Open
Description
If you run tally -o cyclonedx-json bom.json
on a syft-json
file, it will exit successfully but not print any repositories. This is because the JSON parsing succeeds but there's no check to validate that the fields are what we expect them to be.
We should try and exit out with exit code 1 when the BOM format doesn't match the one we expected.