Skip to content

6.2.0

Latest

Choose a tag to compare

@github-actions github-actions released this 27 Apr 00:07

Added

  • `--configuration` / `-c` CLI option (#1056, fixes #1028) — passes `-p:Configuration=` to `dotnet restore` so MSBuild evaluates conditional `PackageReference` items during restore. Configuration-specific packages (e.g. debug-only `Avalonia.Diagnostics`) are no longer included in the SBOM when a Release configuration is requested.
  • NuGet license file support (#1011, #1002) — packages declaring `` now have their license file embedded as base64-encoded text in the BOM when `--include-license-text` is specified; without the flag the license is still detected but not embedded

Fixed

  • Suppress `aka.ms/deprecateLicenseUrl` stub URL (#1011) — NuGet auto-injects `https://aka.ms/deprecateLicenseUrl\` into `` for packages packed with ``; this URL is now correctly ignored rather than being emitted as a license entry in the BOM
  • Fix null-URL license stub (#1011) — packages with no `` no longer produce a spurious `License { Name="Unknown - See URL", Url=null }` node in the BOM
  • Fix `UNLICENSED` emitted as SPDX id (#1004, fixes #915) — `UNLICENSED` is a NuGet-specific token that is not a valid SPDX identifier; it is now emitted as `license.name` instead of `license.id` to keep BOM output valid

Changed

  • Upgrade CycloneDX.Core from 12.0.1 to 12.1.1 (#1084)
  • Bump System.CommandLine from 2.0.0 to 2.0.5 (#1083)

Contributors

Thanks to everyone who contributed to this release: