Skip to content

fix(sbom): stable component order independent of filesystem walk - #424

Merged
vibgrate-team merged 3 commits into
mainfrom
cursor/sbom-stable-component-order-bbfb
Oct 9, 2026
Merged

vibgrate-team merged 3 commits into
mainfrom
cursor/sbom-stable-component-order-bbfb

Conversation

@vibgrate-team

@vibgrate-team vibgrate-team commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Summary

vg sbom export used to emit direct scan rows in scan order, which follows the filesystem walk, and sorted only the lockfile-only rows after them. The same tree could therefore produce a different components order, different SPDXRef-Package-N ids, and a different order of dependency entries.

SBOM component and dependency arrays are now sorted before serialization:

  1. Package URL, when the component has one
  2. otherwise the package name
  3. then version

Rows that share a purl and version are ordered by name. CycloneDX dependencies still starts with vibgrate-root, followed by the components in that order. Directory walk order and map iteration no longer change components, SPDX packages, or those dependency entries. Document ids stay content-derived. vg export CycloneDX and SPDX use the same order.

A fixture test runs the export twice, reversing the lockfile component list and the edge map and moving a package with no purl inside the same project. Both runs emit identical CycloneDX and SPDX documents, serial number included.

Related issues

Closes #286

Checklist

  • pnpm test passes
  • pnpm lint is clean
  • pnpm typecheck is clean
  • Docs updated where behavior changed
  • Determinism preserved
  • No proprietary or internal references
  • Commits use Conventional Commits and are signed off

How to verify

pnpm test
pnpm lint
pnpm typecheck

cursoragent and others added 3 commits October 9, 2026 12:11
Direct scan rows were emitted ahead of the sorted lockfile-only list, so
CycloneDX components, dependency entries, and SPDX packages followed scan
and filesystem order. Sort the full list by Package URL when one is
written, otherwise by name, then version, then ecosystem, and apply the
same order to graph CycloneDX and SPDX export.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
Sort SBOM components by Package URL when one is written, otherwise by
package name, then by version. Rows that share a purl and a version are
ordered by name. CycloneDX components, dependency entries, and SPDX
packages, including SPDXRef-Package-N, follow that order.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
@vibgrate-team
vibgrate-team marked this pull request as ready for review October 9, 2026 13:23
@vibgrate-team
vibgrate-team merged commit 3fa0bba into main Oct 9, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Enhancement: stable component ordering in vg sbom JSON independent of filesystem walk order

2 participants