Closed
Description
Create clearer documentation on why SBOMs generated by some tools might not work with osv-scanner scanning, as they don't generate package URLs, or don't include what ecosystem the package comes from.
The scanner's error should also be more helpful error in clarifying this, or maybe link to the documentation.
See #93 for additional context.
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment