Skip to content

Bug: CycloneDX 1.6 SBOM being generated without dependency details #1618

Open
@DennisClark

Description

@DennisClark

Using the scan-single-package pipeline I recently scanned scancode.io-34.9.5.tar.gz in SCIO v34.9.5. The scan identified 52 dependencies. When I generate an SPDX 2.3 SBOM from this project the dependency relationships are included in the generated document. When I generate a CycloneDX 1.6 SBOM from this same project the dependency relationships are not included in the generated document.

Attachments: the scan results, the SPDX SBOM, the CycloneDX SBOM

scancodeio_scio-v34.9.5.json.zip

scancodeio_scio-v34.9.5_results-2025-02-24-21-44-28.spdx.json.zip

scancodeio_scio-v34.9.5_results-2025-02-24-21-44-34.cdx.json.zip

Metadata

Metadata

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions