From befc6125e4a2ba809a9c77931e91e86880435577 Mon Sep 17 00:00:00 2001 From: Florian Schreiber Date: Wed, 12 Aug 2026 17:16:04 +0200 Subject: [PATCH] feat(UP-4705): Use upstream release of yarn-plugin-cyclonedx The new version 3.4.0 finally supports the `--lockfile-only` flag, that we need to support generating SBOMs without downloading artifacts. --- sauron-service/Dockerfile | 22 ++-------------------- 1 file changed, 2 insertions(+), 20 deletions(-) diff --git a/sauron-service/Dockerfile b/sauron-service/Dockerfile index 74eca06..5d77ea3 100644 --- a/sauron-service/Dockerfile +++ b/sauron-service/Dockerfile @@ -1,22 +1,6 @@ FROM eclipse-temurin:11-jre AS java-dist FROM node:24-slim AS node-dist FROM anchore/syft:v1.42.3 AS syft-dist -# TODO remove this stage once https://github.com/CycloneDX/cyclonedx-node-yarn/pull/490 is merged -FROM node-dist AS cyclonedx-yarn - -RUN corepack enable yarn - -RUN yarn set version 4.13.0 - -RUN apt-get update && apt-get install -y --no-install-recommends git - -RUN GIT_SSL_NO_VERIFY=true git clone -b support-package-lock-only https://github.com/molikuner/cyclonedx-node-yarn.git /cyclonedx - -WORKDIR /cyclonedx - -RUN yarn install --immutable - -RUN yarn run build # Consolidated Tooling Image with Python, Node, and Syft (SBOM Generator) FROM python:3.11-slim AS sauron-tooling @@ -49,10 +33,8 @@ RUN python -m pip install --upgrade pip && \ ENV PATH="/usr/local/bin:${PATH}" # Install cyclonedx yarn plugin -# TODO Instead of copying from custom build above, use the download below after merge of https://github.com/CycloneDX/cyclonedx-node-yarn/pull/490 -COPY --from=cyclonedx-yarn /cyclonedx/bundles/@yarnpkg/plugin-cyclonedx.js /yarn-plugins/cyclonedx.js -#RUN mkdir -p /yarn-plugins && \ -# curl --silent --location https://github.com/CycloneDX/cyclonedx-node-yarn/releases/download/v3.3.1/yarn-plugin-cyclonedx.cjs > /yarn-plugins/cyclonedx.js +RUN mkdir -p /yarn-plugins && \ + curl --silent --fail --location https://github.com/CycloneDX/cyclonedx-node-yarn/releases/download/v3.4.0/yarn-plugin-cyclonedx.cjs > /yarn-plugins/cyclonedx.js ENV YARN_PLUGINS=/yarn-plugins/cyclonedx.js