-
## What happened
The deprecated syntax for the "`author`" field is still used by `syft v1.9.0`,
resulting in the following warning/error deprecation message:
![syft-Screenshot_20240715_110037](…
-
## Description
The Quarkus CLI has a set of default values that if not specified on the command line will be used.
## Implementation ideas
It would be good if one could override these defaul…
-
Currently it is possible to specify a value for `scope` without offering any evidence.
https://github.com/CycloneDX/specification/blob/master/schema/bom-1.6.schema.json#L4783
This creates potent…
-
There is some confusion when it comes to the BOM, with the BOM on multiple pages it can lead to multiple orders from the same vendor. Also the BOM could use more clarity for what you need for each to…
-
### Describe the bug
With 1.34.0 when building I have the following error:
> [ERROR] /home/kogito/serverless-workflow-project/target/generated-sources/open-api-stream/org/kie/kogito/openapi/moveku…
-
Hi,
All my projects use Java for backend and Angular for frontend. With `makeAggregateBom` I could only aggregate the BOMs generated by Maven plugin but not the BOM generated by [cyclonedx-webpack-…
-
Currently the tool generates BOM file for each detected package manager like `bom-go-mod.spdx`, `bom-yarn.spdx` etc.
On addition of this flag, say `--merge`, the tool shall produce only a output f…
-
Currently the tooling in https://github.com/kubernetes-sigs/bom rewrites its SPDX library/structs. Part of this is to investigate how we can shape the library or provide helpers to incentivize the bom…
-
A proposal has been suggested that the CycloneDX specification add native support for the [SCVS BOM Maturity Model](https://scvs.owasp.org/bom-maturity-model/) to the schema itself. This may likely be…
-
While attempting to outsource a build and assembly of these boards, we realized the BOM and PnP files are missing from this repo.