I am not sure what fields comp_with_uniq_id is scoring #221
Unanswered
aidankeefe2022
asked this question in
Q&A
Replies: 1 comment 1 reply
-
A unique id for SPDX is the SPDXID of a component, along with the namespace of the document. Line 102 in f95627d
If you remove SPDXID of packages the count should drop. Below i removed SPDXID
There is a off by one bug, which i will fix. Does this answer your question ? |
Beta Was this translation helpful? Give feedback.
1 reply
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
I was removing parts of SBOMs and running them back through SBOMqs and comparing scores the comp_with_uniq_id never changed while all the others did for SPDX. I removed externalRefs and also removed SPDXID but the score did not change. I tried reading the score code but it seemed to support my idea that SPDXID and CPEs (stored in externalRefs?) were what the targets where. Where am I going wrong here?
Beta Was this translation helpful? Give feedback.
All reactions