Skip to content

chore(deps): update @cyclonedx/cdxgen to 12.1.2#1117

Merged
jdalton merged 2 commits intov1.xfrom
update-cdxgen-12.1.2
Mar 11, 2026
Merged

chore(deps): update @cyclonedx/cdxgen to 12.1.2#1117
jdalton merged 2 commits intov1.xfrom
update-cdxgen-12.1.2

Conversation

@jdalton
Copy link
Contributor

@jdalton jdalton commented Mar 11, 2026

Summary

Updates @cyclonedx/cdxgen from version 11.11.0 to 12.1.2 to get the latest features and bug fixes.

Changes

  • Updated @cyclonedx/cdxgen dependency from 11.11.0 to 12.1.2 in package.json
  • Updated pnpm-lock.yaml to reflect new dependency versions

Test Plan

  • Built the CLI successfully (pnpm run build:dist:src)
  • Verified cdxgen tests - pre-existing test failures remain unchanged by this update
  • No new build errors introduced

Notes

The cdxgen command tests have pre-existing failures that existed before this update and are unrelated to the version bump.


Note

Medium Risk
Primarily a dependency upgrade, but it changes SBOM generation tooling and many transitive packages/binaries, which can affect scan output and platform-specific builds.

Overview
Updates the SBOM generation tooling by bumping @cyclonedx/cdxgen from 11.11.0 to 12.1.2, pulling in a large set of transitive dependency updates and some dependency graph reshaping (notably new @cdxgen/* plugin binaries and refreshed @appthreat/* components).

Includes a tiny formatting-only tweak in src/commands/scan/reachability-flags.mts (single-line description string; no behavior change).

Written by Cursor Bugbot for commit a4b680f. This will update automatically on new commits. Configure here.

Updated @cyclonedx/cdxgen from 11.11.0 to 12.1.2 to get latest features and bug fixes.

Note: Pre-existing cdxgen test failures remain unchanged by this update.
@socket-security
Copy link

socket-security bot commented Mar 11, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​cyclonedx/​cdxgen@​11.11.0 ⏵ 12.1.28610010097 +5100

View full report

@socket-security-staging
Copy link

socket-security-staging bot commented Mar 11, 2026

Review the following changes in direct dependencies. Learn more about Socket for GitHub.

Diff Package Supply Chain
Security
Vulnerability Quality Maintenance License
Updatednpm/​@​cyclonedx/​cdxgen@​11.11.0 ⏵ 12.1.286 -110010099100

View full report

@socket-security-staging
Copy link

socket-security-staging bot commented Mar 11, 2026

Warning

Review the following alerts detected in dependencies.

According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.

Action Severity Alert  (click "▶" to expand/collapse)
Warn Medium
Low adoption: npm @cdxgen/cdxgen-plugins-bin-darwin-arm64

Location: Package overview

From: pnpm-lock.yamlnpm/@cyclonedx/cdxgen@12.1.2npm/@cdxgen/cdxgen-plugins-bin-darwin-arm64@2.0.2

ℹ Read more on: This package | This alert | What are unpopular packages?

Next steps: Take a moment to review the security alert above. Review the linked package source code to understand the potential risk. Ensure the package is not malicious before proceeding. If you're unsure how to proceed, reach out to your security team or ask the Socket team for help at support@socket.dev.

Suggestion: Unpopular packages may have less maintenance and contain other problems.

Mark the package as acceptable risk. To ignore this alert only in this pull request, reply with the comment @SocketSecurity-Staging ignore npm/@cdxgen/cdxgen-plugins-bin-darwin-arm64@2.0.2. You can also ignore all packages with @SocketSecurity-Staging ignore-all. To ignore an alert for all future pull requests, use Socket's Dashboard to change the triage state of this alert.

View full report

Consolidate multi-line description for reachDisableExternalToolChecks flag
to a single line for consistency with other flag definitions in the file.
@jdalton jdalton merged commit 0d98aa7 into v1.x Mar 11, 2026
8 checks passed
@jdalton jdalton deleted the update-cdxgen-12.1.2 branch March 11, 2026 16:35
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants