aboutcode-org / aboutcode-org/scancode-toolkit

CDX License Support

未關閉
#4,021 4 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
bug
主要語言
Python
星號
2.6k
分支
791
平均合併
1 天 12 小時
30 天內合併 PR
5

描述

[scancode_cyclone.json](https://github.com/user-attachments/files/18147075/scancode_cyclone.json)

### Description

I experimented with the sbom cyclonedx format in order to import it into 4.12 Dependency track web app (https://dependencytrack.org/). Attached you can find a cyclonedx json sbom created on a project via --package --cyclonedx=scancode_cyclone.json -n 4 options with Scancode toolkit. The json schema can’t be imported into the web app and fails also the validation via cyclonedx-cli. I was just going deeper in finding the differences in the schemas comparing with other cyclone dx bom examples that I managed to import correctly. Has anybody reported this problem? I have seen in one of your presentation online on slideshares that as a roadmap you’re going to adapt more and more this standard.

### System configuration

* What OS are you running on? I tried locally on Windows and Linux
* What version of scancode-toolkit was used to generate the scan file? Latest
* What installation method was used to install/run scancode? (pip/source download/other) Via pip

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。