mirror of
https://github.com/anchore/grype
synced 2024-11-10 14:44:12 +00:00
6 lines
385 B
Markdown
6 lines
385 B
Markdown
|
# CycloneDX Schemas
|
||
|
|
||
|
`grype` generates a CycloneDX BOm output with the vulnerability extension. This validation is similar to what is done in `syft`, validating output against CycloneDX schemas.
|
||
|
|
||
|
Validation is done with `xmllint`, which requires a copy of all schemas because it can't work with HTTP references. The schemas are modified to reference local copies of dependent schemas.
|