aboutcode-org / aboutcode-org/scancode.io

Bug: CycloneDX 1.6 SBOM being generated without dependency details

未關閉
#1,618 1 則留言 0 個 reaction 已指派 2 人 已被 @tdruez 認領 在 GitHub 檢視
bug high priority
主要語言
Python
星號
215
分支
203
平均合併
4 天 8 小時
30 天內合併 PR
6

描述

Using the scan-single-package pipeline I recently scanned scancode.io-34.9.5.tar.gz in SCIO v34.9.5. The scan identified 52 dependencies. When I generate an SPDX 2.3 SBOM from this project the dependency relationships are included in the generated document. When I generate a CycloneDX 1.6 SBOM from this same project the dependency relationships are not included in the generated document.

Attachments: the scan results, the SPDX SBOM, the CycloneDX SBOM

[scancodeio_scio-v34.9.5.json.zip](https://github.com/user-attachments/files/19093574/scancodeio_scio-v34.9.5.json.zip)

[scancodeio_scio-v34.9.5_results-2025-02-24-21-44-28.spdx.json.zip](https://github.com/user-attachments/files/19093581/scancodeio_scio-v34.9.5_results-2025-02-24-21-44-28.spdx.json.zip)

[scancodeio_scio-v34.9.5_results-2025-02-24-21-44-34.cdx.json.zip](https://github.com/user-attachments/files/19093588/scancodeio_scio-v34.9.5_results-2025-02-24-21-44-34.cdx.json.zip)

貢獻指南

開啟貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。