CycloneDX/sbom-utility

SBOM Utility passing SBOM with unexpected WITH clause

Open

#131 opened on Jun 12, 2025

 (2 comments) (0 reactions) (0 assignees)Go (20 forks)auto 404
enhancementhelp wantedworking as designed

Repository metrics

Stars
 (155 stars)
PR merge metrics
 (PR metrics pending)

Description

Our SBOM tool created an invalid license in that it was defined as an expression and not as it should have been as a name. (Currently being fixed.

We ran the SBOM Utility against it and it passed the validation, but it would not import into Dependency Track.

The issue is that what is in the expression is not a valid expression. DT correctly picked this up, but the utility passed it.

      {
        "expression": "Apache-2.0 WITH LLVM-exception"
      },
      "licenses": [
        {
          "expression": "Apache-2.0 WITH LLVM-exception"
        }
      ],

In this case, the tool should have thrown a wobbly as it is not valid.

Our work around is to change the license to Apache-2.0-with-LLVM-exception and that forces it to name.

Contributor guide