Replies: 1 comment
-
Hello @goneall Created #7402 Regards, Dmitriy |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Description
Per the spec - NONE should be used if there is a conclusion that no license or download location exists. In the case of missing metadata, NOASSERTION should be used since their very well could be a license or download location even though that information is not present in the metadata.
Example spec reference to the package concluded license.
Desired Behavior
When creating an SBOM with
--format spdx-json
, any data which is not present in the package metadata should have a value ofNOASSERTION
.Actual Behavior
When creating an SBOM with
--format spdx-json
, any data which is not present in the package metadata a value ofNONE
. Is found.Reproduction Steps
Target
None
Scanner
License
Output Format
SPDX
Mode
Standalone
Debug Output
Checklist
trivy clean --all
Beta Was this translation helpful? Give feedback.
All reactions