Skip to content

feat(CSENG-58): document snyk:npm:scope and snyk:maven:build_scope SBOM labels.#991

Open
snyk-abedonik wants to merge 1 commit intomainfrom
feat/CSENG-58/document-sbom-npm-scope-maven-build-scope-labels
Open

feat(CSENG-58): document snyk:npm:scope and snyk:maven:build_scope SBOM labels.#991
snyk-abedonik wants to merge 1 commit intomainfrom
feat/CSENG-58/document-sbom-npm-scope-maven-build-scope-labels

Conversation

@snyk-abedonik
Copy link
Collaborator

Snyk now enriches every component in generated SBOM documents with Snyk-specific
dependency-scope properties. This PR adds documentation for two new labels:

  • snyk:npm:scope — for npm, PNPM, and Yarn projects: prod, dev, unknown
  • snyk:maven:build_scope — for Maven projects: compile, provided, runtime, test, system, unknown

The properties are present in all commands that produce SBOM output:
snyk sbom --format=cyclonedx1.6+json, snyk sbom --format=spdx2.3+json,
snyk test --print-deps --json, and snyk monitor --print-deps --json.

@snyk-abedonik snyk-abedonik requested review from a team as code owners March 6, 2026 17:15
@snyk-io
Copy link

snyk-io bot commented Mar 6, 2026

Snyk checks have passed. No issues have been found so far.

Status Scanner Critical High Medium Low Total (0)
Open Source Security 0 0 0 0 0 issues
Licenses 0 0 0 0 0 issues
Code Security 0 0 0 0 0 issues

💻 Catch issues earlier using the plugins for VS Code, JetBrains IDEs, Visual Studio, and Eclipse.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants