opensbom-generator / spdx-sbom-generator

Support CI generation of SBOMs via golang tooling.
396 stars 109 forks source link

SSB-50: PHP - NOASSERTION is displayed for License even when license exists in composer.lock #96

Closed rynofinn closed 3 years ago

rynofinn commented 3 years ago

Original Reporter: nvelagapudi Environment: Not Specified Version: Not Specified Migrated From: http://jira.linuxfoundation.org/browse/SSB-50

spdx-sbom-generator tool version v0.0.2Test Repo that I used for testinghttps://github.com/woocommerce/woocommerceObserved that NOASSERTION is displayed for License even when license exists in composer.lockObserved this issue for below packages Package-jetpack-autoloader-2.10.1 Package-jetpack-constants-1.5.1 Package-action-scheduler-3.2.0 Package-woocommerce-admin-2.3.1 Package-woocommerce-blocks-5.1.0SPDX data (PFA SPDX for reference)Composer.lock

niruautomation commented 3 years ago

Verified and closed in JIRA and hence closing the ticket