Skip to content

Invalid SPDX generated #10

@vargenau

Description

@vargenau

A directory sbom-composer containing two files AAA.spdx and BBB.spdx.

Files are attached (suffix .txt added to be able to upload on github).

compose -c ~/git/sbom-composer/config/example_config.yaml -d test-sbom-composer -s test-sbom-composer.spdx 

File test-sbom-composer.spdx is not valid SPDX.

The following warning(s) were raised: [Invalid element reference in relationship: SPDXRef-top-level-artifact-1.0 at line number 47, Invalid element reference in relationship: SPDXRef-top-level-artifact-1.0 at line number 48, Package at line 34 invalid: Missing required package files for top-level-artifact, Missing required license information from files for top-level-artifact, Missing required package files for top-level-artifact]

AAA.spdx.txt
BBB.spdx.txt
test-sbom-composer.spdx.txt

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type
    No fields configured for issues without a type.

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions