chainguard-dev/apko

SBOM missing extracted licensing info

xnox opened this issue · 0 comments

xnox commented

In docker-selenium image with newly created custom licensing info, it is missing from the image spdx like so:

# ntia-checker -v --file docker-selenium.latest.spdx.json | grep ubuntu
Unrecognized license reference: LicenseRef-ubuntu-font. license_expression must only use IDs from the license list or extracted licensing info, but is: LicenseRef-ubuntu-font