Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

[🐛] SPDX output only reports vulnerabilities #43

Open
hectorj2f opened this issue May 9, 2022 · 4 comments
Open

[🐛] SPDX output only reports vulnerabilities #43

hectorj2f opened this issue May 9, 2022 · 4 comments
Labels

Comments

@hectorj2f
Copy link

hectorj2f commented May 9, 2022

  • node -v:
  • npm -v:
  • OS: (e.g. Linux,, ...)
  • Command run: (e.g. snyk2spdx ..., ...)

Expected behaviour

Please share expected behaviour.
I would expect the rest of SPDX fields to be populated instead of only the vulnerabilities.

Actual behaviour

SPDX output only populates the vulnerabilities field of SPDX 3.0.

@lili2311
Copy link
Contributor

hi @hectorj2f, thanks for you request, at the time of building this the spec for very much in progress and had missing/ undocumented fields so these are not present today.
This repo has not been updated since, I am checking internally if there are any plans to evolve this projects and will share back your feedback.

@hectorj2f
Copy link
Author

I am checking internally if there are any plans to evolve this projects and will share back your feedback.

Thanks @lili2311. That would help us to get some expectations.

@lili2311
Copy link
Contributor

lili2311 commented Jul 7, 2022

Hi @hectorj2f

This tool is a look ahead at the new vulnerability extension in the WIP SPDX v3 spec

We’re building out a new API for Snyk at the moment, and working on where this will utilise various emerging standards
This will include issues from Snyk Open Source projects, where SPDX + the vulnerability extension is relevant
We have have an API in the works for grabbing the dependency information in standard formats as well, starting with CycloneDX, but we’ll be adding support for SPDX as well

If you want to chat about this talk to your Snyk contact who can grab someone from the product team to talk more

@hectorj2f
Copy link
Author

hectorj2f commented Jul 7, 2022

@lili2311 Thanks for the update. We are currently using this tool. We are definitely interested on any more stable service that could provide similar functionalities.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
Projects
None yet
Development

No branches or pull requests

2 participants