interlynk-io/sbomqs

CycloneDX XML SBOM incorrectly checks for bomFormat

Closed this issue · 0 comments

Scoring for the two SBOMs at

even though both are prepared for the same image/tag with the same tool (syft-0.73.00). The root cause is bomFormat and version fields which are required in JSON and omitted from XML : https://cyclonedx.org/docs/1.4/xml/#element_bom

Expected Result:
Both sboms should produce identical scores.