We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
When purl/bom-ref field contains a '?' char like this:
{ "bomFormat": "CycloneDX", "specVersion": "1.4", "serialNumber": "urn:uuid:151b045d-ef9c-47e8-9943-7b325834a13b", "version": 1, "metadata": { "timestamp": "2022-05-25T11:38:14.899573013Z", "tools": [ { "vendor": "aquasecurity", "name": "trivy", "version": "0.25.2" } ], "component": { "bom-ref": "pkg:oci/isp_aggregationdatahandler@sha256:4a5986dc98d7d899fa2fce87626862aed7bec168b44f83ffca2c5d179f917823?repository_url=...
then dependency graph not working. Maybe this can be an Issue in Trivy output otherwise? see here https://aquasecurity.github.io/trivy/v0.28.0/docs/sbom/cyclonedx/
The text was updated successfully, but these errors were encountered:
Do you have a bom from trivy that you can attach to the ticket?
Sorry, something went wrong.
Test-sbom.zip
Duplicate of #85
No branches or pull requests
When purl/bom-ref field contains a '?' char like this:
then dependency graph not working. Maybe this can be an Issue in Trivy output otherwise? see here https://aquasecurity.github.io/trivy/v0.28.0/docs/sbom/cyclonedx/
The text was updated successfully, but these errors were encountered: