sbom-tool icon indicating copy to clipboard operation
sbom-tool copied to clipboard

Investigate root cause of SBOMs from the Dark Ages

Open alisonlomaka opened this issue 7 months ago • 6 comments

We occasionally receive SBOMs where the SPDX Created field has values with datestamps from year 1403. This suggests that the SBOM generation code is creating invalid timestamps under some circumstances. So far this has occurred for products related to iOS and Apple/Mac, so maybe it is related to a Mac build environment? Need to investigate the root cause of the anomalous dates and fix or determine if or how we should fix.

alisonlomaka avatar Mar 24 '25 16:03 alisonlomaka