oasis-tcs/sarif-spec

any spdx to sarif converter available?

Opened this issue · 1 comments

any spdx to sarif converter available?

@marcellodesales the question might profit from describing the expected mappings or use cases. As is, we could add CSAF, CycloneDX, Heimdall, SWID, and others to the mix equally well. But, we need actionable use cases as these are most probably not 1 to 1 mappings.

Please help us make this a meaningful and provide an initial description of something like a use case. Thanks.