Skip to content

BOM download should let users choose a CycloneDX spec version #1473

@anthonymastreanvae

Description

@anthonymastreanvae

Current Behavior

Downloading the BOM from a project created with a v1.6 format BOM is creating a v1.5 format BOM.

Steps to Reproduce

  1. Create a project
  2. Generate a v1.6 BOM with @cyclonedx/cyclonedx-npm or dotnet-cyclonedx
  3. Upload the BOM
  4. Download the BOM

Expected Behavior

I expect either...

  • the latest BOM format to be supported
  • the same BOM format that was uploaded (successfully) to be downloaded
  • or to have a choice of which BOM format to download

Dependency-Track Version

4.14.0

Dependency-Track Distribution

Container Image

Database Server

PostgreSQL

Database Server Version

No response

Browser

Microsoft Edge

Checklist

Metadata

Metadata

Assignees

No one assigned

    Labels

    defectSomething isn't workingp2Non-critical bugs, and features that help organizations to identify and reduce risksize/SSmall effort

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions