advanced-security / gh-sbom

Generate SBOMs with gh CLI
MIT License
161 stars 13 forks source link

Invalid SPDXID: SPDXRef-actions-actions/checkout-3 #16

Open surendrapathak opened 1 year ago

surendrapathak commented 1 year ago

Value: SPDXRef-actions-actions/checkout-3 Expected: SPDXID only supports string containing letters, numbers, “.”,“–”.

Reference: https://spdx.github.io/spdx-spec/v2.3/package-information/#72-package-spdx-identifier-field

SBOM URL: | https://sbomlc.s3.amazonaws.com/gh-sbom-v0.0.9_accelerate-0.18.0.spdx.json?AWSAccessKeyId=AKIA2ZBFUJ4NNQGYD5OF&Signature=OwGArrr6ZDlkpgUCzBaKEpDa%2Fl8%3D&Expires=1713580541 QS URL: | https://sbombenchmark.dev/score/gh-sbom-v0.0.9_huggingface-hub-0.13.4.spdx.json