Skip to content

Commit 51aca1f

Browse files
committed
sbom: Use layer digest for layer package version
Currently we use the base OS version for the layer version, which confusingly sets most image layers for Wolfi based packages to an old looking package version which doesn't really have much to do with the image layer. For the top level image, we use the image digest. This change duplicates that behavior for image layers.
1 parent 89f7c13 commit 51aca1f

1 file changed

Lines changed: 4 additions & 4 deletions

File tree

pkg/sbom/generator/spdx/spdx.go

Lines changed: 4 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -427,13 +427,13 @@ func (sx *SPDX) imagePackage(opts *options.Options) (p *Package) {
427427

428428
// LayerPackage returns a package describing the layer
429429
func (sx *SPDX) layerPackage(opts *options.Options, layer v1.Descriptor) *Package {
430-
layerPackageName := hashToString(layer.Digest)
431-
mainPkgID := stringToIdentifier(layerPackageName)
430+
layerDigest := hashToString(layer.Digest)
431+
mainPkgID := stringToIdentifier(layerDigest)
432432

433433
return &Package{
434434
ID: fmt.Sprintf("SPDXRef-Package-%s", mainPkgID),
435-
Name: layerPackageName,
436-
Version: opts.OS.Version,
435+
Name: layerDigest,
436+
Version: layerDigest,
437437
FilesAnalyzed: false,
438438
Description: "apko operating system layer",
439439
DownloadLocation: NOASSERTION,

0 commit comments

Comments
 (0)