Export SBOM - DESCRIBES
relationship is required
#129991
Unanswered
aleksandrserbin
asked this question in
API and Webhooks
Replies: 1 comment
-
Github SBOM contains |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Select Topic Area
Question
Body
Hello, I am using an API for SBOM export, and the resulting SBOM does not contain
DESCRIBES
relationship, which seems to be mandatory according to the SPDX spec.If I interpret it correctly, this relationship has to be specified whenever there is more than one element in
packages
list to declare which package is the "root" and bind it with the whole document.Beta Was this translation helpful? Give feedback.
All reactions