Skip to content

Cargo fingerprint doesn't include SBOM #15695

Open
@tofay

Description

@tofay

Problem

If you do a build without setting CARGO_BUILD_SBOM=true, then do the same build except this time setting CARGO_BUILD_SBOM=true, then no SBOM is generated.

Actual behaviour

$ cargo init foo
$ cd foo
$ cargo +nightly build
...
$ CARGO_BUILD_SBOM=true cargo +nightly -Z sbom build
...
$ ls target/debug/
build  deps  examples  foo  foo.d  incremental

Expected behaviour

I expect the second build to generate an SBOM file for foo.

Steps

No response

Possible Solution(s)

No response

Notes

No response

Version

cargo 1.89.0-nightly (fc1518ef0 2025-06-06)

Metadata

Metadata

Assignees

No one assigned

    Labels

    A-rebuild-detectionArea: rebuild detection and fingerprintingC-bugCategory: bugS-triageStatus: This issue is waiting on initial triage.

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions