I am not sure what fields comp_with_uniq_id is scoring #221
-
I was removing parts of SBOMs and running them back through SBOMqs and comparing scores the comp_with_uniq_id never changed while all the others did for SPDX. I removed externalRefs and also removed SPDXID but the score did not change. I tried reading the score code but it seemed to support my idea that SPDXID and CPEs (stored in externalRefs?) were what the targets where. Where am I going wrong here? |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 1 reply
-
A unique id for SPDX is the SPDXID of a component, along with the namespace of the document. Line 102 in f95627d
If you remove SPDXID of packages the count should drop. Below i removed SPDXID
There is a off by one bug, which i will fix. Does this answer your question ? |
Beta Was this translation helpful? Give feedback.
It absolutely does thank you so much!