You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
The classifier information is lost on the generated spdx sbom. The end result is two entries with the same netty reference.
{
"SPDXID" : "SPDXRef-gnrtd11",
"copyrightText" : "UNSPECIFIED",
"description" : "Netty is an asynchronous event-driven network application framework for\n rapid development of maintainable high performance protocol servers and\n clients.",
"downloadLocation" : "NOASSERTION",
"filesAnalyzed" : false,
"homepage" : "https://netty.io/netty-resolver-dns-native-macos/",
"licenseConcluded" : "NOASSERTION",
"licenseDeclared" : "Apache-2.0",
"name" : "Netty/Resolver/DNS/Native/MacOS",
"originator" : "Organization:The Netty Project",
"summary" : "Netty is an asynchronous event-driven network application framework for\n rapid development of maintainable high performance protocol servers and\n clients.",
"versionInfo" : "4.1.107.Final"
}, {
"SPDXID" : "SPDXRef-gnrtd0",
"copyrightText" : "UNSPECIFIED",
"description" : "Netty is an asynchronous event-driven network application framework for\n rapid development of maintainable high performance protocol servers and\n clients.",
"downloadLocation" : "NOASSERTION",
"filesAnalyzed" : false,
"homepage" : "https://netty.io/netty-resolver-dns-native-macos/",
"licenseConcluded" : "NOASSERTION",
"licenseDeclared" : "Apache-2.0",
"name" : "Netty/Resolver/DNS/Native/MacOS",
"originator" : "Organization:The Netty Project",
"summary" : "Netty is an asynchronous event-driven network application framework for\n rapid development of maintainable high performance protocol servers and\n clients.",
"versionInfo" : "4.1.107.Final"
}
The classifier information is lost. This is related to spdx/spdx-gradle-plugin#115 on the gradle plugin side which really does not handle this very gracefully.
The text was updated successfully, but these errors were encountered:
For a pom like with multiple references to the same dependency with different classifiers
io.netty:netty-resolver-dns-native-macos:4.1.107.Final:osx-aarch_64
io.netty:netty-resolver-dns-native-macos:4.1.107.Final:osx-x86_64
The classifier information is lost on the generated spdx sbom. The end result is two entries with the same netty reference.
The classifier information is lost. This is related to spdx/spdx-gradle-plugin#115 on the gradle plugin side which really does not handle this very gracefully.
The text was updated successfully, but these errors were encountered: