aboutcode-org / aboutcode-org/scancode.io
Bug: CycloneDX 1.6 SBOM being generated without dependency details
- Ngôn ngữ chính
- Python
- Star
- 215
- Fork
- 203
- Merge trung bình
- 4 ngày 8 giờ
- Pull request đã merge (30 ngày)
- 6
Mô tả
Using the scan-single-package pipeline I recently scanned scancode.io-34.9.5.tar.gz in SCIO v34.9.5. The scan identified 52 dependencies. When I generate an SPDX 2.3 SBOM from this project the dependency relationships are included in the generated document. When I generate a CycloneDX 1.6 SBOM from this same project the dependency relationships are not included in the generated document.
Attachments: the scan results, the SPDX SBOM, the CycloneDX SBOM
[scancodeio_scio-v34.9.5.json.zip](https://github.com/user-attachments/files/19093574/scancodeio_scio-v34.9.5.json.zip)
[scancodeio_scio-v34.9.5_results-2025-02-24-21-44-28.spdx.json.zip](https://github.com/user-attachments/files/19093581/scancodeio_scio-v34.9.5_results-2025-02-24-21-44-28.spdx.json.zip)
[scancodeio_scio-v34.9.5_results-2025-02-24-21-44-34.cdx.json.zip](https://github.com/user-attachments/files/19093588/scancodeio_scio-v34.9.5_results-2025-02-24-21-44-34.cdx.json.zip)
Hướng dẫn đóng góp
Đánh giá
Issue này chưa được đánh giá.