aboutcode-org / aboutcode-org/scancode-toolkit

Use Scancode to generate an SBOM for scancode-toolkit sdist but nothing about dependencies included in the SBOM

Đang mở
#3,878 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
bug
Ngôn ngữ chính
Python
Star
2.6k
Fork
791
Merge trung bình
1 ngày 12 giờ
Pull request đã merge (30 ngày)
5

Mô tả

### Description

> Please leave a brief description of the bug or feature request:
I use scancode binary to generate SBOM for scancode-toolkit source distribution downloaded from pypi, but there's nothing about dependencies both in spdx and cyclonedx SBOM.(only package information, file information and metadata.)

### How To Reproduce

> Tell us how to reproduce the issue.

scancode -p -l -c -i -e -u --cyclonedx ~/cdx.json ./example/scancode-toolkit-32.2.1 -n 16

### System configuration

> For bug reports, it really helps us to know:

* What OS are you running on? (Windows/MacOS/Linux)
Linux
* What version of scancode-toolkit was used to generate the scan file?
32.2.1
* What installation method was used to install/run scancode? (pip/source download/other)
pip and binary download both

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Đánh giá

Issue này chưa được đánh giá.

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.