SPDX Generator with RefIDs and package hierarchy


daniel@...
 

All,
I feel like I'm missing something obvious here, but which SBOM generators actually generate SPDX SBOMs that (1) have refID's for the overall asset (documentDescribes), and (2) have package dependency hierarchy information, i.e. something that I could use to build a tree visualization of how the software dependencies are introduced into the main piece of software?

Thanks,
Daniel

Join {spdx@lists.spdx.org to automatically receive all group messages.