You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用cyclonedx-gomod生成SBOM失败,如何解决vendored模块枚举错误?

解决cyclonedx-gomod生成SBOM时的vendored模块错误

问题描述

尝试使用cyclonedx-gomod工具为oracle/terraform-provider-oci仓库生成SBOM,执行的流水线步骤如下:

steps:
  - type: Command
    name: "go version"
    command: |
       go version
  - type: Command
    name: "install cyclonedx-gomod"
    command: |
      GOBIN=$(pwd) go install github.com/CycloneDX/cyclonedx-gomod@v0.8.3
  - type: Command
    name: "run cyclonedx-gomod"
    command: |
      ./cyclonedx-gomod -licenses -std -output bom.json -json

使用的Go版本为go1.16.5 linux/amd64(该版本受cyclonedx-gomod v0.8.3支持),但流水线执行失败,报错信息:

** generating sbom failed: failed to enumerate modules: listing vendored modules failed: exit status 1   
Step 'run cyclonedx-gomod' failed with exit code: '1', please check the commands on the spec file.

解决方法

  • 跳过vendored模块处理:直接在命令中添加-no-vendor参数,绕过对vendor目录的扫描,这是最直接的临时解决方案:

    ./cyclonedx-gomod -licenses -std -no-vendor -output bom.json -json
    
  • 重新生成vendor目录:如果项目依赖vendor目录,先清理缓存并重新生成vendor文件,修复可能的目录异常:

    go clean -modcache
    go mod vendor
    

    完成后再执行原cyclonedx-gomod命令。

  • 升级cyclonedx-gomod版本:v0.8.3可能存在特定场景下的vendor处理bug,尝试升级到兼容Go1.16的较新版本(如v1.0.0):

    GOBIN=$(pwd) go install github.com/CycloneDX/cyclonedx-gomod@v1.0.0
    

    替换安装命令后重新执行SBOM生成步骤。

  • 修复Go模块配置:检查并整理项目的模块依赖,确保go.mod和go.sum文件正常:

    go mod tidy
    

    该命令会自动修复依赖不一致问题,之后再尝试生成SBOM。

内容的提问来源于stack exchange,提问作者Mohammed Az

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.06.24 17:37:08