Skip to content

Has CBOM been added to this project? #881

Answered by mtsfoni
joe-ratzer asked this question in Q&A
Discussion options

You must be logged in to vote

CBOM is newly supported in CycloneDX 1.6 which was released 9th of April this year.

The CycloneDX Library doesn't support 1.6 yet, and adaption will still take weeks to months until it support 1.6.

This cyclonedx-dotnet tool currently is only a package scanner and doesn't have any code-scanning capabilities whatsoever. I don't see that changing unless somebody is willing to put a lot of work into it.

Regarding flagging things as a problem: the general approach of CycloneDX generating tools is to describe the current state as factual as possible. Most of them by loading data from the respective package manager. So the flagging as problems regularly has to be done by another analyzing tool …

Replies: 1 comment 1 reply

Comment options

You must be logged in to vote
1 reply
@joe-ratzer
Comment options

Answer selected by joe-ratzer
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants