You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Right now, syft isnt putting the top level package as SPDX objects
I think for now we can add a PURL OCI reference type by heuristics based on the name in the document. But ill open an issue in Syft to include this as well (anchore/syft#1241).
The checksum is not currently stored, but would be good to also include "name" as the package ref
Right now, syft isnt putting the top level package as SPDX objects
I think for now we can add a PURL OCI reference type by heuristics based on the name in the document. But ill open an issue in Syft to include this as well (anchore/syft#1241).
The checksum is not currently stored, but would be good to also include "name" as the package ref
The text was updated successfully, but these errors were encountered: