From bb25554fcd96cfb9397de2fc4b7cfaef847e4504 Mon Sep 17 00:00:00 2001 From: Orie Steele Date: Tue, 13 Aug 2024 15:11:18 -0500 Subject: [PATCH] readme --- README.md | 19 ++++++++++++------- 1 file changed, 12 insertions(+), 7 deletions(-) diff --git a/README.md b/README.md index 3e5642f9..5ebf0dd3 100644 --- a/README.md +++ b/README.md @@ -98,22 +98,27 @@ TODO: all command examples ```bash -sbom-tool generate -b ./dist -bc ./ -pn transmute -ps transmute.industries -pv `jq -r .version package.json` -nsu `git rev-parse --verify HEAD` +sbom-tool generate -b ./dist -bc ./ -pn transmute -ps transmute.industries \ +-pv `jq -r .version package.json` -nsu `git rev-parse --verify HEAD` -transmute scitt issue-statement ./tests/fixtures/private.notary.key.cbor ./dist/_manifest/spdx_2.2/manifest.spdx.json \ +transmute scitt issue-statement ./tests/fixtures/private.notary.key.cbor \ +./dist/_manifest/spdx_2.2/manifest.spdx.json \ --iss https://software.vendor.example \ --sub `jq -r .documentNamespace ./dist/_manifest/spdx_2.2/manifest.spdx.json` \ --content-type application/spdx+json \ ---location https://github.com/transmute-industries/transmute/blob/main/dist/_manifest/spdx_2.2/manifest.spdx.json \ +--location https://github.com/.../dist/_manifest/spdx_2.2/manifest.spdx.json \ --output ./dist/_manifest/spdx_2.2/manifest.spdx.scitt.cbor -transmute scitt issue-receipt ./tests/fixtures/private.notary.key.cbor ./dist/_manifest/spdx_2.2/manifest.spdx.scitt.cbor \ +transmute scitt issue-receipt ./tests/fixtures/private.notary.key.cbor \ +./dist/_manifest/spdx_2.2/manifest.spdx.scitt.cbor \ --iss https://software.notary.example \ --sub `jq -r .documentNamespace ./dist/_manifest/spdx_2.2/manifest.spdx.json` \ --log ./tests/fixtures/trans.json \ --output ./dist/_manifest/spdx_2.2/manifest.spdx.scitt.cbor -transmute scitt verify-receipt-hash ./tests/fixtures/public.notary.key.cbor ./dist/_manifest/spdx_2.2/manifest.spdx.scitt.cbor `cat ./dist/_manifest/spdx_2.2/manifest.spdx.json.sha256` +transmute scitt verify-receipt-hash ./tests/fixtures/public.notary.key.cbor \ +./dist/_manifest/spdx_2.2/manifest.spdx.scitt.cbor \ +`cat ./dist/_manifest/spdx_2.2/manifest.spdx.json.sha256` ``` @@ -142,11 +147,11 @@ jobs: --push ``` -graph query results +graph query results ``` MATCH (statement { - subject: 'https://spdx.org/spdxdocs/sbom-tool-2.2.7-66a07f86-0f12-4c6f-887b-9a1510b11d8a/transmute/0.9.2/2e57d4b2d9b45cccdd74dad91edbaabaa06074f9' + subject: 'https://spdx.org/...sbom-tool-2.2.7.../0.9.2/2e57d4b2d9b45cccdd74dad91edbaabaa06074f9' }) MATCH (receipt { subject: statement.subject