advanced-security / gh-sbom

Generate SBOMs with gh CLI
MIT License
164 stars 13 forks source link

versionInfo value is incorrect #13

Open surendrapathak opened 1 year ago

surendrapathak commented 1 year ago

versionInfo value is incorrect

Value: versionInfo: \u003e= 1.17 for pip-numpy Expected: 1.17 is a valid version for pip-numpy Reference: https://github.com/spdx/spdx-spec/blob/development/v2.3.1/schemas/spdx-schema.json#L438

SBOM URL: | https://sbomlc.s3.amazonaws.com/gh-sbom-v0.0.9_accelerate-0.18.0.spdx.json?AWSAccessKeyId=AKIA2ZBFUJ4NNQGYD5OF&Signature=OwGArrr6ZDlkpgUCzBaKEpDa%2Fl8%3D&Expires=1713580541 QS URL: | https://sbombenchmark.dev/score/gh-sbom-v0.0.9_huggingface-hub-0.13.4.spdx.json