cyclonedx-linux-generator icon indicating copy to clipboard operation
cyclonedx-linux-generator copied to clipboard

compoent purl is not download url

Open sify21 opened this issue 3 years ago • 0 comments

in RedHatSBomGenerator.java, the method to get component purl is by parsing cmd output from yumdownloader --urls "softwarename", which returns http url to download the rpm, but that's not purl. purl definition is here: https://github.com/package-url/purl-spec

Furthermore, yumdownloader --urls seems to return availabe package download url rather than installed package download url, so it's not accurate.

sify21 avatar Oct 08 '22 16:10 sify21