Open RicardoAReyes opened 1 year ago
It looks the like cyclonedx diff only works with xml file formats.
% cyclonedx diff api-xml/elasticsearch-cyclonedx.xml xml/elasticsearch-cyclonedx.xml.xml --from-format xml --to-format xml --component-versions
Component versions that have changed:
+ aiohttp @ 3.7.4.post0
+ asgiref @ 3.3.4
+ async-timeout @ 3.0.1
+ attrs @ 21.2.0
+ certifi @ 2022.9.24
+ certifi @ 2021.5.30
- chardet @ 3.0.4
+ chardet @ 4.0.0
+ click @ 8.0.1
+ elastic-apm @ 6.2.1
- elasticsearch @ 8.6.0
+ elasticsearch @ 8.5.2
+ elasticsearch @ 7.13.1
+ elastic-transport @
+ elastic-transport @ 8.4.0
+ fastapi @ 0.65.1
+ h11 @ 0.12.0
- idna @ 2.5
+ idna @ 3.2
+ multidict @ 5.1.0
+ pydantic @ 1.8.2
+ starlette @ 0.14.2
I am comparing two CycloneDX JSON SBOM files from reputable sources.