Replies: 1 comment
-
@wujunhuge c/c++ support in cdxgen is incomplete. The SBOM generated will be imprecise, lacking correct purl & other metadata indicated with a confidence value of 0. Further, the license lookup used by cdxgen is quite weak and cannot be used in any legal context. Best to use projects like scancode and clearlydefined for better license information. |
Beta Was this translation helpful? Give feedback.
0 replies
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
-
Why does the analysis of C++/C projects not include licenses? Do we need to analyze based on any specific files
Beta Was this translation helpful? Give feedback.
All reactions