feat: detect component hash changes — supply-chain tampering signal - #69
Merged
Conversation
added 2 commits
August 7, 2026 13:23
…report Closes #21 parse() previously accepted any JSON — a package.json passed by mistake, a truncated export, or garbage — and silently returned an empty CycloneDX SBOM. In a CI gate that read 'nothing changed' (a false negative). - parse() now throws ParseError when input is not a recognized CycloneDX or SPDX document (missing bomFormat/spdxVersion), is invalid JSON, or is not an object (array/null/primitives) - The CLI's loadSbom already wraps this in a clear 'Failed to parse' message; main() exits 1 (verified) - 6 new tests cover the rejection paths + valid-document acceptance 106 tests pass, tsc clean.
Closes #22 Component.hashes was declared but never parsed, compared, or rendered — a dependency re-published under the same name@version (event-stream / xz class attack) produced zero output. - Parser: extract CycloneDX hashes[] (alg/content) and SPDX checksums[] (algorithm/checksumValue) into a normalized {algorithm: digest} map - diff(): report HashChange when a component's version is unchanged but a digest differs; a version bump is already reported as an upgrade so its hash change is not double-counted - Reporter: Hash changes section + summary metric in text and markdown - 4 new tests (parser both formats, diff detection, upgrade-exclusion) 110 tests pass, tsc clean.
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #22
Problem
Component.hashes was declared in the type but never parsed, compared, or rendered — a dependency re-published under the same name@version (the event-stream / xz class of attack) produced zero output.
Fix
hashes[](alg/content) and SPDXchecksums[](algorithm/checksumValue) into a normalized{algorithm: digest}map (lowercased for cross-generator comparison)HashChangewhen a component's version is unchanged but a digest differs; version bumps are already reported as upgrades so their hash changes aren't double-countedVerification