Skip to content

Difference with cyclonedx-dotnet? #505

Answered by prabhu
Herve-M asked this question in Q&A
Discussion options

You must be logged in to vote

@Herve-M, the last time we checked cyclonedx-dotnet did a better job with retaining the license string and dependency tree. We subsequently improved license fetching for dotnet via #352. We will add dependency tree via #501 in a future release. Are there differences with list of purls in the components section? Could you attach any sbom for comparison so that we can advise?

Where cdxgen shines is mixed projects and monorepos where there are javascript and other apps along with .net projects in the same repo.

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@Herve-M
Comment options

@prabhu
Comment options

Answer selected by Herve-M
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants