-
-
Notifications
You must be signed in to change notification settings - Fork 19
Open
Labels
enhancementNew feature or requestNew feature or requesthelp wantedExtra attention is neededExtra attention is neededworking as designedThe description indicates the tool is working as designedThe description indicates the tool is working as designed
Description
Our SBOM tool created an invalid license in that it was defined as an expression and not as it should have been as a name. (Currently being fixed.
We ran the SBOM Utility against it and it passed the validation, but it would not import into Dependency Track.
The issue is that what is in the expression is not a valid expression. DT correctly picked this up, but the utility passed it.
{
"expression": "Apache-2.0 WITH LLVM-exception"
},
"licenses": [
{
"expression": "Apache-2.0 WITH LLVM-exception"
}
],
In this case, the tool should have thrown a wobbly as it is not valid.
Our work around is to change the license to Apache-2.0-with-LLVM-exception and that forces it to name.
Metadata
Metadata
Assignees
Labels
enhancementNew feature or requestNew feature or requesthelp wantedExtra attention is neededExtra attention is neededworking as designedThe description indicates the tool is working as designedThe description indicates the tool is working as designed