CycloneDX / CycloneDX/cyclonedx-dotnet

BOM should include Framework Components

Open
#836 9 comments 4 reactions 0 assignees View on GitHub
enhancement
Dominant language
C#
Stars
294
Forks
123
PR merge metrics
No merged PRs in 30d

Description

The BOM generated by the tool should also include:

- Framework Component for each TargetFramework and the version is based upon what is installed
- Library Component for both implicit and explicit FrameworkReferences and the version is based upon what is installed.

Contributor guide

Open the contributing guide

Research direction

No files, tests, or entry points are named in the issue. Start by locating the BOM generation logic and existing handling for framework references; then trace how installed versions are discovered for target frameworks and implicit or explicit references. Done means the generated BOM contains the requested framework and library components with installed versions, supported by tests.

Written by the indexing model from the issue text.

Assessment

Tech stack
csharp
Domain
tooling
Issue type
Feature
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.