What happened:
When i scan a file (.war) I get different results each scan. A jar with multiple pom.xml can result in, for example:
pkg:maven/org.glassfish.jaxb/jaxb-core@2.2.11
pkg:maven/com.sun.xml.bind/jaxb-core@2.2.11
What you expected to happen:
same result each time
Steps to reproduce the issue:
Repeatedly scan webgoat/webgoat container or JAR releases
Anything else we need to know?:
it impacts the number of results I get from syft.
Environment:
- Output of
syft version: 1.17.0
- OS (e.g:
cat /etc/os-release or similar): mac
What happened:
When i scan a file (.war) I get different results each scan. A jar with multiple
pom.xmlcan result in, for example:What you expected to happen:
same result each time
Steps to reproduce the issue:
Repeatedly scan
webgoat/webgoatcontainer or JAR releasesAnything else we need to know?:
it impacts the number of results I get from syft.
Environment:
syft version: 1.17.0cat /etc/os-releaseor similar): mac