SBOM is different from cyclonedx-node-module's SBOM #680
Replies: 2 comments
-
all true. the resulting CyconeDX documents are still correct.
This tool is more precise when generating PURLs. this is in favour of the PURL spec for NPM: https://github.com/package-url/purl-spec/blob/master/PURL-TYPES.rst#npm |
Beta Was this translation helpful? Give feedback.
-
This should be a bug. there is even a demo/integration test for this feature: https://github.com/CycloneDX/cyclonedx-node-npm/tree/main/demo/package-integrity would you provide a reproducible example and file an issue here: https://github.com/CycloneDX/cyclonedx-node-npm/issues/new/choose |
Beta Was this translation helpful? Give feedback.
-
Utils both use same "--spec-version 1.3", but result format is different.This is why?
for Example, purl and bom-ref in cyclonedx-node-module are like this:
They in cyclonedx-node-npm are like this:
Another issue: cyclonedx-node-module resolved hash value, but cyclonedx-node-npm not resolve.Will this issue be resolved in future versions?
Beta Was this translation helpful? Give feedback.
All reactions