Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Invalid SPDX generated #10

Open
vargenau opened this issue Sep 28, 2022 · 0 comments
Open

Invalid SPDX generated #10

vargenau opened this issue Sep 28, 2022 · 0 comments

Comments

@vargenau
Copy link
Contributor

A directory sbom-composer containing two files AAA.spdx and BBB.spdx.

Files are attached (suffix .txt added to be able to upload on github).

compose -c ~/git/sbom-composer/config/example_config.yaml -d test-sbom-composer -s test-sbom-composer.spdx 

File test-sbom-composer.spdx is not valid SPDX.

The following warning(s) were raised: [Invalid element reference in relationship: SPDXRef-top-level-artifact-1.0 at line number 47, Invalid element reference in relationship: SPDXRef-top-level-artifact-1.0 at line number 48, Package at line 34 invalid: Missing required package files for top-level-artifact, Missing required license information from files for top-level-artifact, Missing required package files for top-level-artifact]

AAA.spdx.txt
BBB.spdx.txt
test-sbom-composer.spdx.txt

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant