opensbom-generator / spdx-sbom-generator

Support CI generation of SBOMs via golang tooling.
396 stars 109 forks source link

Ruby - PackageLicenseConcluded/PackageLicenseDeclared not displayed for any package even when license exists in gemspec #137

Open niruautomation opened 3 years ago

niruautomation commented 3 years ago

Tool Version Cloned code from main branch of https://github.com/spdx/spdx-sbom-generator on 11-06-2021 and built the tool Test Repo https://github.com/lewisojile/ruby-gem-sample OS Windows 10

Observed that PackageLicenseConcluded/PackageLicenseDeclared not displayed for any package even when license exists in gemspec

Example1 SPDX file image

Gemspec image

Example2 SPDX file image

Gemspec image

lewisojile commented 3 years ago

@niruautomation this issue has been fixed and merged recently to master PR : https://github.com/spdx/spdx-sbom-generator/pull/142

niruautomation commented 3 years ago

I cloned the code from master on 14-06-2021, build the tool and verified the ticket. Issue is still reproducible bom-bundler.spdx.txt