In some cases we can figure out the repository for a package just by looking at the SBOM, without the deps.dev dataset.
For instance:
This would be useful when the package isn't in deps.dev but its repository is in the scorecard dataset. Or, when the package is internal.
In some cases we can figure out the repository for a package just by looking at the SBOM, without the deps.dev dataset.
For instance:
vcstype in theexternalReferencesof a component, which typically contains the github repositoryThis would be useful when the package isn't in deps.dev but its repository is in the scorecard dataset. Or, when the package is internal.