diff --git a/contrib/fine-tuning/cdxgen-docs/cli.jsonl b/contrib/fine-tuning/cdxgen-docs/cli.jsonl index e5db0b9eb..febb3d4d1 100644 --- a/contrib/fine-tuning/cdxgen-docs/cli.jsonl +++ b/contrib/fine-tuning/cdxgen-docs/cli.jsonl @@ -7,7 +7,7 @@ {"messages": [{"role": "user", "content": "How do I use the cdxgen-deno container image?"}, {"role": "assistant", "content": "Run the command docker run --rm -v /tmp:/tmp -v $(pwd):/app:rw -t ghcr.io/cyclonedx/cdxgen-deno -r /app -o /app/bom.json."}]} {"messages": [{"role": "user", "content": "How do I get help with cdxgen's CLI?"}, {"role": "assistant", "content": "Run the command cdxgen -h."}]} {"messages": [{"role": "user", "content": "What is the purpose of the -o or --output option?"}, {"role": "assistant", "content": "It specifies the output file for the generated SBOM. The default is bom.json."}]} -{"messages": [{"role": "user", "content": "What is the purpose of the -t or --type option?"}, {"role": "assistant", "content": "It specifies the project type. Refer to the documentation for supported languages/platforms."}]} +{"messages": [{"role": "user", "content": "What is the purpose of the -t or --type option?"}, {"role": "assistant", "content": "It specifies the project type. Refer to the documentation for supported languages/platforms. cdxgen automatically detects the project types, so this option can be ignored."}]} {"messages": [{"role": "user", "content": "What is the purpose of the --exclude-type option?"}, {"role": "assistant", "content": "It specifies project types to exclude. Refer to the documentation for supported languages/platforms."}]} {"messages": [{"role": "user", "content": "What is the purpose of the -r or --recurse option?"}, {"role": "assistant", "content": "It enables or disables recursive mode, which is suitable for mono-repos. It defaults to true. Pass --no-recurse to disable it."}]} {"messages": [{"role": "user", "content": "What is the purpose of the -p or --print option?"}, {"role": "assistant", "content": "It prints the SBOM as a table with a tree structure."}]} @@ -46,4 +46,98 @@ {"messages": [{"role": "user", "content": "What are the possible values for --technique?", "role": "assistant", "content": "Possible values: auto, source-code-analysis, binary-analysis, manifest-analysis, hash-comparison, instrumentation, filename."}]} {"messages": [{"role": "user", "content": "What is the purpose of the --auto-compositions option?"}, {"role": "assistant", "content": "Automatically set compositions when the BOM was filtered. Defaults to true."}]} {"messages": [{"role": "user", "content": "If a boolean argument has --no prefix, what does it mean?", "role": "assistant", "content": "All boolean arguments accept --no prefix to toggle the behavior."}]} -{"messages": [{"role": "user", "content": "What is the purpose of the --skip-dt-tls-check option?", "role": "assistant", "content": "Skip TLS certificate check when calling Dependency-Track. Defaults to false."}]} \ No newline at end of file +{"messages": [{"role": "user", "content": "What is the purpose of the --skip-dt-tls-check option?", "role": "assistant", "content": "Skip TLS certificate check when calling Dependency-Track. Defaults to false."}]} +{"messages": [{"role": "user", "content": "What are the supported project types for Node.js?"}, {"role": "assistant", "content": "The supported project types for Node.js are: `npm`, `pnpm`, `nodejs`, `js`, `javascript`, `typescript`, `ts`, `tsx`, `yarn`, and `rush`. These can be used with the `-t` or `--type` flag in CLI mode, or as the `projectType` parameter in Server mode."}]} +{"messages": [{"role": "user", "content": "What package formats are supported for Node.js projects?"}, {"role": "assistant", "content": "For Node.js projects, the following package formats are supported: `npm-shrinkwrap.json`, `package-lock.json`, `pnpm-lock.yaml`, `yarn.lock`, `rush.js`, `bower.json`, and `.min.js`."}]} +{"messages": [{"role": "user", "content": "Does cdxgen support transitive dependencies for Node.js projects?"}, {"role": "assistant", "content": "Yes, cdxgen supports transitive dependencies for Node.js projects, except for `.min.js` files."}]} +{"messages": [{"role": "user", "content": "What are the specific Node.js version project types?"}, {"role": "assistant", "content": "Specific Node.js version project types include: `node8`, `node10`, `node12`, `node14`, `node16`, `node18`, `node20`, `node22`, `node23`, `nodejs8`, `nodejs10`, `nodejs12`, `nodejs14`, `nodejs16`, `nodejs18`, `nodejs20`, `nodejs22`, and `nodejs23`. cdxgen automatically installs the appropriate version of the Node runtime when the `nvm` tool is installed and available. The cdxgen container images, such as the default `CycloneDX/cdxgen` and `cdxgen-node20`, come with the `nvm` tool already bundled."}]} +{"messages": [{"role": "user", "content": "What are the supported project types for Java?"}, {"role": "assistant", "content": "The supported project types for Java are: `java`, `groovy`, `kotlin`, `scala`, `jvm`, `gradle`, `mvn`, `maven`, `sbt`, and `quarkus`."}]} +{"messages": [{"role": "user", "content": "What package formats are used with Java projects?"}, {"role": "assistant", "content": "Java projects use the following package formats: `pom.xml`, `build.gradle`, `.kts`, `sbt`, and `bazel`."}]} +{"messages": [{"role": "user", "content": "Are transitive dependencies supported for Java?"}, {"role": "assistant", "content": "Yes, transitive dependencies are supported for Java, unless `pom.xml` is manually parsed due to the unavailability of Maven or errors."}]} +{"messages": [{"role": "user", "content": "What are the specific Java version project types?"}, {"role": "assistant", "content": "Specific Java version project types include: `java8`, `java11`, `java17`, `java21`, `java22`, and `java23`. cdxgen automatically installs the appropriate version of the Java runtime when the `sdkman` tool is installed and available. The cdxgen container images, such as the default `CycloneDX/cdxgen` and `cdxgen-java17`, come with the `sdkman` tool already bundled."}]} +{"messages": [{"role": "user", "content": "What project types are available for Android?"}, {"role": "assistant", "content": "For Android, the project types are: `android`, `apk`, and `aab`. The SBOM is generated by invoking the OWASP blint tool, which is bundled with certain container images, such as `CycloneDX/cdxgen`."}]} +{"messages": [{"role": "user", "content": "What is the project type for standalone JAR files?"}, {"role": "assistant", "content": "The project type for standalone JAR files is `jar`."}]} +{"messages": [{"role": "user", "content": "What package format is supported for the `jar` project type?"}, {"role": "assistant", "content": "The `jar` project type supports the `.jar` package format."}]} +{"messages": [{"role": "user", "content": "What are the project types for analyzing JAR files in Gradle, SBT, and Maven caches?"}, {"role": "assistant", "content": "The project types are `gradle-index` or `gradle-cache` for Gradle, `sbt-index` or `sbt-cache` for SBT, and `maven-index`, `maven-cache`, or `maven-repo` for Maven."}]} +{"messages": [{"role": "user", "content": "What are the typical file paths for JARs in Gradle, SBT, and Maven caches?"}, {"role": "assistant", "content": "Gradle cache: `$HOME/caches/modules-2/files-2.1/**/\\*.jar`, SBT cache: `$HOME/.ivy2/cache/**/\\*.jar`, Maven cache: `$HOME/.m2/repository/**/\\*.jar`"}]} +{"messages": [{"role": "user", "content": "What are the supported project types for Python?"}, {"role": "assistant", "content": "Supported Python project types are: `python`, `py`, `pypi`, `uv`, `pip`, `poetry`, `pdm`, and `hatch`."}]} +{"messages": [{"role": "user", "content": "What package formats are supported for Python projects?"}, {"role": "assistant", "content": "Python projects support these package formats: `pyproject.toml`, `setup.py`, `requirements.txt`, `Pipfile.lock`, `poetry.lock`, `pdm.lock`, `uv.lock`, `bdist_wheel`, `.whl`, and `.egg-info`."}]} +{"messages": [{"role": "user", "content": "Does cdxgen support transitive dependencies for Python?"}, {"role": "assistant", "content": "Yes, cdxgen supports transitive dependencies for Python using automatic pip install/freeze. When disabled, it supports transitive dependencies with `Pipfile.lock`, `pdm.lock`, `uv.lock`, and `poetry.lock`."}]} +{"messages": [{"role": "user", "content": "What are the specific Python version project types?"}, {"role": "assistant", "content": "Specific Python version project types include: `python36`, `python38`, `python39`, `python310`, `python311`, and `python312`."}]} +{"messages": [{"role": "user", "content": "What project types are supported for Golang?"}, {"role": "assistant", "content": "The supported project types for Golang are: `go` and `golang`."}]} +{"messages": [{"role": "user", "content": "What package formats are supported for Golang?"}, {"role": "assistant", "content": "Golang supports these package formats: `binary`, `go.mod`, `go.sum`, and `Gopkg.lock`."}]} +{"messages": [{"role": "user", "content": "Are transitive dependencies supported for Golang?"}, {"role": "assistant", "content": "Yes, transitive dependencies are supported for Golang, except for `binary`."}]} +{"messages": [{"role": "user", "content": "What are the project types for Rust?"}, {"role": "assistant", "content": "The project types for Rust are: `rust`, `rust-lang`, and `cargo`."}]} +{"messages": [{"role": "user", "content": "What package formats does Rust support?"}, {"role": "assistant", "content": "Rust supports these package formats: `binary`, `Cargo.toml`, and `Cargo.lock`."}]} +{"messages": [{"role": "user", "content": "Are transitive dependencies supported for Rust?"}, {"role": "assistant", "content": "Transitive dependencies are only supported for `Cargo.lock` in Rust."}]} +{"messages": [{"role": "user", "content": "What are the project types for Ruby?"}, {"role": "assistant", "content": "Project types for Ruby include: `ruby`, `gems`, `rubygems`, `bundler`, `rb`, and `gemspec`."}]} +{"messages": [{"role": "user", "content": "What package formats are supported for Ruby?"}, {"role": "assistant", "content": "Ruby supports `Gemfile.lock` and `gemspec` package formats."}]} +{"messages": [{"role": "user", "content": "Are transitive dependencies supported for Ruby projects?"}, {"role": "assistant", "content": "Transitive dependencies are only supported for `Gemfile.lock` in Ruby projects."}]} +{"messages": [{"role": "user", "content": "What are the specific Ruby version project types?"}, {"role": "assistant", "content": "Specific Ruby version project types follow the format `ruby*`. Examples include `ruby2.5.4` and `ruby3.4.0`."}]} +{"messages": [{"role": "user", "content": "What are the project types for PHP?"}, {"role": "assistant", "content": "The supported project types for PHP are: `php` and `composer`."}]} +{"messages": [{"role": "user", "content": "What is the supported package format for PHP?"}, {"role": "assistant", "content": "PHP supports the `Composer.lock` package format."}]} +{"messages": [{"role": "user", "content": "Does cdxgen support transitive dependencies for PHP?"}, {"role": "assistant", "content": "Yes, cdxgen supports transitive dependencies for PHP."}]} +{"messages": [{"role": "user", "content": "What are the project types for .NET (#C)?"}, {"role": "assistant", "content": "Project types for .NET include: `csharp`, `netcore`, `dotnet`, `vb`, and `dotnet-framework`."}]} +{"messages": [{"role": "user", "content": "What package formats are supported for .NET?"}, {"role": "assistant", "content": ".NET supports these package formats: `.csproj`, `.vbproj`, `.fsproj`, `packages.config`, `project.assets.json`, `packages.lock.json`, `.nupkg`, `paket.lock`, and `binary`."}]} +{"messages": [{"role": "user", "content": "Are transitive dependencies supported for .NET?"}, {"role": "assistant", "content": "Transitive dependencies are supported for .NET only with `project.assets.json`, `packages.lock.json`, and `paket.lock`."}]} +{"messages": [{"role": "user", "content": "What project types are available for Dart?"}, {"role": "assistant", "content": "For Dart, the project types are: `dart`, `flutter`, and `pub`."}]} +{"messages": [{"role": "user", "content": "What package formats are supported for Dart?"}, {"role": "assistant", "content": "Dart supports `pubspec.lock` and `pubspec.yaml` package formats."}]} +{"messages": [{"role": "user", "content": "Are transitive dependencies supported for Dart?"}, {"role": "assistant", "content": "Transitive dependencies are supported only for `pubspec.lock` in Dart."}]} +{"messages": [{"role": "user", "content": "What are the project types for Haskell?"}, {"role": "assistant", "content": "Project types for Haskell include: `haskell`, `hackage`, and `cabal`."}]} +{"messages": [{"role": "user", "content": "What is the supported package format for Haskell?"}, {"role": "assistant", "content": "Haskell supports the `cabal.project.freeze` package format."}]} +{"messages": [{"role": "user", "content": "Does cdxgen support transitive dependencies for Haskell?"}, {"role": "assistant", "content": "Yes, cdxgen supports transitive dependencies for Haskell."}]} +{"messages": [{"role": "user", "content": "What project types are supported for Elixir?"}, {"role": "assistant", "content": "For Elixir, the project types are: `elixir`, `hex`, and `mix`."}]} +{"messages": [{"role": "user", "content": "What package format is supported for Elixir?"}, {"role": "assistant", "content": "Elixir supports the `mix.lock` package format."}]} +{"messages": [{"role": "user", "content": "Does cdxgen support transitive dependencies for Elixir?"}, {"role": "assistant", "content": "Yes, cdxgen supports transitive dependencies for Elixir."}]} +{"messages": [{"role": "user", "content": "What are the project types for C++?"}, {"role": "assistant", "content": "Project types for C++ include: `c`, `cpp`, `c++`, and `conan`."}]} +{"messages": [{"role": "user", "content": "What package formats are supported for C++?"}, {"role": "assistant", "content": "C++ supports these formats: `conan.lock`, `conanfile.txt`, `*.cmake`, `CMakeLists.txt`, and `meson.build`. It also supports codebases without package managers."}]} +{"messages": [{"role": "user", "content": "Are transitive dependencies supported for C++?"}, {"role": "assistant", "content": "Yes, transitive dependencies are supported for C++ only with `conan.lock`. CMake support is on a best-effort basis without version numbers."}]} +{"messages": [{"role": "user", "content": "What project types are supported for Clojure?"}, {"role": "assistant", "content": "For Clojure, project types include: `clojure`, `edn`, `clj`, and `leiningen`."}]} +{"messages": [{"role": "user", "content": "What package formats does Clojure support?"}, {"role": "assistant", "content": "Clojure supports `deps.edn` and `project.clj` package formats."}]} +{"messages": [{"role": "user", "content": "Does cdxgen support transitive dependencies for Clojure?"}, {"role": "assistant", "content": "Yes, unless the files are parsed manually due to a lack of the Clojure CLI or Leiningen command."}]} +{"messages": [{"role": "user", "content": "What project types are associated with GitHub Actions?"}, {"role": "assistant", "content": "The project types for GitHub Actions are: `github` and `actions`."}]} +{"messages": [{"role": "user", "content": "What file format is used for GitHub Actions?"}, {"role": "assistant", "content": "GitHub Actions uses `.github/workflows/*.yml` files."}]} +{"messages": [{"role": "user", "content": "What project types are available for identifying installed operating system packages?"}, {"role": "assistant", "content": "For identifying operating system packages, the project types are: `os`, `osquery`, `windows`, `linux`, `mac`, `macos`, and `darwin`."}]} +{"messages": [{"role": "user", "content": "What is the project type for Jenkins plugins?"}, {"role": "assistant", "content": "The project type for Jenkins plugins is `jenkins`."}]} +{"messages": [{"role": "user", "content": "What is the package format for Jenkins plugins?"}, {"role": "assistant", "content": "Jenkins plugins use the `.hpi` file format."}]} +{"messages":[{"role": "user", "content": "What are the supported project types for analyzing helm charts?"}, {"role": "assistant", "content": "The supported project types for Helm are: `helm` and `charts`."}]} +{"messages":[{"role": "user", "content": "What file format is used for standard Helm charts?"}, {"role": "assistant", "content": "Helm charts commonly uses `.yaml` files."}]} +{"messages":[{"role": "user", "content": "What are the project types for analyzing Helm charts in cache?"}, {"role": "assistant", "content": "The project types for analyzing Helm charts cache are: `helm-index` and `helm-repo`."}]} +{"messages":[{"role": "user", "content": "What is the typical file paths for Helm charts in cache?"}, {"role": "assistant", "content": "Helm cache uses this format: `$HOME/.cache/helm/repository/*/*.yaml`."}]} +{"messages":[{"role": "user", "content": "What are the project types for containers?"}, {"role": "assistant", "content": "The project types for containers are `oci`, `docker`, `podman`, and `container`."}]} +{"messages":[{"role": "user", "content": "What are the project types for analyzing container-related configuration files?"}, {"role": "assistant", "content": "Project types for container-related files include: `universal`, `containerfile`, `docker-compose`, `dockerfile`, `swarm`, `tekton`, `kustomize`, `operator`, `skaffold`, `kubernetes`, `openshift`, and `yaml-manifest`."}]} +{"messages":[{"role": "user", "content": "What file formats are supported for container-related project types?"}, {"role": "assistant", "content": "Supported formats include: `.yaml`, `docker-compose*.yml`, `*Dockerfile*`, `*Containerfile*`, and `bitbucket-pipelines.yml`."}]} +{"messages":[{"role": "user", "content": "What is the project type for Google Cloud Build?"}, {"role": "assistant", "content": "The project type for Google Cloud Build is `cloudbuild`."}]} +{"messages":[{"role": "user", "content": "What file format does Google Cloud Build use?"}, {"role": "assistant", "content": "Google Cloud Build uses the `cloudbuild.yaml` file format."}]} +{"messages":[{"role": "user", "content": "What is the project type for Swift (iOS)?"}, {"role": "assistant", "content": "The project type for Swift is `swift`."}]} +{"messages":[{"role": "user", "content": "What package formats are supported for Swift?"}, {"role": "assistant", "content": "Swift supports `Package.resolved` and `Package.swift` (swiftpm) package formats."}]} +{"messages":[{"role": "user", "content": "Does cdxgen supports transitive dependencies for Swift?"}, {"role": "assistant", "content": "Yes, cdxgen supports transitive dependencies for Swift."}]} +{"messages":[{"role": "user", "content": "What are the project types for identifying binary files?"}, {"role": "assistant", "content": "The project types for binary files are `binary` and `blint`."}]} +{"messages":[{"role": "user", "content": "What project type should I use for Open API specifications?"}, {"role": "assistant", "content": "Use the `yaml-manifest` project type for Open API specifications."}]} +{"messages":[{"role": "user", "content": "What file formats are supported for Open API specifications?"}, {"role": "assistant", "content": "Supported formats for Open API are: `openapi*.json` and `openapi*.yaml`."}]} +{"messages":[{"role": "user", "content": "What tools are required for parsing pom.xml files?"}, {"role": "assistant", "content": "Apache Maven 3.x is required for parsing `pom.xml` files."}]} +{"messages":[{"role": "user", "content": "What is required to parse Gradle projects?"}, {"role": "assistant", "content": "`gradle` or `gradlew` is required to parse Gradle projects."}]} +{"messages":[{"role": "user", "content": "How is Quarkus support handled in cdxgen?"}, {"role": "assistant", "content": "The Quarkus plugin is automatically detected and used when parsing `pom.xml` files (since cdxgen version 11.0.5). You can also explicitly specify it with `-t quarkus`, especially when using `--no-recurse`."}]} +{"messages":[{"role": "user", "content": "What is required for parsing Scala SBT projects?"}, {"role": "assistant", "content": "`sbt` is required. Only Scala 2.10 + sbt 0.13.6+ and 2.12 + sbt 1.0+ are currently supported. Alternatively, create a lock file using the sbt-dependency-lock plugin."}]} +{"messages":[{"role": "user", "content": "What is required to use Java version-specific types like java8, java11, etc.?"}, {"role": "assistant", "content": "`sdkman` must be installed and set up to use the new Java with version types."}]} +{"messages":[{"role": "user", "content": "What version of Python is required for dependency tree construction when using python36?"}, {"role": "assistant", "content": "While `python3.6` is supported (`-t python36`), dependency tree construction requires Python >= 3.9."}]} +{"messages":[{"role": "user", "content": "What is required to use Ruby version-specific types like ruby2.5.4?"}, {"role": "assistant", "content": "`rbenv` must be installed and set up to use the specific Ruby version."}]} +{"messages":[{"role": "user", "content": "What is the recommended way to use cdxgen, especially with projects requiring specific build tools?"}, {"role": "assistant", "content": "Using the container images is recommended, as it has the build tools pre-installed."}]} +{"messages":[{"role": "user", "content": "What is a caveat for multi-module Java applications?"}, {"role": "assistant", "content": "For multi-module applications, the BOM file could include components not included in the packaged `war` or `ear` file."}]} +{"messages":[{"role": "user", "content": "What is required to get indirect dependencies for .NET projects?"}, {"role": "assistant", "content": "Perform `dotnet` or `nuget restore` to generate `project.assets.json`. Without this file, cdxgen will not include indirect dependencies."}]} +{"messages":[{"role": "user", "content": "What is osquery used for in cdxgen?"}, {"role": "assistant", "content": "osquery is to gather information about the Operation System packages."}]} +{"messages":[{"role": "user", "content": "How can I see a visual representation of the dependency tree generated by cdxgen?"}, {"role": "assistant", "content": "There is an image included in the document, `_media/cdxgen-tree.jpg`, that shows a visual representation of a cdxgen tree. Although details can not be extracted from it."}]} +{"messages":[{"role": "user", "content": "If I pass 'npm' as project type in CLI mode, how should I specify it?"}, {"role": "assistant", "content": "You can specify it using either `-t npm` or `--type npm` as a flag."}]} +{"messages":[{"role": "user", "content": "In Server mode, what parameter should be used to pass the project type?"}, {"role": "assistant", "content": "In Server mode, the project type is passed using the `projectType` parameter."}]} +{"messages":[{"role": "user", "content": "Are there any project types that produce the same output?"}, {"role": "assistant", "content": "Yes, there are multiple project types or aliases that will produce the same output. For example, `npm`, `nodejs`, and `js` for Node.js projects may all yield similar results."}]} +{"messages":[{"role": "user", "content": "What does 'transitive' mean in the context of dependencies?"}, {"role": "assistant", "content": "Transitive dependencies refer to the dependencies of your project's dependencies, and so on. It represents the full graph of libraries and frameworks that your project indirectly relies upon."}]} +{"messages":[{"role": "user", "content": "Which project types do NOT support transitive dependencies?"}, {"role": "assistant", "content": "Based on the table, the following project types do not support transitive dependencies or their support is limited:\n\n* **Node.js:** `.min.js`\n* **Android:** `android`, `apk`, `aab`\n* **JAR:** `jar`\n* **JAR (Gradle/SBT/Maven Cache):** `gradle-index`, `gradle-cache`, `sbt-index`, `sbt-cache`, `maven-index`, `maven-cache`, `maven-repo`\n* **Rust:** `binary` (Only `Cargo.lock` supports transitive dependencies)\n* **Ruby:** Only for `Gemfile.lock`\n* **.NET:** Only for `project.assets.json`, `packages.lock.json`, `paket.lock`\n* **Dart:** Only for `pubspec.lock`\n* **Helm (Cache):** helm-index, helm-repo\n* **Container:** oci, docker, podman, container\n* **Container File:** N/A"}]} +{"messages":[{"role": "user", "content": "Is it possible for cdxgen to produce an empty BOM?"}, {"role": "assistant", "content": "While the documentation doesn't explicitly state that an empty BOM *cannot* be produced, certain scenarios could lead to a very minimal or potentially empty BOM. This could happen if:\n\n* The project type is not correctly identified.\n* The project has no dependencies (uncommon, but possible).\n* Required build tools are missing (e.g., Maven for `pom.xml` files).\n* There are errors during dependency resolution.\n* A project type that does not resolve dependencies is used with no supported files. (binary)"}]} +{"messages":[{"role": "user", "content": "What is the difference between the project types 'nodejs' and 'node18'?"}, {"role": "assistant", "content": "`nodejs` is a general project type for Node.js applications, while `node18` is a specific version project type that targets Node.js version 18. Using the specific version can be helpful if your application's dependencies are sensitive to the Node.js runtime version."}]} +{"messages":[{"role": "user", "content": "How can I be sure cdxgen is using the correct version of a build tool, like Maven or Gradle?"}, {"role": "assistant", "content": "The documentation recommends using the container image, as it has the build tools pre-installed and configured. If you're not using the container image, ensure that the required build tools (Maven 3.x, Gradle, sbt, etc.) are in your system's PATH and that the correct versions are being invoked. For some tools like Java, you may need `sdkman` to manage multiple versions."}]} +{"messages":[{"role": "user", "content": "Can I use cdxgen to analyze projects with mixed languages (e.g., a project with both Java and JavaScript)?"}, {"role": "assistant", "content": "The documentation doesn't directly address mixed-language projects. The best approach would be to run cdxgen separately for each language component of your project, using the appropriate project type for each part. For example, use `-t java` for the Java parts and `-t nodejs` for the JavaScript parts. You might then need a separate process to combine the resulting BOMs."}]} +{"messages":[{"role": "user", "content": "Can I analyze a project without a package manager file (e.g., a C++ project with just source code)?"}, {"role": "assistant", "content": "Yes, the C++ project type supports codebases *without* package managers. It will attempt to analyze the code on a best-effort basis, but it's important to note that dependency information (especially version numbers) will likely be limited."}]} +{"messages":[{"role": "user", "content": "If a project type says 'Yes' for transitive dependencies, does that mean it *always* includes *all* transitive dependencies?"}, {"role": "assistant", "content": "Generally yes, but there can be exceptions. The notes mention some cases where transitive dependencies might not be fully resolved, such as when Maven is unavailable for Java projects or when `pip install/freeze` fails for Python. It is a goal to resolve all transitive dependencies."}]} +{"messages":[{"role": "user", "content": "What kind of evidence is collected for Node.js?"}, {"role": "assistant", "content": "The table mentions that except for .min.js, cdxgen collects evidence for other package formats, which includes: `npm-shrinkwrap.json`, `package-lock.json`, `pnpm-lock.yaml`, `yarn.lock`, `rush.js`, and `bower.json`."}]} +{"messages":[{"role": "user", "content": "What's the difference between `dockerfile` and `container` project types?"}, {"role": "assistant", "content": "`container` (`oci`, `docker`, `podman`, `container`) refers to analyzing a *running* container or a container image. `dockerfile` (`containerfile`, `dockerfile`, etc.) refers to analyzing the *Dockerfile* (or similar configuration file) that defines how to *build* a container image. They serve different purposes: one looks at the result, the other looks at the instructions."}]} +{"messages":[{"role": "user", "content": "What output formats does cdxgen support?"}, {"role": "assistant", "content": "CycloneDX json format."}]} \ No newline at end of file diff --git a/contrib/fine-tuning/cdxgen-docs/readme.jsonl b/contrib/fine-tuning/cdxgen-docs/readme.jsonl index f10bcff82..f32d8f0b0 100644 --- a/contrib/fine-tuning/cdxgen-docs/readme.jsonl +++ b/contrib/fine-tuning/cdxgen-docs/readme.jsonl @@ -47,7 +47,7 @@ {"messages": [{"role": "user", "content": "Can I use cdxgen to generate an SBOM for a Docker Compose project?"}, {"role": "assistant", "content": "While cdxgen doesn't directly process Docker Compose files, you can generate SBOMs for each individual container image defined in your docker-compose.yml file."}]} {"messages": [{"role": "user", "content": "I'm working with a very large project. Are there any performance considerations when using cdxgen?"}, {"role": "assistant", "content": "For large projects, consider using the recursive scan option (-r) with caution as it can increase processing time. Also, enabling license fetching (FETCH_LICENSE=true) can significantly slow down the process. You may want to exclude certain directories or files using configuration options if available (consult the more complete documentation not present here) to improve performance."}]} {"messages": [{"role": "user", "content": "How can I contribute to the cdxgen project?"}, {"role": "assistant", "content": "Refer to the cdxgen project's GitHub repository for contribution guidelines. You can contribute by submitting bug reports, feature requests, or code contributions."}]} -{"messages": [{"role": "user", "content": "Can cdxgen identify vulnerabilities directly?"}, {"role": "assistant", "content": "No, cdxgen generates SBOMs, which are lists of components and their dependencies. You can then use other tools, such as Dependency-Track or vulnerability scanners, to analyze the SBOM and identify potential vulnerabilities."}]} +{"messages": [{"role": "user", "content": "Can cdxgen identify vulnerabilities directly?"}, {"role": "assistant", "content": "No, cdxgen generates SBOMs, which are lists of components and their dependencies. You can then use other tools, such as OWASP depscan or vulnerability scanners, to analyze the SBOM and identify potential vulnerabilities."}]} {"messages": [{"role": "user", "content": "I'm using the REPL and want to export the SBOM I created to a file. How do I do this?"}, {"role": "assistant", "content": "Use the .save command followed by the desired file path. For example, .save my_sbom.json will save the current SBOM to a file named my_sbom.json."}]} {"messages": [{"role": "user", "content": "If I have a BOM generated using an older version of CycloneDX, can I import it to the REPL and upgrade it to the current version?"}, {"role": "assistant", "content": "Yes, you can import any CycloneDX BOM using the .import command, and the REPL might automatically upgrade it or allow you to manipulate it using JSONata queries to match the current version's schema. However, ensure you validate the resulting BOM after upgrading."}]} {"messages": [{"role": "user", "content": "Is there a way to see the relationships between components in my SBOM?"}, {"role": "assistant", "content": "The .tree command attempts to visualize the dependency tree, if that information is available in the SBOM. It can help understand how components relate to each other."}]} diff --git a/contrib/xBOMEval/tests/logic/purl1.toml b/contrib/xBOMEval/tests/logic/purl1.toml new file mode 100644 index 000000000..14d3e6ebe --- /dev/null +++ b/contrib/xBOMEval/tests/logic/purl1.toml @@ -0,0 +1,11 @@ +title = "Who knows purl better?" + +prompt = ''' +What is the package URL type for Node applications? Alice says it is 'pkg:node', while Bob claims it is 'pkg:npm'. Meanwhile, Peter believes it could be 'pkg:npm', 'pkg:yarn', or 'pkg:pnpm', depending on the package manager. +''' + +human_answer = ''' +''' + +teacher_model_answer = ''' +''' diff --git a/contrib/xBOMEval/tests/standards/cyclonedx1.toml b/contrib/xBOMEval/tests/standards/cyclonedx1.toml new file mode 100644 index 000000000..6092cda21 --- /dev/null +++ b/contrib/xBOMEval/tests/standards/cyclonedx1.toml @@ -0,0 +1,12 @@ +title = "Software transparency" + +prompt = ''' +Why do we need Software transparency? +''' + +human_answer = ''' +''' + +teacher_model_answer = ''' +''' +