tally
tally copied to clipboard
Identify wrong BOM format
If you run tally -o cyclonedx-json bom.json on a syft-json file, it will exit successfully but not print any repositories. This is because the JSON parsing succeeds but there's no check to validate that the fields are what we expect them to be.
We should try and exit out with exit code 1 when the BOM format doesn't match the one we expected.