google / google/osv-scanner

Migration guide uses an unsupported osv-scanner SPDX format name

Open
#3,009 2 comments 0 reactions 1 assignee Claimed by @haimingZZ View on GitHub
Dominant language
Go
Stars
11k
Forks
792
Avg merge
1d 20h
Merged PRs (30d)
48

Description

### Problem

The migration guide currently uses an SPDX format name that the osv-scanner CLI rejects:

- `docs/migrating-from-scalibr.md:83` uses `--format spdx-2.3-json`.
- `docs/migrating-from-scalibr.md:95` maps `spdx23-json` to `--format spdx-2.3-json`.
- `internal/reporter/format.go:10` lists the supported format as `spdx-2-3`.

The example therefore fails with `unsupported output format "spdx-2.3-json"`. The output documentation already shows the working command shape: `osv-scanner scan --format spdx-2-3 ...`.

### Expected behavior

The migration guide should use the current supported format name and command shape, including the documented `scan` and `--output-file` flags where appropriate.

Would a maintainer be willing to assign this documentation fix? I can prepare a small, focused PR after assignment.

Contributor guide

Open the contributing guide

Assessment

This issue has not been assessed yet.

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.