Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Wrong supplier in RootPackage of SBOM #84

Closed
Brend-Smits opened this issue Jul 27, 2022 · 3 comments · Fixed by #92
Closed

Wrong supplier in RootPackage of SBOM #84

Brend-Smits opened this issue Jul 27, 2022 · 3 comments · Fixed by #92
Assignees
Labels
z-aa-triaged (Deprecated label) This issue has been triaged by AA z-bug (Deprecated label) Something isn't working z-P1 (Deprecated label) Priority 1 on bugs

Comments

@Brend-Smits
Copy link

Hey there,

I am working on generating an SBOM for a GitHub Action that sets up this SBOM-Tool in a convenient way (see: https://github.com/philips-software/sbom-tool-installer-action). After generating the SBOM, I noticed that the supplier field of the RootPackage is set to Organization: Microsoft, which seems incorrect.
There should be a parameter to control this value.

I uploaded the SBOM as a Gist. Please have a look here:
https://gist.github.com/Brend-Smits/90b62120de7abc989c2768c92a2a49c8#file-sbom-tool-installer-action-sbom-L10757-L10772

@aasim
Copy link
Collaborator

aasim commented Jul 29, 2022

Thanks for bringing this to our attention, will add a parameter to the tool for this.

@Brend-Smits
Copy link
Author

Thanks for bringing this to our attention, will add a parameter to the tool for this.

Is this something I can help with? I don't mind opening a PR.

@edgarrs edgarrs added z-aa-triaged (Deprecated label) This issue has been triaged by AA z-bug (Deprecated label) Something isn't working z-P1 (Deprecated label) Priority 1 on bugs labels Aug 2, 2022
@edgarrs
Copy link
Contributor

edgarrs commented Aug 2, 2022

Thanks @Brend-Smits , @ByAgenT is already working on a fix for this. But how about you help us fixing #85?

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
z-aa-triaged (Deprecated label) This issue has been triaged by AA z-bug (Deprecated label) Something isn't working z-P1 (Deprecated label) Priority 1 on bugs
Projects
None yet
Development

Successfully merging a pull request may close this issue.

4 participants