You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Hi @surendrapathak, the solution here should be the same as the previous ticket: #1568 (comment) -- if you set the environment variables @kzantow listed, you should see the checksums in the result.
Flagger uses sbom-action to produce spdx with release artifacts. However, the file is an invalid SPDX.
SPDX2.3 requires at least one SHA to be SHA1 for File.
However, the SBOM is missing SHA1 checksums for all files starting line 1835 -
Steps to reproduce the issue:
Anything else we need to know?:
Environment:
Output of
syft version
:From SBOM: "Tool: syft-0.68.1"
OS (e.g:
cat /etc/os-release
or similar):The text was updated successfully, but these errors were encountered: