Warn when a BOM contains no vulnerabilities #6

Merged
liamjd merged 1 commit from no-vulnerabilities into main 2026-07-30 20:14:01 +01:00
Owner

An empty or absent vulnerabilities array reads the same as a scanned,
clean BOM, but almost always means no scanner ran. Surface it in the
existing warning strip so the distinction is visible.

Suppressed when the BOM has no components either, since that case
already has its own warning.

Co-Authored-By: Claude Opus 5 (1M context) noreply@anthropic.com

An empty or absent vulnerabilities array reads the same as a scanned, clean BOM, but almost always means no scanner ran. Surface it in the existing warning strip so the distinction is visible. Suppressed when the BOM has no components either, since that case already has its own warning. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
An empty or absent vulnerabilities array reads the same as a scanned,
clean BOM, but almost always means no scanner ran. Surface it in the
existing warning strip so the distinction is visible.

Suppressed when the BOM has no components either, since that case
already has its own warning.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
liamjd merged commit 98c107e800 into main 2026-07-30 20:14:01 +01:00
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set.

Reference
liamjd/SBOMViewer!6
No description provided.