Open vargenau opened 11 months ago
This seems to be two unrelated things:
convert
should also be included in the new proposed configuration items (such that the package would be dropped, missing values filled in with stubs, or something else). We should consider splitting this into separate issues if they are not tacked at the same time.
I've carved off the package name consideration into a new issue #3067 and left this issue to describe only the license problems being described.
What happened:
hello.spdx.txt hello.cdx.json.txt hello-converted.spdx.txt
SPDX is invalid:
(Edit: this has been broken off into #3067 )
Also,
hello.spdx
has:This becomes in
hello-converted.spdx
:What you expected to happen:
The SPDX file should be valid SPDX. (Edit: this has been broken off into #3067 )
I am not a CycloneDX expert, but from my understanding, CycloneDX cannot make the difference between declared and concluded licences, so it cannot store both. So it is OK to have
But
is clearly incorrect.
Steps to reproduce the issue:
See above
Anything else we need to know?:
Environment:
syft version
: syft 0.92.0cat /etc/os-release
or similar): MacOS 13.6