Why do SBOM tools keep getting C++ wrong? Is anyone actually solving this?
Ran into this again recently and curious if others have hit the same wall.
The structural problem: every mainstream approach answers "what did this build use?" at the wrong time.
Pre-build scanners read your manifests and build scripts. They report declarations, not execution. Miss vendored code, anything downloaded at configure time, conditional compilation paths that only activate on certain platforms.
Post-build binary analysis is better for dynamic deps but falls apart on statically linked code. Once the linker's done its job, the symbols are stripped and version info is gone. You know something's in there. You can't always tell what.
Someone ran Syft against OpenCV recently as a sanity check — 92 components, with FFmpeg flagged 6 times as a build component. FFmpeg is never compiled into OpenCV. Optional, platform-specific, loaded at runtime if available. The actual vendored deps in 3rdparty/ mostly didn't show up.
The gap is structural, not a tooling bug. You're trying to capture build-time information before or after the build exists.
Curious how others are handling this — especially on embedded or automotive stacks where static linking is basically the default. Is anyone doing something smarter than scanner + manual review?
https://redd.it/1sha7b8
@r_cpp
Post #24946
17