cyclonedx-gomod icon indicating copy to clipboard operation
cyclonedx-gomod copied to clipboard

Include OS and architecture in PURL qualifiers of main components

Open nscuro opened this issue 2 years ago • 0 comments

At the moment all main components in SBOMs generated with app and bin share the same PURL. For example, the SBOM for a binary compiled for windows/amd64 will have the same PURL as a binary compiled for darwin/arm64.

Include at least GOOS and GOARCH in those PURLs. Investigate whether it makes sense to include even more qualifiers (the go version maybe?). This is for app and bin mode, for mod this wouldn't really make sense.

nscuro avatar Apr 22 '22 23:04 nscuro