diff --git a/pkg/sbom/spdx.go b/pkg/sbom/spdx.go index a10eb04..f6bd917 100644 --- a/pkg/sbom/spdx.go +++ b/pkg/sbom/spdx.go @@ -189,7 +189,8 @@ func (s *spdxDoc) parseComps() { nc.supplier = *supp } nc.supplierName = s.addSupplierName(index) - if sc.PackageOriginator != nil { + + if sc.PackageVerificationCode != nil { nc.sourceCodeHash = sc.PackageVerificationCode.Value }