sbt-bom
sbt-bom copied to clipboard
support SPDX
Should we also support publishing the SBOM in SPDX format?
This could be pretty easy using https://github.com/spdx/cdx2spdx It's available on maven.
Interesting find! It's hard to predict whether it'll be easier to pull in that dependency or to generate SPDX 'directly', but both approaches are worth a try!