sbomqs
sbomqs copied to clipboard
[Scoring] Files Analyzed
A component's metadata in an SBOM is probably more accurate if the generator tool has analyzed the files for the repo. We should consider using this metric for scoring. We know this field exists for SPDX however for cyclonedx we are still re-searching how this is encoded.
@surendrapathak