diff --git a/cve_bin_tool/sbom_manager/spdx_parser.py b/cve_bin_tool/sbom_manager/spdx_parser.py index 5ba764afe1..4ef399991a 100644 --- a/cve_bin_tool/sbom_manager/spdx_parser.py +++ b/cve_bin_tool/sbom_manager/spdx_parser.py @@ -45,6 +45,7 @@ def parse_spdx_tag(self, sbom_file: str) -> list[list[str]]: package = line_elements[1].strip().rstrip("\n") version = None if line_elements[0] == "PackageVersion": + # Version may contain : version = line[16:].strip().rstrip("\n") version = version.split("-")[0] version = version.split("+")[0]