Export SBOM - DESCRIBES
relationship is required
#129991
Replies: 2 comments
-
Github SBOM contains |
Beta Was this translation helpful? Give feedback.
-
🕒 Discussion Activity Reminder 🕒 This Discussion has been labeled as dormant by an automated system for having no activity in the last 60 days. Please consider one the following actions: 1️⃣ Close as Out of Date: If the topic is no longer relevant, close the Discussion as 2️⃣ Provide More Information: Share additional details or context — or let the community know if you've found a solution on your own. 3️⃣ Mark a Reply as Answer: If your question has been answered by a reply, mark the most helpful reply as the solution. Note: This dormant notification will only apply to Discussions with the Thank you for helping bring this Discussion to a resolution! 💬 |
Beta Was this translation helpful? Give feedback.
-
Select Topic Area
Question
Body
Hello, I am using an API for SBOM export, and the resulting SBOM does not contain
DESCRIBES
relationship, which seems to be mandatory according to the SPDX spec.If I interpret it correctly, this relationship has to be specified whenever there is more than one element in
packages
list to declare which package is the "root" and bind it with the whole document.Beta Was this translation helpful? Give feedback.
All reactions