aboutcode-org / aboutcode-org/scancode-toolkit

Use Scancode to generate an SBOM for scancode-toolkit sdist but nothing about dependencies included in the SBOM

Abierto
#3,878 0 comentarios 0 reacciones 0 asignados Ver en GitHub
bug
Lenguaje dominante
Python
Estrellas
2.6k
Forks
791
Merge medio
1 d 12 h
PR fusionados (30 d)
5

Descripción

### Description

> Please leave a brief description of the bug or feature request:
I use scancode binary to generate SBOM for scancode-toolkit source distribution downloaded from pypi, but there's nothing about dependencies both in spdx and cyclonedx SBOM.(only package information, file information and metadata.)

### How To Reproduce

> Tell us how to reproduce the issue.

scancode -p -l -c -i -e -u --cyclonedx ~/cdx.json ./example/scancode-toolkit-32.2.1 -n 16

### System configuration

> For bug reports, it really helps us to know:

* What OS are you running on? (Windows/MacOS/Linux)
Linux
* What version of scancode-toolkit was used to generate the scan file?
32.2.1
* What installation method was used to install/run scancode? (pip/source download/other)
pip and binary download both

Guía de contribución

Abrir la guía de contribución

Evaluación

Este issue todavía no se ha evaluado.

Recibe los nuevos issues en tu correo

Un resumen breve de issues de GitHub para principiantes.