You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
the dependency names are recognized but not versions and other metadata, and i think this is due to some differences in which fields of the SPDX format are populated by Yocto vs what this action expects.
The text was updated successfully, but these errors were encountered:
@mischief i appreciate you may have resolved some of your issues.
however i have created a script that may be of interest to you. This is a post script that is ran against a folder of spdx json files and updates them accordingly to reflect some of the "undefined" items.
I would note that it does not provide you the ability to get any links to external layers etc.
hi,
is this project maintained?
is it possible to make this work with Yocto generated SBOMs? i have a demo using the action in https://github.com/mischief/spdx-sbom-test, with an SBOM generated by running upstream poky with https://github.com/yoctoproject/poky/blob/mickledore/meta/classes/create-spdx-2.2.bbclass enabled.
the dependency names are recognized but not versions and other metadata, and i think this is due to some differences in which fields of the SPDX format are populated by Yocto vs what this action expects.
The text was updated successfully, but these errors were encountered: