025-09-09T08:05:33Z\tINFO\tNumber of language-specific files\tnum=3 |  \n  |   | 2025-09-09 10:05:33.121 |   |  \n  |   | 2025-09-09 10:05:33.121 | 📣 Notices: |  \n  |   | 2025-09-09 10:05:33.121 | - Version 0.66.0 of Trivy is now available, current version is 0.65.0 |  \n  |   | 2025-09-09 10:05:33.121 |   |  \n  |   | 2025-09-09 10:05:33.121 | To suppress version checks, run Trivy scans with the --skip-version-check flag |  \n  |   | 2025-09-09 10:05:33.121 |   |  \n  |   | 2025-09-09 10:05:38.016 | 2025/09/09 08:05:38 Main Container exited. Lurker will end as well. |  \n  |   | 2025-09-09 10:05:38.016 | 2025/09/09 08:05:38 Uploading result files. |  \n  |   | 2025-09-09 10:05:38.016 | 2025/09/09 08:05:38 Uploading /home/securecodebox/sbom-cyclonedx.json |  \n  |   | 2025-09-09 10:05:38.016 | 2025/09/09 08:05:38 Scan result file has a size of 299188 bytes |  \n  |   | 2025-09-09 10:05:38.242 | 2025/09/09 08:05:38 Uploaded file successfully |  \n  |   | 2025-09-09 10:05:44.173 | Starting Parser |  \n  |   | 2025-09-09 10:05:44.396 | (node:1) [DEP0040] DeprecationWarning: The `punycode` module is deprecated. Please use a userland alternative instead. |  \n  |   | 2025-09-09 10:05:44.396 | (Use `node --trace-deprecation ...` to show where the warning was created) |  \n  |   | 2025-09-09 10:05:44.493 | Fetching result file |  \n  |   | 2025-09-09 10:05:44.674 | Fetched result file |  \n  |   | 2025-09-09 10:05:44.675 | Transformed raw result file into 1 findings |  \n  |   | 2025-09-09 10:05:44.675 | Adding UUIDs and Dates to the findings |  \n  |   | 2025-09-09 10:05:44.676 | Adding scan metadata to the findings |  \n  |   | 2025-09-09 10:05:44.677 | Validating Findings. Environment variable CRASH_ON_FAILED_VALIDATION is set to false |  \n  |   | 2025-09-09 10:05:44.882 | The Findings were successfully validated |  \n  |   | 2025-09-09 10:05:44.917 | Updated status successfully |  \n  |   | 2025-09-09 10:05:44.917 | Uploading results to the file storage service |  \n  |   | 2025-09-09 10:05:44.963 | Completed parser\n\n\n```\n\nDependency-Track hook\n\n```txt\n\n2025-09-09 10:05:49.175 | Starting hook for Scan \"service-example-sbom\" |  \n-- | -- | --\n  |   | 2025-09-09 10:05:49.380 | (node:1) [DEP0040] DeprecationWarning: The `punycode` module is deprecated. Please use a userland alternative instead. |  \n  |   | 2025-09-09 10:05:49.380 | (Use `node --trace-deprecation ...` to show where the warning was created) |  \n  |   | 2025-09-09 10:05:49.569 | Fetched raw result file contents from the file storage |  \n  |   | 2025-09-09 10:05:49.583 | Only CycloneDX SBOMs can be sent to DependencyTrack, ignoring. |  \n  |   | 2025-09-09 10:05:49.583 | Hook completed\n\n\n```\n### Additional context\n\u003c!-- Add any other context about the problem here. --\u003e\n","author":{"url":"https://github.com/YuriiBudnyi","@type":"Person","name":"YuriiBudnyi"},"datePublished":"2025-09-11T12:44:47.000Z","interactionStatistic":{"@type":"InteractionCounter","interactionType":"https://schema.org/CommentAction","userInteractionCount":3},"url":"https://github.com/3272/secureCodeBox/issues/3272"}

route-pattern/_view_fragments/issues/show/:user_id/:repository/:id/issue_layout(.:format)
route-controllervoltron_issues_fragments
route-actionissue_layout
fetch-noncev2:659248f2-fd11-b54c-083b-704a68e180e4
current-catalog-service-hash81bb79d38c15960b92d99bca9288a9108c7a47b18f2423d0f6438c5b7bcd2114
request-idBA34:EC594:33BD4C:46D397:69774BDD
html-safe-noncee89ff048fbb30d07e0e15a3526a25bb485c8960b1013beadaf842ef7865f68ab
visitor-payloadeyJyZWZlcnJlciI6IiIsInJlcXVlc3RfaWQiOiJCQTM0OkVDNTk0OjMzQkQ0Qzo0NkQzOTc6Njk3NzRCREQiLCJ2aXNpdG9yX2lkIjoiNTk5MTE5NzQ1Mzc0MTE0OTE0OSIsInJlZ2lvbl9lZGdlIjoiaWFkIiwicmVnaW9uX3JlbmRlciI6ImlhZCJ9
visitor-hmaca9218f020677e30679b42cf97af42d73134153a2122802691a4826d65cff7f11
hovercard-subject-tagissue:3406403572
github-keyboard-shortcutsrepository,issues,copilot
google-site-verificationApib7-x98H0j5cPqHWwSMm6dNU4GmODRoqxLiDzdx9I
octolytics-urlhttps://collector.github.com/github/collect
analytics-location///voltron/issues_fragments/issue_layout
fb:app_id1401488693436528
apple-itunes-appapp-id=1477376905, app-argument=https://github.com/_view_fragments/issues/show/secureCodeBox/secureCodeBox/3272/issue_layout
twitter:imagehttps://opengraph.githubassets.com/0774be3ac94ca72a557b2e2b9db45ca2a99e3eb4428d7bd1e3b2b1a56e93e075/secureCodeBox/secureCodeBox/issues/3272
twitter:cardsummary_large_image
og:imagehttps://opengraph.githubassets.com/0774be3ac94ca72a557b2e2b9db45ca2a99e3eb4428d7bd1e3b2b1a56e93e075/secureCodeBox/secureCodeBox/issues/3272
og:image:alt🐞 Bug report Describe the bug After upgrading to secureCodeBox 5.0.0, the persistence-dependencytrack hook is skipping uploads with the message: Only CycloneDX SBOMs can be sent to DependencyTrack,...
og:image:width1200
og:image:height600
og:site_nameGitHub
og:typeobject
og:author:usernameYuriiBudnyi
hostnamegithub.com
expected-hostnamegithub.com
None3310064f35a62c06a4024ba37f41c06836f39376a095c2dfd2c4b693c34965be
turbo-cache-controlno-preview
go-importgithub.com/secureCodeBox/secureCodeBox git https://github.com/secureCodeBox/secureCodeBox.git
octolytics-dimension-user_id34573705
octolytics-dimension-user_loginsecureCodeBox
octolytics-dimension-repository_id80711933
octolytics-dimension-repository_nwosecureCodeBox/secureCodeBox
octolytics-dimension-repository_publictrue
octolytics-dimension-repository_is_forkfalse
octolytics-dimension-repository_network_root_id80711933
octolytics-dimension-repository_network_root_nwosecureCodeBox/secureCodeBox
turbo-body-classeslogged-out env-production page-responsive
disable-turbofalse
browser-stats-urlhttps://api.github.com/_private/browser/stats
browser-errors-urlhttps://api.github.com/_private/browser/errors
release67d5f8d1d53c3cc4f49fc3bb8029933c3dc219e6
ui-targetcanary-1
theme-color#1e2327
color-schemelight dark

Links:

Skip to contenthttps://github.com/secureCodeBox/secureCodeBox/issues/3272#start-of-content
https://github.com/
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2FsecureCodeBox%2FsecureCodeBox%2Fissues%2F3272
GitHub CopilotWrite better code with AIhttps://github.com/features/copilot
GitHub SparkBuild and deploy intelligent appshttps://github.com/features/spark
GitHub ModelsManage and compare promptshttps://github.com/features/models
MCP RegistryNewIntegrate external toolshttps://github.com/mcp
ActionsAutomate any workflowhttps://github.com/features/actions
CodespacesInstant dev environmentshttps://github.com/features/codespaces
IssuesPlan and track workhttps://github.com/features/issues
Code ReviewManage code changeshttps://github.com/features/code-review
GitHub Advanced SecurityFind and fix vulnerabilitieshttps://github.com/security/advanced-security
Code securitySecure your code as you buildhttps://github.com/security/advanced-security/code-security
Secret protectionStop leaks before they starthttps://github.com/security/advanced-security/secret-protection
Why GitHubhttps://github.com/why-github
Documentationhttps://docs.github.com
Bloghttps://github.blog
Changeloghttps://github.blog/changelog
Marketplacehttps://github.com/marketplace
View all featureshttps://github.com/features
Enterpriseshttps://github.com/enterprise
Small and medium teamshttps://github.com/team
Startupshttps://github.com/enterprise/startups
Nonprofitshttps://github.com/solutions/industry/nonprofits
App Modernizationhttps://github.com/solutions/use-case/app-modernization
DevSecOpshttps://github.com/solutions/use-case/devsecops
DevOpshttps://github.com/solutions/use-case/devops
CI/CDhttps://github.com/solutions/use-case/ci-cd
View all use caseshttps://github.com/solutions/use-case
Healthcarehttps://github.com/solutions/industry/healthcare
Financial serviceshttps://github.com/solutions/industry/financial-services
Manufacturinghttps://github.com/solutions/industry/manufacturing
Governmenthttps://github.com/solutions/industry/government
View all industrieshttps://github.com/solutions/industry
View all solutionshttps://github.com/solutions
AIhttps://github.com/resources/articles?topic=ai
Software Developmenthttps://github.com/resources/articles?topic=software-development
DevOpshttps://github.com/resources/articles?topic=devops
Securityhttps://github.com/resources/articles?topic=security
View all topicshttps://github.com/resources/articles
Customer storieshttps://github.com/customer-stories
Events & webinarshttps://github.com/resources/events
Ebooks & reportshttps://github.com/resources/whitepapers
Business insightshttps://github.com/solutions/executive-insights
GitHub Skillshttps://skills.github.com
Documentationhttps://docs.github.com
Customer supporthttps://support.github.com
Community forumhttps://github.com/orgs/community/discussions
Trust centerhttps://github.com/trust-center
Partnershttps://github.com/partners
GitHub SponsorsFund open source developershttps://github.com/sponsors
Security Labhttps://securitylab.github.com
Maintainer Communityhttps://maintainers.github.com
Acceleratorhttps://github.com/accelerator
Archive Programhttps://archiveprogram.github.com
Topicshttps://github.com/topics
Trendinghttps://github.com/trending
Collectionshttps://github.com/collections
Enterprise platformAI-powered developer platformhttps://github.com/enterprise
GitHub Advanced SecurityEnterprise-grade security featureshttps://github.com/security/advanced-security
Copilot for BusinessEnterprise-grade AI featureshttps://github.com/features/copilot/copilot-business
Premium SupportEnterprise-grade 24/7 supporthttps://github.com/premium-support
Pricinghttps://github.com/pricing
Search syntax tipshttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
documentationhttps://docs.github.com/search-github/github-code-search/understanding-github-code-search-syntax
Sign in https://github.com/login?return_to=https%3A%2F%2Fgithub.com%2FsecureCodeBox%2FsecureCodeBox%2Fissues%2F3272
Sign up https://github.com/signup?ref_cta=Sign+up&ref_loc=header+logged+out&ref_page=%2F%3Cuser-name%3E%2F%3Crepo-name%3E%2Fvoltron%2Fissues_fragments%2Fissue_layout&source=header-repo&source_repo=secureCodeBox%2FsecureCodeBox
Reloadhttps://github.com/secureCodeBox/secureCodeBox/issues/3272
Reloadhttps://github.com/secureCodeBox/secureCodeBox/issues/3272
Reloadhttps://github.com/secureCodeBox/secureCodeBox/issues/3272
secureCodeBox https://github.com/secureCodeBox
secureCodeBoxhttps://github.com/secureCodeBox/secureCodeBox
Notifications https://github.com/login?return_to=%2FsecureCodeBox%2FsecureCodeBox
Fork 175 https://github.com/login?return_to=%2FsecureCodeBox%2FsecureCodeBox
Star 941 https://github.com/login?return_to=%2FsecureCodeBox%2FsecureCodeBox
Code https://github.com/secureCodeBox/secureCodeBox
Issues 72 https://github.com/secureCodeBox/secureCodeBox/issues
Pull requests 3 https://github.com/secureCodeBox/secureCodeBox/pulls
Discussions https://github.com/secureCodeBox/secureCodeBox/discussions
Actions https://github.com/secureCodeBox/secureCodeBox/actions
Projects 1 https://github.com/secureCodeBox/secureCodeBox/projects
Security 1 https://github.com/secureCodeBox/secureCodeBox/security
Insights https://github.com/secureCodeBox/secureCodeBox/pulse
Code https://github.com/secureCodeBox/secureCodeBox
Issues https://github.com/secureCodeBox/secureCodeBox/issues
Pull requests https://github.com/secureCodeBox/secureCodeBox/pulls
Discussions https://github.com/secureCodeBox/secureCodeBox/discussions
Actions https://github.com/secureCodeBox/secureCodeBox/actions
Projects https://github.com/secureCodeBox/secureCodeBox/projects
Security https://github.com/secureCodeBox/secureCodeBox/security
Insights https://github.com/secureCodeBox/secureCodeBox/pulse
New issuehttps://github.com/login?return_to=https://github.com/secureCodeBox/secureCodeBox/issues/3272
New issuehttps://github.com/login?return_to=https://github.com/secureCodeBox/secureCodeBox/issues/3272
#3290https://github.com/secureCodeBox/secureCodeBox/pull/3290
Dependency-Track hook ignores CycloneDX SBOM after secureCodeBox v5.0.0 upgradehttps://github.com/secureCodeBox/secureCodeBox/issues/3272#top
#3290https://github.com/secureCodeBox/secureCodeBox/pull/3290
https://github.com/p4trickweiss
bugBugshttps://github.com/secureCodeBox/secureCodeBox/issues?q=state%3Aopen%20label%3A%22bug%22
help wantedExtra attention is neededhttps://github.com/secureCodeBox/secureCodeBox/issues?q=state%3Aopen%20label%3A%22help%20wanted%22
https://github.com/YuriiBudnyi
https://github.com/YuriiBudnyi
YuriiBudnyihttps://github.com/YuriiBudnyi
on Sep 11, 2025https://github.com/secureCodeBox/secureCodeBox/issues/3272#issue-3406403572
p4trickweisshttps://github.com/p4trickweiss
bugBugshttps://github.com/secureCodeBox/secureCodeBox/issues?q=state%3Aopen%20label%3A%22bug%22
help wantedExtra attention is neededhttps://github.com/secureCodeBox/secureCodeBox/issues?q=state%3Aopen%20label%3A%22help%20wanted%22
secureCodeBoxhttps://github.com/orgs/secureCodeBox/projects/6
https://github.com
Termshttps://docs.github.com/site-policy/github-terms/github-terms-of-service
Privacyhttps://docs.github.com/site-policy/privacy-policies/github-privacy-statement
Securityhttps://github.com/security
Statushttps://www.githubstatus.com/
Communityhttps://github.community/
Docshttps://docs.github.com/
Contacthttps://support.github.com?tags=dotcom-footer

Viewport: width=device-width


URLs of crawlers that visited me.