tern-tools / tern

Tern is a software composition analysis tool and Python library that generates a Software Bill of Materials for container images and Dockerfiles. The SBOM that Tern generates will give you a layer-by-layer view of what's inside your container in a variety of formats including human-readable, JSON, HTML, SPDX and more.
BSD 2-Clause "Simplified" License
967 stars 188 forks source link

Remove underscores from SPDXIDs #1150

Closed rnjudge closed 2 years ago

rnjudge commented 2 years ago

An SPDXID is generated using the package name and version metadta. Some versions, however, contain an underscore in them and an SPDXID cannot contain an underscore character. This commit replaces underscores in SPDXIDs with a dash.

Resolves #1143

Signed-off-by: Marc-Etienne Vargenau marc-etienne.vargenau@nokia.com Signed-off-by: Rose Judge rjudge@vmware.com