使用cyclonedx-gomod生成SBOM失败,如何解决vendored模块枚举错误?
解决cyclonedx-gomod生成SBOM时的vendored模块错误
问题描述
尝试使用cyclonedx-gomod工具为oracle/terraform-provider-oci仓库生成SBOM,执行的流水线步骤如下:
steps: - type: Command name: "go version" command: | go version - type: Command name: "install cyclonedx-gomod" command: | GOBIN=$(pwd) go install github.com/CycloneDX/cyclonedx-gomod@v0.8.3 - type: Command name: "run cyclonedx-gomod" command: | ./cyclonedx-gomod -licenses -std -output bom.json -json
使用的Go版本为go1.16.5 linux/amd64(该版本受cyclonedx-gomod v0.8.3支持),但流水线执行失败,报错信息:
** generating sbom failed: failed to enumerate modules: listing vendored modules failed: exit status 1 Step 'run cyclonedx-gomod' failed with exit code: '1', please check the commands on the spec file.
解决方法
跳过vendored模块处理:直接在命令中添加
-no-vendor参数,绕过对vendor目录的扫描,这是最直接的临时解决方案:./cyclonedx-gomod -licenses -std -no-vendor -output bom.json -json重新生成vendor目录:如果项目依赖vendor目录,先清理缓存并重新生成vendor文件,修复可能的目录异常:
go clean -modcache go mod vendor完成后再执行原cyclonedx-gomod命令。
升级cyclonedx-gomod版本:v0.8.3可能存在特定场景下的vendor处理bug,尝试升级到兼容Go1.16的较新版本(如v1.0.0):
GOBIN=$(pwd) go install github.com/CycloneDX/cyclonedx-gomod@v1.0.0替换安装命令后重新执行SBOM生成步骤。
修复Go模块配置:检查并整理项目的模块依赖,确保
go.mod和go.sum文件正常:go mod tidy该命令会自动修复依赖不一致问题,之后再尝试生成SBOM。
内容的提问来源于stack exchange,提问作者Mohammed Az
相关产品推荐
相关产品推荐

