mirror of
https://github.com/anchore/syft.git
synced 2025-11-18 17:03:17 +01:00
* Use SBOM descriptor version Signed-off-by: Jonas Xavier <jonasx@anchore.com> * Update tests Signed-off-by: Jonas Xavier <jonasx@anchore.com> * CycloneDX extract tools metadata in decoding stage Signed-off-by: Jonas Xavier <jonasx@anchore.com> * add descriptor to spdx tag-value test Signed-off-by: Jonas Xavier <jonasx@anchore.com> * remove comment Signed-off-by: Jonas Xavier <jonasx@anchore.com>
64 lines
2.7 KiB
XML
64 lines
2.7 KiB
XML
<?xml version="1.0" encoding="UTF-8"?>
|
|
<bom xmlns="http://cyclonedx.org/schema/bom/1.4" serialNumber="urn:uuid:155802bd-09e5-4b95-9485-826b94447495" version="1">
|
|
<metadata>
|
|
<timestamp>2022-05-23T12:02:42-07:00</timestamp>
|
|
<tools>
|
|
<tool>
|
|
<vendor>anchore</vendor>
|
|
<name>syft</name>
|
|
<version>v0.42.0-bogus</version>
|
|
</tool>
|
|
</tools>
|
|
<component bom-ref="e779c1ed804ba529" type="container">
|
|
<name>user-image-input</name>
|
|
<version>sha256:2731251dc34951c0e50fcc643b4c5f74922dad1a5d98f302b504cf46cd5d9368</version>
|
|
</component>
|
|
</metadata>
|
|
<components>
|
|
<component bom-ref="2a46171f91c8d4bc" type="library">
|
|
<name>package-1</name>
|
|
<version>1.0.1</version>
|
|
<licenses>
|
|
<license>
|
|
<id>MIT</id>
|
|
</license>
|
|
</licenses>
|
|
<cpe>cpe:2.3:*:some:package:1:*:*:*:*:*:*:*</cpe>
|
|
<purl>a-purl-1</purl>
|
|
<properties>
|
|
<property name="syft:package:foundBy">the-cataloger-1</property>
|
|
<property name="syft:package:language">python</property>
|
|
<property name="syft:package:metadataType">PythonPackageMetadata</property>
|
|
<property name="syft:package:type">python</property>
|
|
<property name="syft:location:0:layerID">sha256:cd8f3884f1211d65c19ce5bbc5174bcd2ce8ba96b63e5b3693969a53279c4405</property>
|
|
<property name="syft:location:0:path">/somefile-1.txt</property>
|
|
</properties>
|
|
</component>
|
|
<component bom-ref="pkg:deb/debian/package-2@2.0.1?package-id=ae77680e9b1d087e" type="library">
|
|
<name>package-2</name>
|
|
<version>2.0.1</version>
|
|
<cpe>cpe:2.3:*:some:package:2:*:*:*:*:*:*:*</cpe>
|
|
<purl>pkg:deb/debian/package-2@2.0.1</purl>
|
|
<properties>
|
|
<property name="syft:package:foundBy">the-cataloger-2</property>
|
|
<property name="syft:package:metadataType">DpkgMetadata</property>
|
|
<property name="syft:package:type">deb</property>
|
|
<property name="syft:location:0:layerID">sha256:42d2ea51c688e6dc7be81a305acbe006d27a6ef0c26ae3888fd0d4ce44f69265</property>
|
|
<property name="syft:location:0:path">/somefile-2.txt</property>
|
|
<property name="syft:metadata:installedSize">0</property>
|
|
</properties>
|
|
</component>
|
|
<component type="operating-system">
|
|
<name>debian</name>
|
|
<version>1.2.3</version>
|
|
<description>debian</description>
|
|
<swid tagId="debian" name="debian" version="1.2.3"></swid>
|
|
<properties>
|
|
<property name="syft:distro:id">debian</property>
|
|
<property name="syft:distro:idLike:0">like!</property>
|
|
<property name="syft:distro:prettyName">debian</property>
|
|
<property name="syft:distro:versionID">1.2.3</property>
|
|
</properties>
|
|
</component>
|
|
</components>
|
|
</bom> |