CycloneDX/sbom-utility

SBOM Utility passing SBOM with unexpected WITH clause

Offen

#131 geöffnet am 12.06.2025

 (2 Kommentare) (0 Reaktionen) (0 zugewiesene Personen)Go (20 Forks)auto 404
enhancementhelp wantedworking as designed

Repository-Metriken

Stars
 (155 Sterne)
PR-Merge-Metriken
 (PR-Metriken ausstehend)

Beschreibung

Our SBOM tool created an invalid license in that it was defined as an expression and not as it should have been as a name. (Currently being fixed.

We ran the SBOM Utility against it and it passed the validation, but it would not import into Dependency Track.

The issue is that what is in the expression is not a valid expression. DT correctly picked this up, but the utility passed it.

      {
        "expression": "Apache-2.0 WITH LLVM-exception"
      },
      "licenses": [
        {
          "expression": "Apache-2.0 WITH LLVM-exception"
        }
      ],

In this case, the tool should have thrown a wobbly as it is not valid.

Our work around is to change the license to Apache-2.0-with-LLVM-exception and that forces it to name.

Contributor Guide