chore(deps): update @cyclonedx/cdxgen to 12.1.2#1117
Conversation
Updated @cyclonedx/cdxgen from 11.11.0 to 12.1.2 to get latest features and bug fixes. Note: Pre-existing cdxgen test failures remain unchanged by this update.
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Review the following changes in direct dependencies. Learn more about Socket for GitHub.
|
|
Warning Review the following alerts detected in dependencies. According to your organization's Security Policy, it is recommended to resolve "Warn" alerts. Learn more about Socket for GitHub.
|
Consolidate multi-line description for reachDisableExternalToolChecks flag to a single line for consistency with other flag definitions in the file.
Summary
Updates @cyclonedx/cdxgen from version 11.11.0 to 12.1.2 to get the latest features and bug fixes.
Changes
@cyclonedx/cdxgendependency from11.11.0to12.1.2in package.jsonTest Plan
pnpm run build:dist:src)Notes
The cdxgen command tests have pre-existing failures that existed before this update and are unrelated to the version bump.
Note
Medium Risk
Primarily a dependency upgrade, but it changes SBOM generation tooling and many transitive packages/binaries, which can affect scan output and platform-specific builds.
Overview
Updates the SBOM generation tooling by bumping
@cyclonedx/cdxgenfrom11.11.0to12.1.2, pulling in a large set of transitive dependency updates and some dependency graph reshaping (notably new@cdxgen/*plugin binaries and refreshed@appthreat/*components).Includes a tiny formatting-only tweak in
src/commands/scan/reachability-flags.mts(single-linedescriptionstring; no behavior change).Written by Cursor Bugbot for commit a4b680f. This will update automatically on new commits. Configure here.