-
Hello, I would like to know if there are specific difference with cyclonedx-dotnet? As I understood, cyclonedx-dotnet:
After testing, the output are quite different (json vs json). |
Beta Was this translation helpful? Give feedback.
Replies: 1 comment 2 replies
-
@Herve-M, the last time we checked cyclonedx-dotnet did a better job with retaining the license string and dependency tree. We subsequently improved license fetching for dotnet via #352. We will add dependency tree via #501 in a future release. Are there differences with list of purls in the components section? Could you attach any sbom for comparison so that we can advise? Where cdxgen shines is mixed projects and monorepos where there are javascript and other apps along with .net projects in the same repo. |
Beta Was this translation helpful? Give feedback.
@Herve-M, the last time we checked cyclonedx-dotnet did a better job with retaining the license string and dependency tree. We subsequently improved license fetching for dotnet via #352. We will add dependency tree via #501 in a future release. Are there differences with list of purls in the components section? Could you attach any sbom for comparison so that we can advise?
Where cdxgen shines is mixed projects and monorepos where there are javascript and other apps along with .net projects in the same repo.