Skip to content

feat: add support for spdx sbom input file#381

Merged
KLongmuirHD merged 1 commit into
mainfrom
381-support-spdx-sbom-input-file
Oct 20, 2025
Merged

feat: add support for spdx sbom input file#381
KLongmuirHD merged 1 commit into
mainfrom
381-support-spdx-sbom-input-file

Conversation

@facundo-herodevs
Copy link
Copy Markdown
Member

SPDX SBOM Support

Summary

Added support for SPDX 2.3 SBOM format to the --file flag, allowing users to scan SPDX SBOMs in addition to CycloneDX SBOMs.

What changed

  • Updated readSbomFromFile() to support both SPDX 2.3 and CycloneDX formats
  • Added format detection logic: checks SPDX first, then CycloneDX
  • Returns CycloneDX format consistently for downstream processing
  • Enhanced error messages to indicate supported formats
  • Updated --file flag description to mention SPDX 2.3 support

@facundo-herodevs facundo-herodevs requested a review from a team as a code owner October 16, 2025 20:41
@facundo-herodevs facundo-herodevs force-pushed the 381-support-spdx-sbom-input-file branch from 7c87b3a to 8144dfb Compare October 16, 2025 20:43
Comment thread README.md Outdated
@facundo-herodevs facundo-herodevs force-pushed the 381-support-spdx-sbom-input-file branch from 8144dfb to 99bde93 Compare October 17, 2025 15:35
@KLongmuirHD KLongmuirHD merged commit f0dce2d into main Oct 20, 2025
12 checks passed
@KLongmuirHD KLongmuirHD deleted the 381-support-spdx-sbom-input-file branch October 20, 2025 12:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants