Skip to content

Relationships are ignored during CycloneDX →SPDX conversion #399

@sharmadi-arista

Description

@sharmadi-arista

Hi,

I've encountered an issue while converting a CycloneDX SBOM to SPDX. It looks like the conversion of dependencies to relationships is currently being completely ignored.

https://github.com/CycloneDX/cyclonedx-dotnet-library/blob/main/src/CycloneDX.Spdx.Interop/Converters/v2_3/SpdxDocumentConverters.cs#L86

It appears that some features are still unimplemented. Is anyone actively working on this, or is there a particular reason these parts haven't been addressed yet? These posses significant gaps in the conversion process.

Thanks you!!

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions