@@ -154,8 +154,8 @@ func TestSBOMEquivalence(t *testing.T) {
154154 want .
Results [
0 ].
Vulnerabilities [
1 ].
PkgIdentifier .
BOMRef = "pkg:rpm/centos/[email protected] ?arch=x86_64&epoch=1&distro=centos-7.6.1810" 155155 want .
Results [
0 ].
Vulnerabilities [
2 ].
PkgIdentifier .
BOMRef = "pkg:rpm/centos/[email protected] ?arch=x86_64&epoch=1&distro=centos-7.6.1810" 156156
157- // SBOM parsing consumes UUIDs #1-#4 for components, so ReportID becomes #5
158- want .ReportID = "3ff14136 -e09f-4df9 -80ea-000000000005 "
157+ // ReportID uses v7 UUID with independent counter from v4 UUIDs used for SBOM components
158+ want .ReportID = "017b7d41 -e09f-7000 -80ea-000000000001 "
159159 },
160160 },
161161 {
@@ -173,8 +173,8 @@ func TestSBOMEquivalence(t *testing.T) {
173173 require .Len (t , got .Results , 1 )
174174 want .Results [0 ].Target = "testdata/fixtures/sbom/centos-7-spdx.txt (centos 7.6.1810)"
175175
176- // SBOM parsing consumes UUIDs #1-#4 for components, so ReportID becomes #5
177- want .ReportID = "3ff14136 -e09f-4df9 -80ea-000000000005 "
176+ // ReportID uses v7 UUID with independent counter from v4 UUIDs used for SBOM components
177+ want .ReportID = "017b7d41 -e09f-7000 -80ea-000000000001 "
178178 },
179179 },
180180 {
@@ -192,8 +192,8 @@ func TestSBOMEquivalence(t *testing.T) {
192192 require .Len (t , got .Results , 1 )
193193 want .Results [0 ].Target = "testdata/fixtures/sbom/centos-7-spdx.json (centos 7.6.1810)"
194194
195- // SBOM parsing consumes UUIDs #1-#4 for components, so ReportID becomes #5
196- want .ReportID = "3ff14136 -e09f-4df9 -80ea-000000000005 "
195+ // ReportID uses v7 UUID with independent counter from v4 UUIDs used for SBOM components
196+ want .ReportID = "017b7d41 -e09f-7000 -80ea-000000000001 "
197197 },
198198 },
199199 {
@@ -216,8 +216,8 @@ func TestSBOMEquivalence(t *testing.T) {
216216 want .
Results [
0 ].
Vulnerabilities [
1 ].
PkgIdentifier .
BOMRef = "pkg:rpm/centos/[email protected] ?arch=x86_64&epoch=1&distro=centos-7.6.1810" 217217 want .
Results [
0 ].
Vulnerabilities [
2 ].
PkgIdentifier .
BOMRef = "pkg:rpm/centos/[email protected] ?arch=x86_64&epoch=1&distro=centos-7.6.1810" 218218
219- // SBOM parsing consumes UUIDs #1-#4 for components, so ReportID becomes #5
220- want .ReportID = "3ff14136 -e09f-4df9 -80ea-000000000005 "
219+ // ReportID uses v7 UUID with independent counter from v4 UUIDs used for SBOM components
220+ want .ReportID = "017b7d41 -e09f-7000 -80ea-000000000001 "
221221 },
222222 },
223223 }
0 commit comments