Force Syft to produce cyclonedx 1.5 and 1.6. Tidelift requires 1.5.
When we bumped syft to 1.11 in pipeline-runner 24.07.15-123300-4 it by default generated a cyclonedx version 1.6. This version is not compatible with tidelift so the pipeline needs to produce both versions until Tidelift is ready for cyclonedx version 1.6.
Zelda trigger run: https://code-ib-zelda.staging.dso.mil/ironbank-tools/tools/trigger/-/jobs/264907
Quick Example using the same pipeline-runner image:
Edited by Jeffrey Wuebbles