Skip to main content

Hoppr JQ Filter

A Hoppr plugin to filter components out of the delivered sbom using jq syntax.

It works as the intersect of "includes" and "excludes".

  • Any components not found with the includes will be removed
  • Any components found with the excludes will be removed
  SampleStage:
    plugins:
    - name: "hoppr_jq_filter.plugin"
      config:
        delete_excluded: True
        purl_regex_includes: []
        purl_regex_excludes: []
        jq_expression_includes: []
        jq_expression_excludes: []
  • delete_excluded
    • A flag indicating if the plugin should delete any excluded components found in collect_root_dir
  • purl_regex_includes
    • A list of regular expressions for purls that should remain in the SBOM
  • purl_regex_excludes
    • A list of regular expressions to remove purls that match in the SBOM
  • jq_expression_includes
    • A list of jq expressions for components that should remain in the SBOM
  • jq_expression_excludes
    • A list of jq expressions to remove components that match in the SBOM

Examples

Only keep generic components in the SBOM

  SampleStage:
    plugins:
    - name: "hoppr_jq_filter.plugin"
      config:
        purl_regex_includes:
          - "^pkg:generic"

Remove any purl with controlled in the name

  SampleStage:
    plugins:
    - name: "hoppr_jq_filter.plugin"
      config:
        purl_regex_excludes:
          - "controlled"

Debugging

If you are having trouble filtering out components, you can easily debug using jq directly.

  1. Run hoppr bundle with a -v and review the logs.
  2. This plugin will print all of the jq queries used and the matching purls found.
  3. You can cat your-sbom.cdx.json | jq '<your query>' to debug.

Metadata

Release files for hoppr_jq_filter 0.2.5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for hoppr_jq_filter 0.2.5
File Size Uploaded
hoppr_jq_filter-0.2.5.tar.gz 4.9 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for hoppr_jq_filter 0.2.5
File Interpreter ABI Platform
hoppr_jq_filter-0.2.5-py3-none-any.whl Python 3 none any Details

Total release size: 10.6 kB

Release files / hoppr_jq_filter-0.2.5.tar.gz

Download URL hoppr_jq_filter-0.2.5.tar.gz
Size 4.9 kB
Tags Source
SHA-256 checksum
How to use checksums
e6d95bb38954b11ee2c77d9a042d286962e60286c95ed0f1d81e61b53b77757c
BLAKE2b-256 checksum
How to use checksums
06889b6aa3ac2cbece9781229f88fc253dc1e5dcea3d7c8bd3f3b580fdccf0ee
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.8.2 CPython/3.10.13 Linux/5.4.109+

Release files / hoppr_jq_filter-0.2.5-py3-none-any.whl

Download URL hoppr_jq_filter-0.2.5-py3-none-any.whl
Size 5.7 kB
Tags Python 3
SHA-256 checksum
How to use checksums
bd2ba9572a081c4224e77621779e46c4ab7630a28cecc07474d3cf22d69113e6
BLAKE2b-256 checksum
How to use checksums
c72cdc530eda5174a67d9d3996662bc3477effeee756ebff692fd71aeba79621
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
No
Uploaded via poetry/1.8.2 CPython/3.10.13 Linux/5.4.109+

Release history Release notifications | RSS feed

This release

0.2.5 This release

2 release files

0.2.4

2 release files

0.2.3

2 release files

0.2.2

2 release files

0.2.1

2 release files

0.2.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page