Exercise sec-sbom — an SBOM parser and a dependency-confusion checker

Parse the CycloneDX shape Supply-chain SBOM just walked, build the dependency graph from its dependencies array, and write find_confusion so it flags an internal-looking name that is already claimable on the public index — including one that's two hops down, not just a direct dependency. This mirrors the actual job task: a supply-chain check that only reads the top-level manifest misses exactly the risk that matters. It runs on your Mac, not in the browser.

~90 minruns locally · uv + pytest 6 checkssec-sbom

What you're building

The tests are ordinary pytest and ship in the public folder with the starter — read them first; the names below are the check list. Solutions are not published.

Get the repo (once)

Needs git. uv installs the right Python itself, so nothing else is required.

# once, anywhere on your machine
git clone https://github.com/theDocWho/ai-ml-roadmap.git
cd ai-ml-roadmap

No git? Download the ZIP, unzip it, and cd into the unzipped folder instead.

Run it

From the repo root:

# one-time: uv (https://docs.astral.sh/uv/) manages the venv and pins Python ≥ 3.12
cd exercises/sec-sbom && uv sync && uv run pytest -q

Done when uv run pytest -q prints 6 passed. The untouched starter fails all 6 — every function is ....

The checks

The last four all run against the same six-component SBOM fixture — the first is the baseline verdict (a direct public match flagged, an unpublished internal name spared), and the other three each isolate one way a plausible find_confusion gets it wrong: a substring match instead of a true prefix, comparing names without normalizing them, and stopping at the root's direct dependencies instead of walking the whole graph.

Files

This is self-attestation — the site cannot see your terminal, so the box and the button are you telling The Path the suite went green on your machine.

If you get stuck