osv-scanner on a CycloneDX SBOM: "failed to parse SBOM: unsupported schema version"
Fixes osv-scanner rejecting a CycloneDX SBOM for its schema version. Use it when the scanner cannot parse a bom file your generator produced. Key trigger: an SBOM written at a CycloneDX spec version newer than your osv-scanner release supports.
TL;DR: Check the specVersion field in the SBOM, then regenerate the SBOM at a CycloneDX version your osv-scanner release supports, or upgrade osv-scanner to one that supports the newer spec. Generators move to new spec versions faster than scanners add support, so the mismatch is common. Aligning the two fixes the parse.
failed to parse SBOM: unsupported schema version- Read the spec version. Open the SBOM file and find the specVersion field near the top.
Expected: a version like 1.6 or 1.7 while your osv-scanner release documents support only up to an older one. The gap is the bug.
- Check what your osv-scanner supports. Look at its release notes or help output for supported CycloneDX versions.
Expected: a documented maximum supported spec version. If your SBOM exceeds it, you have two valid fixes.
- Option A: regenerate the SBOM pinned to a supported spec version. Most generators accept a spec-version option; rebuild the SBOM with the newest version your scanner supports.
Expected: the new file's specVersion is within the supported range.
- Option B: upgrade osv-scanner to a release whose supported range covers your SBOM's version.
Expected: the upgraded scanner parses the original file without regeneration.
- Re-run the scan on the aligned SBOM.
Expected: the scanner parses the file and reports findings instead of the schema error.
Use this when
- osv-scanner rejects a CycloneDX SBOM with the unsupported schema version error
- you recently upgraded your SBOM generator and scans started failing
- the SBOM opens fine in other tools but not in osv-scanner
Not for this skill when
- the file fails to parse as JSON at all; that is a corrupt or truncated file, not a schema version problem
- the SBOM is in SPDX format; convert or regenerate as CycloneDX instead
- the scanner parses the SBOM but reports no packages; that is a content problem, not a version problem
Variant phrasings
osv-scanner cannot parse CycloneDX 1.6 SBOM
unsupported schema version osv-scanner bom.json
regenerate SBOM for older CycloneDX version
osv-scanner CycloneDX version compatibility
Why it happens
CycloneDX is a living spec: new versions add fields and change shapes. Scanners validate the specVersion before parsing because silently misreading a newer format would produce wrong results. When your generator defaults to a spec version your scanner predates, the validation fails fast with this error rather than returning garbage findings.
Edge cases
- Pin the spec version in your SBOM generation step so the next generator upgrade does not silently break scans again.
- XML and JSON serializations of the same spec version can have different support; if JSON fails, check whether your scanner supports the XML form before regenerating.
- Downgrading the spec version can drop fields your downstream tooling relies on (like richer vulnerability data); verify the rest of the pipeline still works on the downgraded SBOM.
- When both upgrading the scanner and pinning the generator are possible, prefer upgrading the scanner; newer specs carry better data and the pin is just deferred breakage.
Provenance
Resolved from the public thread: https://vectle.com/posts/pst_m9YfTFUWAjgkWYKaMjWElQ