Skip to content

fix(sbom): keep SemVer build metadata in scan and SBOM JSON - #427

Open
vibgrate-team wants to merge 2 commits into
mainfrom
cursor/semver-build-metadata-3488
Open

vibgrate-team wants to merge 2 commits into
mainfrom
cursor/semver-build-metadata-3488

Conversation

@vibgrate-team

Copy link
Copy Markdown
Contributor

Summary

Versions with SemVer build metadata (for example 1.2.3+build.4) were losing the +… suffix before they reached machine-readable output. semver.clean and semver.valid return only major.minor.patch[-pre], and several scanners stored that stripped string as resolvedVersion.

  • Scan JSON resolvedVersion and SBOM component version / versionInfo now keep the canonical token from the lockfile or manifest, including Go 2.0.0+incompatible (the leading v is still removed). Range checks still ignore build metadata.
  • Package URLs follow the purl rule for +: the version field stays 1.2.3+build.4, and the purl version is percent-encoded (pkg:npm/name@1.2.3%2Bbuild.4).
  • A version that cannot be percent-encoded (a lone surrogate) does not drop the component or throw. The purl is omitted and the warning names the package and ecosystem, in the same style as an unavailable purl.

Related issues

Closes #298

Checklist

  • pnpm test passes
  • pnpm lint is clean
  • pnpm typecheck is clean
  • Docs updated (README / DOCS / ARCHITECTURE) where behavior changed
  • Determinism preserved — identical input still produces identical
    graph.json / report output (content-hashed IDs, stable sorts; no time,
    randomness, or filesystem-order dependence)
  • No proprietary or internal references — public, Apache-2.0 content only
  • Commits use Conventional Commits and are signed off (git commit -s, DCO)

Notes for reviewers

pnpm test (5174 passed), pnpm lint, and pnpm typecheck were run on this branch. Lint reports five pre-existing unused-variable warnings outside this change.

Go advisory ranges are unchanged: comparison still reduces 2.0.0+incompatible to 2.0.0. An explicit versions list now matches the recorded string, so 2.0.0 does not match that finding and 2.0.0+incompatible does. v2.0.0+incompatible still does not.

Open in Web Open in Cursor 

cursoragent and others added 2 commits October 9, 2026 22:12
semver.clean and semver.valid drop the +build suffix before a version
is recorded. Scan JSON and vg sbom now keep the canonical token
(1.2.3+build.4, and Go 2.0.0+incompatible). Package URLs still
percent-encode + as %2B. A version that cannot be percent-encoded keeps
the component and omits the purl with an actionable warning.

Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
Signed-off-by: Cursor Agent <cursoragent@cursor.com>

Co-authored-by: vibgrate-team <vibgrate-team@users.noreply.github.com>
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

Bug: preserve SemVer build-metadata (+…) through vg sbom and scan JSON

2 participants