-
Notifications
You must be signed in to change notification settings - Fork 358
Open
Labels
analyzerAbout the analyzer toolAbout the analyzer toolreporterAbout the reporter toolAbout the reporter tool
Description
See https://github.com/nokia/SBOM-QA, thanks to @willebra for making me aware of this.
- Clarify on the wrong option syntax for creating SPDX-2.3 documents.
Done: Fix ORT option to specify the SPDX version nokia/SBOM-QA#17 - Investigate "which necessitated modifications in the pom.xml file as described below" statement.
- Investigate why the generated ORT-Java-Maven.json was reported as invalid.
- Consider adding support for the PDM package manager.
- Improve supplier information in SBOMs.
See: Improve the "supplier" information for SBOM formats #7449 - Review "CreatorComment and Organization fields in CreationInfo missing" statements.
- Review differences to reference SBOMs.
Thanks @CsatariGergely and team for your work here!
CsatariGergely, willebra and elhamrasti
Metadata
Metadata
Assignees
Labels
analyzerAbout the analyzer toolAbout the analyzer toolreporterAbout the reporter toolAbout the reporter tool