Seemingly valid 1.6 cyclonedx sbom failing to import. From Slack
$ bomctl import oraclelinux-8-sbom.json
FATAL import: importing document: failed to store document: storing document urn:uuid:a121dd23-1dca-4132-b7f2-ec7e7cac11f2: saving nodes: insert nodes to table "nodes": SQL logic error: too many SQL variables (1)
Validation succeed with: https://github.com/CycloneDX/sbom-utility/releases/tag/v0.18.1
Output:
$ sbom-utility validate -i Downloads/oraclelinux-8-slim-sbom.json
Welcome to the sbom-utility! Version 'v0.18.1' (sbom-utility) (linux/amd64)
===========================================================================
[INFO] Loading (embedded) default schema config file: 'config.json'...
[INFO] Loading (embedded) default license policy file: 'license.json'...
[INFO] Attempting to load and unmarshal data from: 'Downloads/oraclelinux-8-slim-sbom.json'...
[INFO] Successfully unmarshalled data from: 'Downloads/oraclelinux-8-slim-sbom.json'
[INFO] Determining file's BOM format and version...
[INFO] Determined BOM format, version (variant): 'CycloneDX', '1.6' (latest)
[INFO] Matching BOM schema (for validation): schema/cyclonedx/1.6/bom-1.6.schema.json
[INFO] Loading schema 'schema/cyclonedx/1.6/bom-1.6.schema.json'...
[INFO] Found schema dependencies: [jsf-0.82.schema.json spdx.schema.json]
[INFO] Added schema 'schema/cyclonedx/common/jsf-0.82.schema.json' to loader:...
[INFO] Added schema 'schema/cyclonedx/common/spdx.schema.json' to loader:...
[INFO] Compiling schema: 'schema/cyclonedx/1.6/bom-1.6.schema.json'...
[INFO] Schema 'schema/cyclonedx/1.6/bom-1.6.schema.json' loaded
[INFO] Validating 'Downloads/oraclelinux-8-slim-sbom.json'...
[INFO] BOM valid against JSON schema: 'true'
sbom in question:
oraclelinux-8-slim-sbom.json
Seemingly valid 1.6 cyclonedx sbom failing to import. From Slack
Validation succeed with: https://github.com/CycloneDX/sbom-utility/releases/tag/v0.18.1
Output:
sbom in question:
oraclelinux-8-slim-sbom.json