-
Notifications
You must be signed in to change notification settings - Fork 24
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
More documentation needed on sbomtype
option
#48
Comments
I also cannot find any documentation on which version(s) (1.4? 1.6?) or format(s) (XML? JSON?) of the CycloneDX specification are supported. For example, I suspect that only the XML flavor of CycloneDX is currently supported, but the tool doesn't document that anywhere. I'm only guessing because this happened:
Considering
|
sbomtype
optionsbomtype
option
After reviewing the source I am more confused because CycloneDX/cyclonedx-go is used which appears to support both JSON and XML formats. And this source appears to attempt both flavors. However, when I attempt to parse JSON output from either trivy or cdxgen, I am getting this out of
Or this when directly specifying the
Here is the SBOM file for reference: |
Well, one mystery is solved. The reason "guess" is thinking this is an spdx file is because the Perhaps it would be better to at least search for more specific data like:
|
The tool offers an
--sbomtype
option but I have been unable to find any documentation on what values are supported for the option flag. TheREADME
says:sbom-scorecard score --help
simply says:Where are the available options documented other than in the source code?
The text was updated successfully, but these errors were encountered: