You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Currently, a SBOM is meant to include delivered components.
The Framework is a dependency that needs to be already available on the target system.
Things can change if CycloneDX/specification#326 gets merged and we have extraneous components. Then it would make sense to add .NET as an extraneous component.
Somewhat related to #622
If the framework was limited using the
-tfm
flag, it would be useful to add it as:Not sure if it's possible to also add the OS component from the runtime identifier.
The text was updated successfully, but these errors were encountered: