all questions regarding PR#13 #14
Replies: 10 comments 28 replies
-
Q: What are sensible defaults for the parameters? |
Beta Was this translation helpful? Give feedback.
-
Q: Decision on license. Am I correct to assume the contained components can be used as part of a Apache-2.0 licensed project? Are you aware of any tool that takes a list of SPDX identifiers for dependencies (or SBOM) and answers which licenses could be chosen? |
Beta Was this translation helpful? Give feedback.
-
Q: Treatment of the root component in the SBOM. Should it be put in the metadata only or also within the components property? |
Beta Was this translation helpful? Give feedback.
-
Q: Many files in the root folder are basically empty templates. |
Beta Was this translation helpful? Give feedback.
-
Q: Do you have sample projects with known expected output regarding listed components and licenses? |
Beta Was this translation helpful? Give feedback.
-
Q: Fallback for component licenses. |
Beta Was this translation helpful? Give feedback.
-
Q: How would one calculate the hash for https://cyclonedx.org/docs/1.5/json/#components_items_hashes for a folder representing a component? |
Beta Was this translation helpful? Give feedback.
-
Q: Which are the important/desired properties in the generated SBOM files besides those marked as required in the JSON schema? |
Beta Was this translation helpful? Give feedback.
-
Q: Is the reproducible results flag mentioned in #8 important? Shouldn't this be a task for a SBOM consumer by masking out properties? |
Beta Was this translation helpful? Give feedback.
-
Q: I've only used this plugin with Yarn 4.1.0. It may or may not work with other Yarn versions. |
Beta Was this translation helpful? Give feedback.
-
all questions from #13 could go below
Beta Was this translation helpful? Give feedback.
All reactions