[BUG] hashes on wrong element #430
Labels
bug
Something isn't working
good first issue
Good for newcomers
help wanted
Extra attention is needed
composer's integrity hash is for the resolved file, not the component in general.
see
cyclonedx-php-composer/src/_internal/MakeBom/Builder.php
Lines 217 to 220 in 09c83c6
solution: to not put the
hash
on the component,but on the
externalReference
that is build from resolved.The text was updated successfully, but these errors were encountered: