trivy
trivy copied to clipboard
reafactor(spdx): save undetected liceneses in `ExtractedLicensingInfo`
Description
There are cases when SPDX license list doesn't contain license of dependency/package. We need to use ExtractedLicensingInfo field. Example: https://github.com/spdx/tools-java/blob/master/testResources/SPDXJSONExample-v2.2.spdx.json