From ee06e541e0e0ed9981d480900200c216fcfdc089 Mon Sep 17 00:00:00 2001 From: anthonyharrison Date: Sat, 8 Jul 2023 17:39:37 +0100 Subject: [PATCH] fix: SPDX version handling --- cve_bin_tool/sbom_manager/spdx_parser.py | 1 + 1 file changed, 1 insertion(+) diff --git a/cve_bin_tool/sbom_manager/spdx_parser.py b/cve_bin_tool/sbom_manager/spdx_parser.py index 5ba764afe1..4ef399991a 100644 --- a/cve_bin_tool/sbom_manager/spdx_parser.py +++ b/cve_bin_tool/sbom_manager/spdx_parser.py @@ -45,6 +45,7 @@ def parse_spdx_tag(self, sbom_file: str) -> list[list[str]]: package = line_elements[1].strip().rstrip("\n") version = None if line_elements[0] == "PackageVersion": + # Version may contain : version = line[16:].strip().rstrip("\n") version = version.split("-")[0] version = version.split("+")[0]