Replies: 1 comment
-
Thanks for reporting. #7756 |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
In the produced SPDX document, it looks like the
attributionTexts
field on packages is being used to record information about the scanning results. For example:From the SPDX spec - the Attribution Text intent id described as "This field provides a place for the SPDX document creator to record, at the package level, acknowledgements that might be required to be communicated in some contexts. "
For example, if a software package has a contributor, the attribution text could include "... was a contributor to this project".
Desired Behavior
From the data in the fields, it looks like these should be Annotations on the package.
For example:
Actual Behavior
Attribution texts being used instead of annotations
Reproduction Steps
Target
Filesystem
Scanner
License
Output Format
SPDX
Mode
Standalone
Debug Output
Operating System
Windows 11
Version
Checklist
trivy clean --all
Beta Was this translation helpful? Give feedback.
All reactions