Skip to content

2.5.0 regression: CycloneDX SBOM scanning drops package namespace (npm scope) #2978

Description

@estyrke

Since v2.5.0, scanning a CycloneDX SBOM with -L strips the namespace from package names. @aws-sdk/client-lambda is queried against osv.dev as client-lambda.

This causes both:

  • False positives: our scoped npm packages now match typosquat malware advisories published for the unscoped name.
  • False negatives: real advisories for namespaced packages are never queried at all.

v2.4.0 handles these correctly.

Minimal repro:

{
  "bomFormat": "CycloneDX",
  "specVersion": "1.6",
  "version": 1,
  "components": [
    {
      "type": "library",
      "bom-ref": "pkg:npm/%40aws-sdk/client-lambda@3.1037.0",
      "group": "@aws-sdk",
      "name": "client-lambda",
      "version": "3.1037.0",
      "purl": "pkg:npm/%40aws-sdk/client-lambda@3.1037.0"
    }
  ]
}

Activity

  1. grehnen commented on Aug 10, 2026

    @grehnen

    Also having this issue!

  2. added a commit that references this issue on Aug 10, 2026
  3. self-assigned this
    on Aug 11, 2026
  4. Ly-Joey commented on Aug 12, 2026

    @Ly-Joey
    Contributor

    Hello! Thank you for raising the issue.

    The fix is in osv-scalibr#2356, but it may take a few days to propagate to osv-scanner.
    We aim to release v2.5.1 soon and will keep you posted in this thread.
    In the meantime, please pin your osv-scanner version to v2.4.0.

    Apologies for the inconvenience!

  5. added
    await releaseIssue has been fixed but is awaiting the next release.
    on Aug 13, 2026
  6. Ly-Joey commented on Aug 17, 2026

    @Ly-Joey
    Contributor

    Hi, the fix is now available in the newly released v2.5.1.
    I'll go ahead and close this issue, but feel free to reopen or comment if the problem persists after updating.
    Thanks again for your report and patience!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

Labels

await releaseIssue has been fixed but is awaiting the next release.

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions