Skip to content

v2.7.0

Latest
Compare
Choose a tag to compare
@tngraf tngraf released this 29 Jan 16:03

2.7.0

  • fix for bom findsources for some JavaScript SBOMs.
  • bom show command also lists purl and source code download url in verbose mode.
    If one of the values is missing and --forceerror has been specified, error code 97 is returned.
  • bom show command also lists license information in verbose mode, but
    only for CycloneDX 1.6 and later.
  • bom validate now also uses -v and --forceerror and uses the same bom show functionality
    to check for missing purl or source code url.
  • until version 2.6.0, project create always set the Project Mainline State of a project release either
    to SPECIFIC of to the value given by -pms. Now existing Project Mainline States are kept.
  • project create has a new parameter --copy_from which allows to first create a copy of the given
    project and then update the releases based on the contents of the given SBOM.
  • fix for bom map losing SBOM items when it tries to map to invalid SW360 releases.
  • fix issue with setting external references (in bom granularity).