opensbom-generator / spdx-sbom-generator

Support CI generation of SBOMs via golang tooling.
396 stars 109 forks source link

Ruby - https:// is prefixed to PackageHomePage value #136

Open niruautomation opened 3 years ago

niruautomation commented 3 years ago

Tool Version Cloned code from main branch of https://github.com/spdx/spdx-sbom-generator on 11-06-2021 and built the tool Test Repo https://github.com/lewisojile/ruby-gem-sample OS Windows 10

Observed that https:// is prefixed to PackageHomePage value

SPDX file image

lewisojile commented 3 years ago

@niravpatel27 @niruautomation @corvramirez This issue is not related to the gem module, the module passes the URL and protocol as retrieved from the gemspecs file, the spdx generation module should have a check to see whether a protocol is already passed from plugin before appending 'https://' by default. This is because some URL's might not be of the 'https' protocol when retrieved by plugin.

niruautomation commented 3 years ago

152 is still not merged and hence issue is still not fixed

image