sbom Validate
-
run command: .\sbom-tool-win-x64.exe generate -b $filepath -bc $codepath -pn alicedemo -pv 1.0.0 -ps Alice -nsb https://alicedemo.com -m $manifestpath
-
To generate the file: $manifestpath_manifest\spdx_2.2\manifest.spdx.json
-
run validate command: .\sbom-tool-win-x64.exe Validate -b $filepath -o $outputpath -m $manifestpath -mi alicedemo:1.0.0
Error: Encountered error while running ManifestTool validation workflow. Error: The given key 'alicedemo:1.0.0' was not present in the dictionary.
How to fix it?
The 'validate' scenario is currently not supported. This tool only generates SBOMs. We are working on a validate solution right now and we should have it ready in a couple of weeks.
Validation is supported now. You can use -mi SPDX:2.2 to validate your SBOM.