-
User Story
-
Resolution: Unresolved
-
P3: Somewhat important
-
None
-
6.10.0
-
None
Consider providing also pkg:generic PURL's for third-party code. E.g.:
....
"externalRefs": [
{
"referenceCategory": "PACKAGE_MANAGER",
"referenceLocator": "pkg:generic/freetype/freetype@2.14.1",
"referenceType": "purl"
}
will help scanners like snyk.
| For Gerrit Dashboard: QTBUG-141165 | ||||||
|---|---|---|---|---|---|---|
| # | Subject | Branch | Project | Status | CR | V |
| 684959,2 | SBOM: Add pkg:generic identifiers where applicable | dev | qt/qtbase | Status: NEW | 0 | 0 |