aboutcode-org / aboutcode-org/scancode-toolkit

CDX License Support

未关闭
#4,021 4 条评论 0 个 reaction 已指派 0 人 在 GitHub 查看
bug
主要语言
Python
星标
2.6k
派生
791
平均合并
1 天 12 小时
30 天内合并 PR
5

描述

[scancode_cyclone.json](https://github.com/user-attachments/files/18147075/scancode_cyclone.json)

### Description

I experimented with the sbom cyclonedx format in order to import it into 4.12 Dependency track web app (https://dependencytrack.org/). Attached you can find a cyclonedx json sbom created on a project via --package --cyclonedx=scancode_cyclone.json -n 4 options with Scancode toolkit. The json schema can’t be imported into the web app and fails also the validation via cyclonedx-cli. I was just going deeper in finding the differences in the schemas comparing with other cyclone dx bom examples that I managed to import correctly. Has anybody reported this problem? I have seen in one of your presentation online on slideshares that as a roadmap you’re going to adapt more and more this standard.

### System configuration

* What OS are you running on? I tried locally on Windows and Linux
* What version of scancode-toolkit was used to generate the scan file? Latest
* What installation method was used to install/run scancode? (pip/source download/other) Via pip

贡献指南

打开贡献指南

评估

这个 Issue 还没有评估数据。

把新 issue 发到你的邮箱

精选适合新手参与的 GitHub issue 摘要。