Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

SPDX formatting issues #4

Open
Madhu173 opened this issue Feb 15, 2024 · 0 comments
Open

SPDX formatting issues #4

Madhu173 opened this issue Feb 15, 2024 · 0 comments

Comments

@Madhu173
Copy link

There are a bunch of warning with generated spdx files and fails SBOM NTIA minimum element conformance. (https://tools.spdx.org/app/ntia_checker/))

  1. licenseDeclared uses & and | between licenses. Where are as the expected usage is AND OR
  2. license identifiers are not compatible, might be because of the source itself. For example GPLv2 in generated spdx but expected is GPL-2.0-only
    generates this warning " license_expression must only use IDs from the license list or extracted licensing info"
    3)externalPackageRef type in category SECURITY must be one of ['cpe22Type', 'cpe23Type', 'advisory', 'fix', 'url', 'swid'], but is: http://spdx.org/rdf/references/cpe23Type
    4)externalPackageRef type in category SECURITY must be one of ['cpe22Type', 'cpe23Type', 'advisory', 'fix', 'url', 'swid'], but is: http://spdx.org/rdf/references/cpe23Type
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

1 participant