OpenChain-Project / Telco-WG

This is the OpenChain Telco Work Group
Other
13 stars 6 forks source link

OpenChain Telco SBOM Validator shows no errors, but SPDX is non compliant #110

Closed agustingroh closed 1 month ago

agustingroh commented 1 month ago

Hi! I am using the openchain-telco-sbom-validatorto validate my SPDX output. Although the error table is empty, the validator still shows a message saying the SPDX is not compliant with the OpenChain Telco SBOM Guide.

I've attached some files for reference. scanoss-engine.spdx.json image

vargenau commented 1 month ago

Hi Agustin, I confirm the issue. We will look after it.

CsatariGergely commented 1 month ago

@agustingroh thanks for the report. I fixed it in here: https://github.com/OpenChain-Project/Telco-WG/pull/111 I'm using the SBOM you provided in the test. I hope it is ok :)