You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Merging SBOMs seems to default to the output file being version 1.5, regardless of the input file versions. See for example test1.txt and test2.txt attached. Both v1.4, created with the snyk sbom CLI command.
The text was updated successfully, but these errors were encountered:
aja08379
changed the title
cyclonedx merge defaults to specVersion 1.5 even when merging two v1.4 filesls -la
cyclonedx merge defaults to specVersion 1.5 even when merging two v1.4 files
Nov 6, 2023
Merging SBOMs seems to default to the output file being version 1.5, regardless of the input file versions. See for example
test1.txt
andtest2.txt
attached. Both v1.4, created with thesnyk sbom
CLI command.Command used to merge them is:
cyclonedx merge --input-files test1.txt test2.txt --output-file new.txt --input-format json --output-format json --name "Test" --version "v0.0"
The output SBOM
new.txt
is v1.5 (also attached):new.txt
test1.txt
test2.txt
The text was updated successfully, but these errors were encountered: