You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
This is probably a weird question, but when running grype dir:<somedir>, I understand grype is essentially running syft under the hood to produce the source SBOM (or similar). Can you control what format is used for this intermediate representation?
Why is this needed:
My reason for asking is this: I have some dependencies in a folder.
What would you like to be added:
This is probably a weird question, but when running
grype dir:<somedir>
, I understand grype is essentially running syft under the hood to produce the source SBOM (or similar). Can you control what format is used for this intermediate representation?Why is this needed:
My reason for asking is this: I have some dependencies in a folder.
If I run:
I get:
If I first generate an SBOM using syft in
cyclonedx-json
format, then ingest it withgrype sbom:.\sbom.json
I get the exact same result.However, if I first generate an SBOM using syft in SPDX format, then ingest it with grype I get:
So obviously the source SBOM format (or whatever the internal syft is producing over it) is somehow relevant to getting usable results?
Additional context:
The text was updated successfully, but these errors were encountered: