-
-
Notifications
You must be signed in to change notification settings - Fork 561
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
CDX License Support #4021
Comments
@giocol91 Please document the error you encountered. |
I tried to load this SBOM into SCIO 34.8.0 and got the following error in step: [get_packages_from_sboms] CycloneDX document "scancode_cyclone.json" is not valid: Failed validating 'type' in schema['properties']['components']['items']['properties']['group']: On instance['components'][0]['group']: Traceback: |
@giocol91 Thanks for the report. We need to fix this alright. Note that ScanCode.io at https://github.com/aboutcode-org/scancode.io that also embeds scancode-toolkit produces CycloneDX formats that should be schema valid. |
@giocol91 the error messages would be very useful! |
scancode_cyclone.json
Description
I experimented with the sbom cyclonedx format in order to import it into 4.12 Dependency track web app (https://dependencytrack.org/). Attached you can find a cyclonedx json sbom created on a project via --package --cyclonedx=scancode_cyclone.json -n 4 options with Scancode toolkit. The json schema can’t be imported into the web app and fails also the validation via cyclonedx-cli. I was just going deeper in finding the differences in the schemas comparing with other cyclone dx bom examples that I managed to import correctly. Has anybody reported this problem? I have seen in one of your presentation online on slideshares that as a roadmap you’re going to adapt more and more this standard.
System configuration
The text was updated successfully, but these errors were encountered: