aboutcode-org / aboutcode-org/scancode-toolkit
CDX License Support
- Dominant language
- Python
- Stars
- 2.6k
- Forks
- 791
- Avg merge
- 1d 12h
- Merged PRs (30d)
- 5
Description
[scancode_cyclone.json](https://github.com/user-attachments/files/18147075/scancode_cyclone.json)
### Description
I experimented with the sbom cyclonedx format in order to import it into 4.12 Dependency track web app (https://dependencytrack.org/). Attached you can find a cyclonedx json sbom created on a project via --package --cyclonedx=scancode_cyclone.json -n 4 options with Scancode toolkit. The json schema can’t be imported into the web app and fails also the validation via cyclonedx-cli. I was just going deeper in finding the differences in the schemas comparing with other cyclone dx bom examples that I managed to import correctly. Has anybody reported this problem? I have seen in one of your presentation online on slideshares that as a roadmap you’re going to adapt more and more this standard.
### System configuration
* What OS are you running on? I tried locally on Windows and Linux
* What version of scancode-toolkit was used to generate the scan file? Latest
* What installation method was used to install/run scancode? (pip/source download/other) Via pip
Contributor guide
Assessment
This issue has not been assessed yet.