Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add 'add_to_dependencies' option for merge command #168

Closed
cedricwritescode opened this issue Apr 25, 2024 · 1 comment
Closed

Add 'add_to_dependencies' option for merge command #168

cedricwritescode opened this issue Apr 25, 2024 · 1 comment

Comments

@cedricwritescode
Copy link
Contributor

When merging multiple SBOMs with a main SBOM, there should be an option that automatically adds the bom-refs of each metadata component from non-main SBOM files.

This is helpful when the other SBOMs are actual dependencies of the main SBOM. Without this option I don't really understand the use case of the merge command.

feature_request.zip

@italvi
Copy link
Collaborator

italvi commented May 6, 2024

@cedricwritescode after discussing this internally, this should be the same use-case as described in #152. So in the future, we most probably will have this feature implemented, however this will not happen before summer, as we currently focus on other features like #146.

In the meantime you could take a look at the merge --hierarchical of the "official" CycloneDX CLI tool, so you don't have to create a solution on your own.

@italvi italvi closed this as completed May 6, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants