cyclonedx-gomod
cyclonedx-gomod copied to clipboard
Include OS and architecture in PURL qualifiers of main components
At the moment all main components in SBOMs generated with app
and bin
share the same PURL. For example, the SBOM for a binary compiled for windows/amd64
will have the same PURL as a binary compiled for darwin/arm64
.
Include at least GOOS and GOARCH in those PURLs. Investigate whether it makes sense to include even more qualifiers (the go version maybe?).
This is for app
and bin
mode, for mod
this wouldn't really make sense.