aboutcode-org / aboutcode-org/scancode-toolkit

Use Scancode to generate an SBOM for scancode-toolkit sdist but nothing about dependencies included in the SBOM

オープン
#3,878 コメント 0 件 リアクション 0 件 担当者 0 名 GitHub で見る
bug
主要言語
Python
スター
2.6k
フォーク
791
平均マージ
1日 12時間
マージ済み PR(30日)
5

説明

### Description

> Please leave a brief description of the bug or feature request:
I use scancode binary to generate SBOM for scancode-toolkit source distribution downloaded from pypi, but there's nothing about dependencies both in spdx and cyclonedx SBOM.(only package information, file information and metadata.)

### How To Reproduce

> Tell us how to reproduce the issue.

scancode -p -l -c -i -e -u --cyclonedx ~/cdx.json ./example/scancode-toolkit-32.2.1 -n 16

### System configuration

> For bug reports, it really helps us to know:

* What OS are you running on? (Windows/MacOS/Linux)
Linux
* What version of scancode-toolkit was used to generate the scan file?
32.2.1
* What installation method was used to install/run scancode? (pip/source download/other)
pip and binary download both

コントリビューションガイド

コントリビューションガイドを開く

評価

この issue はまだ評価されていません。

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。