Comments (1)
This is a bug in the sense that the package version is missing in SPDX reports, but it's not missing because of the missing tag in the base OS refernece, it's missing because of the docker-daemon
prefix for local images when Tern gets run. A fix for #1212 will also fix this issue.
from tern.
Related Issues (20)
- Export specific format versions (SPDX) HOT 1
- Container package name incorrect when analyzing local image
- Modify apk workaround commit now that purl spec has been updated HOT 1
- golang package names create invalid SPDXRefs
- Shall we move the test Docker image somewhere else? HOT 7
- Commas included in SPDX license expressions instead of 'AND'
- [SPDX][JSON] SBOM value format is incorrect for licenseDeclared HOT 1
- Error on image load if prefixed with a variable HOT 1
- Parsing error: JAVA_OPTS:: bad variable name HOT 1
- Potential issue with `LicenseInfoFromFiles` HOT 3
- Problem with broken symlinks while scaning some containers HOT 2
- Can't build images with Dockerfile samples HOT 4
- What is the best test image for integration testing? HOT 4
- Invalid file information in SPDX documents HOT 9
- Project still alive? HOT 3
- Docker image building seems to run indefinitely on extern dockerfiles
- Support for SPDX 2.3? HOT 1
- Support all skopeo image prefixes for `tern report -i`
- Support `docker build` arguments for `tern sbom -f Dockerfile` and `tern lock`
Recommend Projects
-
React
A declarative, efficient, and flexible JavaScript library for building user interfaces.
-
Vue.js
🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.
-
Typescript
TypeScript is a superset of JavaScript that compiles to clean JavaScript output.
-
TensorFlow
An Open Source Machine Learning Framework for Everyone
-
Django
The Web framework for perfectionists with deadlines.
-
Laravel
A PHP framework for web artisans
-
D3
Bring data to life with SVG, Canvas and HTML. 📊📈🎉
-
Recommend Topics
-
javascript
JavaScript (JS) is a lightweight interpreted programming language with first-class functions.
-
web
Some thing interesting about web. New door for the world.
-
server
A server is a program made to process requests and deliver data to clients.
-
Machine learning
Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.
-
Visualization
Some thing interesting about visualization, use data art
-
Game
Some thing interesting about game, make everyone happy.
Recommend Org
-
Facebook
We are working to build community through open source technology. NB: members must have two-factor auth.
-
Microsoft
Open source projects and samples from Microsoft.
-
Google
Google ❤️ Open Source for everyone.
-
Alibaba
Alibaba Open Source for everyone
-
D3
Data-Driven Documents codes.
-
Tencent
China tencent open source team.
from tern.